Cyber Incident Response

What happens if you get hacked? Here’s exactly what to do.

Being hacked is frightening — but panic is the enemy. Whether you’re worried about it or dealing with it right now, this is the plain-English plan: what to do in the first hour, what not to do, and how we help you contain, recover and come back stronger.

Fast response · calm, expert help · Greater Manchester & UK-wide

We help you

  • Contain the attack fast
  • Investigate what happened
  • Recover from tested backups
  • Report & communicate properly
⚠ Being attacked right now?
Don’t wait — call us immediately and we’ll help you respond. We can assist even if you’re not yet a client.
Call 0161 738 1399

Quick answer

If you think you’ve been hacked: stay calm, disconnect affected devices (but don’t delete anything), don’t pay a ransom, change passwords from a clean device, and call for expert help straight away. If personal data is involved you may need to report to the ICO within 72 hours. Foresight helps you contain the incident, work out what happened, recover from backups, and report and communicate properly — then harden everything so it can’t happen again.

The first hour

What to do if you think you’ve been hacked

1

Don’t panic — but act fast

Take a breath. Most incidents are contained quickly if you move calmly and in the right order. The first hour matters most.

2

Disconnect, don’t delete

Isolate affected devices — unplug the network cable or turn off Wi-Fi — to stop it spreading. But do not wipe or “clean” anything yet; you’ll destroy the evidence needed to understand what happened.

3

Don’t pay a ransom (yet)

Paying rarely guarantees you get your data back and it funds more crime. Get expert help first — there are often better options, especially if your backups are sound.

4

Change passwords from a clean device

Using a device you know is safe, reset passwords for email and critical accounts, and turn on multi-factor authentication if it isn’t already.

5

Call for expert help

Phone your IT and security provider immediately. The sooner specialists are involved, the faster it’s contained and the less it costs you. We’re on 0161 738 1399.

6

Preserve evidence & keep notes

Write down what you saw and when — odd messages, locked files, suspicious emails. It helps the investigation, your insurer and any report you have to make.

7

Report it

If personal data may be affected, you may need to tell the ICO within 72 hours. Report cyber crime to Action Fraud and the NCSC. We’ll guide you through it.

8

Communicate carefully

Keep staff informed, and tell affected clients or suppliers if needed — calmly and factually. We’ll help you say the right thing.

How we help

Respond, recover, come back stronger

When you call us, we move fast and calmly: we contain the attack to stop it spreading, investigate how they got in, recover your data from tested backups, and help you report to the ICO and authorities and handle communications. Then we harden everything — Microsoft 365 security, MFA, monitoring and Cyber Essentials — so the same door can’t be used twice.

Prevention

The best time to prepare was yesterday

The second best time is now. Most attacks are stopped by the basics done properly: tested backups, MFA everywhere, hardened Microsoft 365, monitoring, and a simple plan everyone knows. Not sure where you stand? Check whether a leaked password already puts you at risk with our free dark-web check or see what an attacker can see with our free risk scan — or book a readiness review below.

FAQs

Common questions

Should I pay the ransom?
It’s not recommended. Paying rarely guarantees you get your data back, it funds more crime, and it can mark you as an easy target. Call for expert help first — if your backups are sound, there are usually better options.
Do I legally have to report being hacked?
If personal data may have been affected, UK GDPR generally requires you to notify the ICO within 72 hours of becoming aware. Cyber crime should also be reported to Action Fraud and the NCSC. We’ll help you work out what applies and guide you through it.
How quickly can you respond?
Quickly — and existing clients already have a plan in place, which makes response far faster. If you’re not a client and you’re under attack, call us anyway; we’ll help.
What’s the single most important thing to get right?
Tested backups. If you can cleanly restore your data, a ransomware attack becomes an inconvenience rather than a catastrophe. After that: MFA everywhere, so a stolen password isn’t enough.
Can you help us build a response plan before anything happens?
Yes — that’s exactly what a readiness review is for. We’ll check your backups, MFA, monitoring and plan, and leave you ready to respond calmly if the day ever comes.

Be ready

Book a free incident-readiness review

We’ll check your backups, MFA, monitoring and plan, and leave you ready to respond calmly if the worst happens. Free and no-obligation.

If it’s urgent, please call 0161 738 1399 — don’t wait for a reply.

Hope you never need us. Be glad you’re ready if you do.

Whether you’re under attack now or want to be prepared, we’re here — calm, fast and local.