Been Hacked? First steps for your business
Been Hacked is the moment to slow down, preserve evidence and take practical action. If your business suspects a hacked email account, compromised password, infected device, suspicious banking request or unauthorised login, IT Life-Raft can help you work through the first hour calmly.
Step 1: contain the immediate risk
Disconnect affected devices from the network if malware is suspected. Do not wipe systems until evidence has been captured. Change passwords from a clean device, prioritising email, Microsoft 365, banking, website admin and any systems that control customer or payment data.
Step 2: secure accounts
Check mailbox forwarding rules, suspicious inbox rules, administrator users, recovery email addresses, MFA prompts and recent sign-in locations. Many incidents are caused by account compromise rather than a dramatic virus infection, so identity and email checks are often the fastest route to containment.
Step 3: preserve evidence
Keep screenshots, message headers, login alerts, unusual invoices, bank details, URLs and timestamps. Evidence helps you understand what happened and supports any bank, insurer or incident report. Avoid deleting emails or logs until the basic timeline is clear.
Step 4: check devices and backups
Review laptops, desktops, phones and shared devices for suspicious software, browser extensions and unknown remote-access tools. Confirm whether backups exist, when they last ran and whether they can be restored safely. A backup that has never been tested should not be treated as a recovery plan.
Step 5: protect customers and staff
If email or customer data may have been exposed, prepare clear internal guidance before messages spread. Staff should know which accounts to avoid, which passwords to change and who is coordinating the response. Customers may need careful, factual communication if their information or invoices could be affected.
Step 6: document what changed
Record every containment step: password resets, MFA changes, device isolation, bank calls, supplier notifications, scans and restored files. This reduces confusion and helps prevent the same gap being missed later.
Step 7: reduce repeat risk
After the immediate incident, review MFA, password managers, administrator access, backups, endpoint updates, staff awareness and supplier permissions. The goal is not just to fix one hacked account, but to make the next attempt harder.
Ask IT Life-Raft for help or read more about cybersecurity support.
How IT Life-Raft helps after the first check
Once the immediate issue is understood, the next stage is to turn the incident or support request into a clearer plan. That means checking accounts, devices, backups, administrator access, email rules, website logins, supplier permissions and any systems that hold customer information. Small businesses often do not need complicated enterprise processes, but they do need a reliable checklist, plain-English advice and someone who can separate urgent risk from background noise.
IT Life-Raft focuses on practical action. We help identify what should be fixed today, what can wait, and what should become part of normal managed IT support. That may include stronger multi-factor authentication, cleaner Microsoft 365 settings, backup testing, endpoint updates, password manager rollout, staff guidance, supplier access reviews and a simple recovery plan. The outcome should be a business that is easier to support, easier to recover and less exposed to avoidable security problems.
The same approach applies whether the problem starts with a suspicious email, a lost device, a failed backup, a slow laptop, an unusual sign-in alert or uncertainty about who manages your IT. The goal is to restore confidence quickly, then reduce the chance of the same problem happening again.
Ongoing improvement
This page is designed to give a clear starting point, but the real value comes from turning the advice into a practical action list. IT Life-Raft can help review the current setup, prioritise the highest-risk gaps, explain the options in plain English and support small improvements over time. That may include account protection, device checks, backup testing, Microsoft 365 settings, staff guidance, supplier access, website security and a simple recovery plan that the business can actually use.