We are an auto parts wholesale and logistics company with 18 employees based in Berlin. This morning, we noticed that some shared folders on our accounting server were locked and a suspicious text file had been left behind. It's clearly unauthorized external access, but we can't tell yet how much data was exfiltrated or whether it spread to other parts of the network. Our annual turnover is around 2.2 million euros, and our systems hold invoice and contact records for both German and Turkish suppliers and customers.
We're trying not to panic, but we aren't sure exactly what operational and legal steps we need to take within the first 24 hours. Should we pull the plug on the systems right away, call the police, or reach out to a private IT security expert? How and when do we need to start the process of notifying customers or regulatory authorities?