The short answer: keep calm, but act immediately. Disconnect affected computers from the network to stop the spread, shut downnotof them (then evidence can disappear), change passwords on important accounts from a clean device, document everything - and bring in help. The first hours determine whether it will be an incident or a disaster.

How do I know if we've been hacked?

Common signs: files that are suddenly encrypted or renamed and a message demanding payment (ransomware), colleagues receiving strange e-mails from your addresses, logins from other countries, systems behaving unexpectedly, or a customer contacting you about shipments you didn't make. When in doubt - treat it as an incident until proven otherwise. It is cheaper to overreact than to wait.

The first hours – step by step

1. Stop the spread

Disconnect the affected devices from the internet and the network – pull the network cable or turn off Wi-Fi on them. The goal is to prevent the attacker from reaching more computers.Do not turn offthe computers and delete nothing; important tracks are in the memory and can disappear otherwise.

2. Change password from a clean device

Use a computer or phone thatnotis affected and change the password on the most important first: email, banking services, administrator accounts and your password manager. Enable two-factor wherever possible. If you assume that the attacker sees everything on the affected device - do not change the password on it.

3. Document everything

Write down the times, what you saw, which units were affected and what you did. Take photos or screenshots of, for example, a ransomware message. This log is worth its weight in gold - both for solving the incident and for possible reporting.

4. Alert the right people internally

Make sure management and the IT manager know what is going on. Designateaperson who keeps the management together, so that five people are not doing conflicting things at the same time.

5. Bring in outside help

Do you have an IT partner or security provider - call now. If you lack it, ZORC andSwedish Cyber ​​Securityhelp you limit the damage and find out what happened. The earlier expert help, the less damage.

Do we have to report the breach?

Often, yes. Haspersonal dataaffected, a personal data incident must as a rule be reported to the Privacy Protection Agency (IMY) within72 hourssince you discovered it. It may also be time to report to the police, and to report to CERT-SE. If you are unsure - document carefully and get help to assess the reporting obligation. The clock starts ticking right away, so don't wait for the documentation.

What should I NOT do?

  • Don't pay the ransom hastily.There's no guarantee you'll get the data back, and it funds crime. Consult first.
  • Do not delete or "clean".before someone knowledgeable looks - you can destroy tracks that are needed.
  • Do not darken.Concealing an incident can make it legally worse and damage trust more.
  • Do not reconnect too quickly.Restore system only when you know the attacker is out.

How do we avoid next time?

When the emergency subsides: find outhowthey came in and plugged the hole. Secure backups (tested regularly), two-factor, up-to-date systems and trained staff are what stop most breaches. Aincident plan- a written list of who does what - means that the next alarm is dealt with calmly instead of in a panic.

Those who have a plan in the box make better decisions under pressure. Write the plan before you need it.

Do you need help - now or to prepare?

ZORC helps Swedish companies both to deal with ongoing incidents and to prepare so that they do not happen. ViaSwedish Cyber ​​Securitywe perform security audits and penetration tests that find the weaknesses before an attacker does. Do you want an incident plan in place – or do you need help right now?Contact ZORC.