forumNew topic

Hosting provider says "you've been hacked" — what are the incident response steps for the first hour?

HHüsniye D***Member
Job title
Customer Relations Manager
Sector
Law
Organization type
family business
Joined
Jul 2024
Message
384
#1

We run a Riyadh-based B2B e-commerce and wholesale ordering platform. We're a team of 14, and our cloud server holds records for roughly 45,000 registered businesses and orders. Late last night we received a high-priority alert from our local hosting provider: they detected abnormal outbound data exfiltration and unauthorized command traffic originating from our server, urging an immediate audit. We process an average of 80.000 SAR in monthly orders through this system.

The moment the email dropped, total panic broke out at the office. Our developer wants to immediately SSH in, run system package updates, close open ports, and start deleting any suspicious-looking scripts. My business partner, on the other hand, insists on immediately killing the machine and restoring from last week's clean backup.

In terms of incident response steps, what should our technical and administrative priorities look like within the very first hour? How do we isolate the environment without destroying evidence or tipping things further in the attacker's favor, and what is the proper sequence for legal disclosures?

RReyhan T***MemberCommunity member
Joined
Nov 2024
Message
318
Most Helpful#2

Short answer: During the first hour, absolutely do not delete suspicious files, do not run updates, and do not reboot the machine; doing so wipes critical volatile memory traces and forensic evidence. Your sole focus in the first 60 minutes is severing external network connectivity to isolate the host, capturing a live memory and disk snapshot, and assembling the crisis team.

Isolation must be completed within the first 15 minutes. Jump into your hosting dashboard and sever public internet access, or reconfigure the firewall to drop all inbound and outbound traffic except for an SSH whitelist tied to your team's static IP. Cutting network access instead of yanking the power preserves volatile RAM artifacts while severing active command-and-control channels.

Minutes 15 through 40 must be dedicated to evidence preservation. Pull a live RAM dump via your hypervisor or console, followed by a full disk snapshot. If your developer starts deleting files or running updates, forensic analysts will find it near impossible to trace the initial intrusion vector and identify what vulnerability was exploited.

Minutes 40 through 60 are for initial scope assessment and compliance prep. Restoring from a backup without reviewing database access logs is pointless; if the attacker holds the exploit, they will be back inside within minutes. Concurrently, brief company leadership and legal counsel to assess potential breach notification duties under Saudi data protection regulations if customer records were accessed.

YYağmur A***Member
Job title
Technical service technician
Sector
Healthcare services
Organization type
300-person organization
Joined
Feb 2024
Message
349
#3

Tell your developer to step away from the keyboard immediately. The urge to "clean up fishy files" is an amateur reflex that obliterates forensic evidence. Any cleanup done before finding every persistence mechanism and backdoor left behind is just an illusion of security.

EEbru K***MemberCommunity member
Joined
Aug 2025
Message
113
#4

Virtually pull the network plug from the cloud panel, but leave the box powered on. Dump network socket states, active process trees, and open file descriptors to an external mount via the console. Any malware running solely in volatile memory vanishes the second the OS reboots.

MMelis K***VeteranCommunity member
Joined
Dec 2025
Message
26
#5

Immediately rotate all external API keys, database credentials, and server access keys from an entirely clean, off-network device. Never trigger these credential resets from inside the compromised machine itself.

HHalil A***MemberCommunity member
Joined
Dec 2024
Message
89
#6

Got an identical alert last year, panicked, wiped the box, and restored from backup. Because we never uncovered the actual point of entry, we got hit with a 45.000 SAR ransom note two days later and had to cough up another 60.000 SAR for digital forensics anyway. Don't touch a thing without preserving evidence first.

SSerkan G***MemberCommunity member
Joined
Aug 2023
Message
37
#7

Just because the hosting provider says "you've been hacked" doesn't always mean an attacker is actively inside. Sometimes a misconfigured DNS service or an open SMTP relay on the server triggers these alarms too. Cut off the network connection, but don't jump to conclusions and condemn the system right away.

AAlper B***MemberCommunity member
Joined
Jul 2022
Message
304
#8

Here is the order of operations for the first 60 minutes: 1) Cut the server's external internet access. 2) Take a RAM dump and a disk snapshot. 3) Change admin passwords from an independent device. 4) Request abnormal traffic logs in writing from the hosting provider. 5) Officially notify company management and legal counsel.

AAycanMember
Job title
Corporate procurement
Joined
Dec 2023
Message
98
#9

Legal obligations come into play simultaneously with the technical interventions carried out during a cyber incident. In the event of a suspected personal data breach, notification obligations to the relevant national regulatory bodies and affected users may arise; therefore, it is essential that all technical steps be thoroughly documented as they are executed.

EElif E***Member
Job title
Sales Manager
Sector
Logistics
Organization type
medium-sized business
Joined
Feb 2024
Message
38
#10

so sorry to hear that I can only imagine the tension in the office riht now. stay calm and stop pointing fingers at each other. the priority shouldn't be rushing to bring the system back online, but figuring out the source of the attack and patching it permanently.

YYiğitMember
Job title
Video production
Joined
May 2024
Message
88
#11

theres a part I dont understand. btw if its your first time, start small; scaling comes later.

if you post the result here, it will help others too.

EEsra Y***MemberCommunity member
Joined
May 2024
Message
285
#12

How did you solve this? Forgotten test environments are more often the entry point than live systems.

Just leaving this note, it might be useful.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#13

A quick correction: "secure" here isn't absolute; it just means raising the cost. The goal isn't to make attacks impossible, but to make them not worth the effort.

ZZehra U***ExpertCommunity member
Joined
Aug 2023
Message
19
#14

I'm a small business, let me explain from my side. If you get three different answers on a topic, the question was asked wrong.

Proven by experience.

MMehmet B***Member
Job title
Customer service representative
Sector
Construction
Organization type
120-person company
Joined
Nov 2023
Message
7

Doki · Vulnerability scanning · 2023

#15

You're right, I've been down that road too. When you try to change everything at once, nothing settles.

VVeli P***Expert
Job title
Product Manager
Sector
Textile
Organization type
chain store
Joined
Dec 2024
Message
23
#16

If you're going this route, sort this out first. Mistakes made on the incident response steps side are usually reversible but expensive.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection. Hope this helps.

FFerhat E***Expert
Job title
Production Manager
Sector
Real estate
Organization type
40-person manufacturing company
Joined
Aug 2023
Message
128

Doki · Infrastructure migration · 2024

#17

I went through the same thing. Everyone rushing into incident response steps gets stuck at the same point.

Correct me if I'm wrong.

SSelin S***Member
Job title
Company Owner
Sector
Accounting & advisory
Organization type
cooperative
Joined
Jul 2024
Message
212
#18

here's how it went for us. when making decisions, write down the worst-case scenario too, not just the best.

FFadimeNew member
Job title
Food manufacturer
Organization type
a company within a holding
Joined
Sep 2024
Message
42
#19

I agree. If you scold false alarms, nobody will report again.

Good luck with that.

GGürkan K***Member
Job title
Human Resources Specialist
Sector
Catering
Organization type
120-person company
Joined
Dec 2024
Message
157
#20

The most overlooked point about incident response steps is this: Processes without records never improve, because you don't know what to fix.

When you try to change everything at once, nothing settles. Proven by experience.

Reply