- Job title
- Customer Relations Manager
- Sector
- Law
- Organization type
- family business
- Joined
- Jul 2024
- Message
- 384
We run a Riyadh-based B2B e-commerce and wholesale ordering platform. We're a team of 14, and our cloud server holds records for roughly 45,000 registered businesses and orders. Late last night we received a high-priority alert from our local hosting provider: they detected abnormal outbound data exfiltration and unauthorized command traffic originating from our server, urging an immediate audit. We process an average of 80.000 SAR in monthly orders through this system.
The moment the email dropped, total panic broke out at the office. Our developer wants to immediately SSH in, run system package updates, close open ports, and start deleting any suspicious-looking scripts. My business partner, on the other hand, insists on immediately killing the machine and restoring from last week's clean backup.
In terms of incident response steps, what should our technical and administrative priorities look like within the very first hour? How do we isolate the environment without destroying evidence or tipping things further in the attacker's favor, and what is the proper sequence for legal disclosures?