forumNew topic

Suspected cyberattack on our corporate IT system — what concrete steps should we take in the first 24 hours?

EEsraMember
Job title
Python developer
Joined
Aug 2024
Message
134
#1

We are an auto parts wholesale and logistics company with 18 employees based in Berlin. This morning, we noticed that some shared folders on our accounting server were locked and a suspicious text file had been left behind. It's clearly unauthorized external access, but we can't tell yet how much data was exfiltrated or whether it spread to other parts of the network. Our annual turnover is around 2.2 million euros, and our systems hold invoice and contact records for both German and Turkish suppliers and customers.

We're trying not to panic, but we aren't sure exactly what operational and legal steps we need to take within the first 24 hours. Should we pull the plug on the systems right away, call the police, or reach out to a private IT security expert? How and when do we need to start the process of notifying customers or regulatory authorities?

GGürkan V***Member
Job title
Customer service representative
Sector
Printing
Organization type
workshop
Joined
Aug 2023
Message
118
Most Helpful#2

Short answer: In the first 24 hours, the priority is stopping the attacker from spreading, isolating without destroying evidence, and starting the legal notification clock. Rather than abruptly pulling the power cords, disconnect all network connections immediately; never reboot the servers before taking a forensic copy of the volatile memory.

Follow these concrete steps in order: First, isolate the network. Unplug the Ethernet cables or shut down switch ports, and disable Wi-Fi. If you power down the machines directly, malware traces and encryption keys in RAM will be lost, so keep the machines on but isolated from the network. Second, contact an external cyber incident response team and an IT law specialist. If your company has cyber insurance, call your insurer immediately; most policies will dispatch approved digital forensics firms right away.

On the legal side, in Germany, you are obligated to notify your state data protection authority within 72 hours from the moment there is reasonable suspicion of a personal data breach. Notifying customers, on the other hand, should only be done with legal counsel approval once the scope of the risk is clarified by the forensics report. Also, file an official criminal complaint with your state cybercrime unit to get the incident formally logged.

HHavva Y***MemberCommunity member
Joined
Jan 2023
Message
354
#3

Whatever you do, don't make the mistake of rebooting the server. Processes in RAM are the most critical area for tracing the source of the attack. If possible, capture a live memory dump and immediately copy the firewall connection logs to an external, read-only drive.

TTülay K***MemberCommunity member
Joined
Mar 2023
Message
216
#4

Where were your backups stored? If they're on a network-attached storage (NAS) unit that's probably compromised too. Do you have backups that are physically air-gapped or stored as immutable copies in a separate cloud account?

TTuğçe E***MemberCommunity member
Joined
Sep 2022
Message
343
#5

Right now, from a clean, non-work machine reset all your corporate email domain admin and cloud control panel passwords enforcing 2FA. Absolutely do not use the infected office machines to change passwords.

TTülay A***Member
Job title
Store associate
Sector
Packaging
Organization type
8-person team
Joined
Dec 2023
Message
64
#6

We dealt with a similar ransomware incident at our Stuttgart warehouse last year. The incident response team billed 4,800 euros for the first 48 hours, and total costs reached 11,000 euros including the forensics report. Because we had cyber insurance, we got every cent back—if you have a policy, don't waste any time.

KKemal G***Expert
Job title
System support specialist
Sector
Cleaning services
Organization type
a company within a holding
Joined
Feb 2024
Message
377

Doki · Log management setup · 2024

#7

Definitely speak with an IT attorney before calling the police. If you panic and make definitive statements to authorities or customers like "our data was stolen," and the investigation reveals that wasn't the case, you'll open yourself up to unnecessary legal liability and reputational damage.

note: I wrote this based on my own experience, it might not apply to everyone.

İİbrahim S***Expert
Job title
Store Manager
Sector
Printing
Organization type
20-person company
Joined
Nov 2022
Message
1
#8

Handle internal communication on day one following these rules: 1) Absolutely do not use company email or local network chat apps to discuss the incident. 2) Brief your staff via personal phones or a secure, external messaging group. 3) Instruct employees not to click on any suspicious screens and to keep their hands off their computers.

MMuhammetNew member
Job title
Association manager
Joined
Oct 2024
Message
34

Doki · Corporate website · 2025

#9

so sorry you're going through this the stress you're feeling right now is completely normal. the most important thing is to stay calm and not reply to any links or email addresses in the ransom note promising payment. honestly don't try negotiating without professional guidance.

GGülayMember
Job title
Textile workshop
Joined
Oct 2023
Message
84
#10

Pull the network cables, not the power cord, and don't format any drives until a digital forensics expert examines them.

HHatice T***ExpertCommunity member
Joined
Mar 2025
Message
222
#11

we need to make a distinction here. the haarder it is to reverse a decision the slower you should make it.

proven by experience.

İİlknur O***Member
Job title
Courier coordinator
Sector
Livestock
Organization type
chain store
Joined
Feb 2025
Message
109
#12

The discussion got scattered, let me summarize. If you scold false alarms, nobody will report again.

When making decisions, write down the worst-case scenario too, not just the best. If you have questions, write them; I'll answer as best I can.

AAli O***Member
Job title
Human Resources Specialist
Sector
Jewelry
Organization type
cooperative
Joined
Apr 2025
Message
360
#13

The answer above hits the nail on the head. If it's your first time, start small; scaling comes later.

This is my opinion I'm not claiming it's absolute truth.

NNurayMember
Job title
Publisher
Organization type
two-branch business
Joined
Oct 2023
Message
92
#14

Thanks for posting.

VVildan U***MemberCommunity member
Joined
Dec 2025
Message
32
#15

Let me share what happened to me; it might be useful. If 2FA is on, a stolen password alone is useless.

If I were you, I'd go this route.

OOğuzMember
Job title
Former founder
Organization type
early-stage startup
Joined
Aug 2023
Message
76
#16

I felt relieved reading this answer so it's not just me. An untested backup is not a backup.

Just leaving this note, it might be useful.

AAhmet Z***MemberCommunity member
Joined
Feb 2024
Message
25
#17

There's a trap here, let me mention it. Forgotten test environments are more often the entry point than live systems.

Of course it varies if your situation is different.

OOkan Y***ExpertCommunity member
Joined
Aug 2023
Message
335
#18

Absolutely. If I were to add anything: If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Hope this helps.

RRıdvan Ç***Member
Job title
Marketing director
Sector
Media and publishing
Organization type
cooperative
Joined
May 2023
Message
200

Doki · Log management setup · 2024

#19

My perspective changed after experiencing that. Taking measures without an inventory leaves doors you haven't seen open.

This is my opinion, I'm not claiming it's absolute truth.

NNazlı E***MemberCommunity member
Joined
Aug 2025
Message
378
#20

You're right. Processes without records never improve, because you don't know what to fix.

Proven by experience.

Reply