forumNew topic

We got hacked this morning: what should a step-by-step cyber incident response look like?

AAhmet Y***Expert
Job title
Field sales representative
Sector
Consulting
Organization type
regional distributor
Joined
Oct 2023
Message
2
#1

We run an industrial packaging wholesale business in Valencia with 22 employees total across the office and warehouse. When we got to work at 8:15 this morning, we found that an unusual admin account had been created on our central order and inventory server, and around 18 GB of data was exfiltrated around 2:40 AM last night.

The guy handling IT in our office is panicking and wants to format the whole OS and restore the server from last week's backup. Our accounting manager says we should freeze the bank accounts right away and call the police. The office is in total chaos right now; no one can figure out what to prioritize.

How do you handle this kind of cyber incident response step-by-step on the business side? Will hastily formatting the server get us into legal or technical trouble? We need a clear roadmap so we don't lose evidence, don't grind operations to a dead halt, and handle any legal reporting requirements.

BBerenMember
Job title
Product designer
Joined
Mar 2024
Message
112
Most Helpful#2

Short answer: Whatever you do, do NOT format the server right away. Wiping the drive destroys all forensic traces that prove how the attacker broke in, what backdoors they left behind, and exactly what data they stole. Cyber incident response isn't about panic-formatting; it's a process of identification, containment, root cause analysis, and secure recovery, in that order.

Step one is containment. Pull the server's network cable immediately or disable the network adapter from the virtualization panel. But do not reboot or shut down the machine. Take a full copy of the system's current state (a forensic image) and a memory dump onto an external drive. Disable the rogue admin account created by the attacker and terminate any active outbound remote access sessions.

Step two is root cause analysis. If you just format and restore a backup, whatever vulnerability the attacker used to get in the first place (like an unpatched firewall or a compromised VPN password) is still wide open. The attacker will be back in within a few hours using the exact same path. So you need to pinpoint and patch the entry point first.

Step three is the legal and administrative side. Since you operate in Spain, if that exfiltrated 18 GB includes personal data of customers or staff, you're legally required to notify the Spanish Data Protection Agency (AEPD). If you format the server, you won't be able to prove what data actually leaked, putting you at risk of hefty fines. Without a professional digital forensics report, you also won't be able to file a proper police report or claim insurance losses.

ÜÜlkü A***New memberCommunity member
Joined
Jul 2026
Message
70
#3

If you format it, firewall logs, session records, and the memory dump are gone for good. Copy the server's event logs and web access logs onto a clean USB drive immediately.

FFatihExpert
Job title
Chief Technology Officer
Joined
Jun 2023
Message
204
#4

Appoint an emergency lead in the company. If the accountant does one thing and the tech guy does another, your coordination will fall apart. Log every action in a notebook with the timestamp, what was done, and who did it.

İİsmail K***Veteran
Job title
QA Tester
Sector
E-commerce
Organization type
medium-sized business
Joined
Sep 2022
Message
3
#5

Reset every employee's email and VPN passwords immediately from a clean device. Check right away if there are any unknown port forwards or active remote desktop rules set up on your office router.

TTülay A***Member
Job title
Store associate
Sector
Packaging
Organization type
8-person team
Joined
Dec 2023
Message
64
#6

We paid 3,800 EUR to an independent incident response team in a similar case. Within four hours, they found two scheduled tasks the attacker had set up for persistence. If we'd just formatted and restored the backup, we would've been hit again the next night.

EEfe A***Member
Job title
IT manager
Sector
Livestock
Organization type
early-stage startup
Joined
Apr 2024
Message
2
#7

An IT guy eager to format is usually just trying to cover up his own mistakes and negligence. Bringing the server back up without knowing the entry point is no different from leaving the front door unlocked for the thief.

DDilekNew member
Job title
Pastry Shop
Organization type
a company within a holding
Joined
Nov 2024
Message
19
#8

so sorry you're dealing with this, walking into something like that in the morning is truly an awful feeling and keep calm and don't rush into restoring a backup and accidentally overwrite yesterday's clean copy.

UUfuk A***ExpertCommunity member
Joined
Dec 2024
Message
410
#9

Your priorities should be: 1) Physically cut the server's internet access. 2) Capture a memory dump and disk image. 3) Find and close the root cause. 4) Restore from a clean backup into a sanitized environment.

RRabia Z***ExpertCommunity member
Joined
May 2025
Message
167
#10

Don't shut down the server, just unplug it from the network and don't let anyone touch the format button until you have a bit-by-bit forensic clone of the drive.

UUfuk G***New member
Job title
General coordinator
Sector
IT services
Organization type
regional distributor
Joined
Jun 2026
Message
188

Doki · Backup setup · 2026

#11

quick summary for newcomers: Trying to do this alonne is the most expensive way.

DDoruk S***New memberCommunity member
Joined
Aug 2026
Message
278
#12

I agree with this. Having backups accessible on the same network and with the same identity makes them part of the target.

PPerihan Y***MemberCommunity member
Joined
Aug 2024
Message
178
#13

Let me summarize the topic, since several different answers were given. Forgotten test environments are more often the entry point than live systems.

I'm also curious if anyone does it differently.

HHakan U***MemberCommunity member
Joined
Apr 2024
Message
43
#14

Here's how it went for us. Processes without records never improve because you don't know what to fix.

Proven by experience.

GGizem U***MemberCommunity member
Joined
Oct 2023
Message
55
#15

i think it's hard to be that definitive about cyber incident response. honestly your time to detect an issue directly determines its cost.

SSultan E***MemberCommunity member
Joined
Jul 2025
Message
230
#16

We got stuck at the same point for a while. Taking notes for two weeks yields better results than a six-month estimate.

If you post the result here, it will help others too.

AAslı A***MemberCommunity member
Joined
Oct 2023
Message
19
#17

Same here.

EEmine A***MemberCommunity member
Joined
May 2022
Message
254
#18

I'm writing this so you don't make the same mistake. Your time to detect an issue directly determines its cost.

If the notification path is long notifications don't arrive; missing notifications mean delayed incident detection. Just leaving this note, it might be useful.

AAycan Ö***MemberCommunity member
Joined
Jul 2023
Message
321
#19

Thanks, this was very helpful. When we decide without measuring, we always end up in the same place.

Your time to detect an issue directly determines its cost.

PPolat K***MemberCommunity member
Joined
May 2023
Message
329
#20

Thanks, that was the answer I was looking for.

Reply