What to Do If Your Business Gets Hacked

A cyberattack can bring a business to a standstill. What you do in the first few minutes and hours can make a major difference in the damage caused, the cost of recovery, and how quickly your business gets back to normal.
If your business gets hacked, your priorities are to contain the incident, protect evidence, determine what was compromised, communicate with the right people, and begin a controlled recovery.
At Digital Sky Solutions, we emphasize that cybersecurity is not only about preventing attacks. Businesses also need a plan for when something goes wrong.
Here is what Canadian businesses should know.
How Do You Know You've Been Hacked?
Not every cyberattack starts with a ransom message. Warning signs can include:
- Employees suddenly being locked out of accounts
- Passwords changing without authorization
- Unusual Microsoft 365 login notifications
- Emails being sent from employee accounts without their knowledge
- Files becoming encrypted, deleted, or inaccessible
- Security software being disabled
- Customers receiving suspicious emails from your company
- Unusual financial transactions
- A ransomware message appearing on a computer
If something looks suspicious, take it seriously. However, avoid having employees experiment with affected computers or accounts. Their actions could destroy evidence or make the situation worse.
The Canadian Centre for Cyber Security recommends documenting when the problem was first noticed, which devices may be affected, and what information may have been exposed.
1. Contact Your IT Provider Immediately
Your first call should be to whoever manages your IT and cybersecurity.
Time matters. An attacker who has compromised one employee account may be trying to access other systems. Malware on one computer could also be spreading across the network.
Your IT team needs to determine:
- What happened
- Which systems and accounts are affected
- Whether the attacker still has access
- Whether the incident is spreading
- Whether information was accessed or stolen
- What needs to be isolated
Keep emergency IT contact information somewhere accessible even if your normal systems are unavailable. If Microsoft 365 is down and your IT provider's phone number is only stored in Outlook, you have an unnecessary problem during an already stressful situation.
2. Contain the Attack Without Destroying Evidence
Your first instinct may be to shut everything down. That is not always the right response.
The Cyber Centre advises organizations to preserve potentially compromised devices because restarting, shutting down, or modifying them can destroy useful evidence.
Instead, your IT provider may isolate affected devices, disable compromised accounts, restrict remote access, or quarantine systems using security tools.
For ransomware, broader isolation may be necessary. The Cyber Centre's ransomware guidance recommends isolating infected systems from internal networks and the Internet to help prevent the attack from spreading.
Unless there is an immediate safety concern, employees should avoid randomly rebooting, wiping, or modifying affected devices before IT professionals assess them.
3. Use a Safe Way to Communicate
If attackers have compromised your email or network, they may be able to see internal communications.
For serious incidents, use a communication method that has been verified as safe. This may mean using phones or another system outside the affected environment.
You should also decide who is authorized to communicate about the incident. Employees should know where to direct questions rather than discussing sensitive details through potentially compromised channels.
4. Determine What Was Compromised
Saying "we were hacked" does not tell you enough. Was one employee's password stolen? Was an administrator account compromised? Did someone access Microsoft 365? Was malware installed? Did an attacker access customer information or accounting systems?
These incidents require different responses.
Your IT team may review security logs, login records, endpoint alerts, email forwarding rules, and administrative changes. Establishing a timeline also helps determine the technical response and whether customers, employees, insurers, or authorities need to be notified.
5. Secure Your Accounts
If credentials may have been stolen, passwords need to be changed in a controlled way.
Pay particular attention to:
- Administrator and Microsoft 365 accounts
- Banking and accounting systems
- Remote access accounts
- Cloud services
- Backup systems
- Website and domain administration
Changing a password alone may not remove an attacker. They could have created another account, added an email forwarding rule, connected a malicious application, or established another way back into the environment.
Multi-factor authentication, or MFA, should also be enabled wherever possible. It adds another verification step beyond a password.
6. Contact Your Cyber Insurance Provider
If your business has cyber insurance, contact your insurer early.
Your policy may have requirements around notification, incident response, forensic investigation, legal advice, and which specialists can be used.
Do not wait until recovery is complete to find out what your policy requires. Keep your insurer's emergency contact information with your incident response documentation.
7. Determine Whether Personal Information Was Exposed
A cyberattack can quickly become more than an IT problem. If attackers accessed information about customers, employees, or other individuals, your business may have legal and privacy obligations.
Organizations subject to Canada's federal private-sector privacy law, PIPEDA, can have reporting, notification, and record-keeping obligations when a breach creates a real risk of significant harm. British Columbia also has its own private-sector privacy legislation.
Requirements depend on your organization and the information involved. For a significant data breach, legal or privacy professionals may need to be involved alongside your IT team.
8. Report Serious Cybercrime
Businesses sometimes hesitate to report cyber incidents because they are worried about reputational damage. However, cybercrime can affect organizations of every size.
The Cyber Centre provides a process to report a cyber incident. Depending on the situation, you may also need to contact local law enforcement or the Canadian Anti-Fraud Centre.
If money has been stolen or banking information may be compromised, contact your financial institution immediately. Acting quickly is particularly important when fraudulent transfers are involved.
9. Be Careful About Paying a Ransom
Ransomware puts business owners under enormous pressure. Systems may be unavailable, employees cannot work, and attackers may threaten to publish stolen information.
Paying a ransom does not guarantee that your systems or information will be recovered. The Cyber Centre also warns that paying can encourage further criminal activity.
Before making a decision, involve appropriate cybersecurity professionals, legal counsel, your cyber insurer, and law enforcement where applicable.
A ransom decision should not be made by one person under pressure while staring at a message on a compromised computer.
10. Restore Systems Carefully
Getting operational again is important, but restoring too quickly can cause another problem.
Before restoring systems, your IT team needs reasonable confidence that the attacker has been removed and the original security weakness has been addressed.
Recovery may include:
- Rebuilding affected computers
- Removing malicious software
- Patching vulnerable systems
- Resetting credentials
- Restoring clean data from backups
- Reconnecting systems gradually
- Monitoring for suspicious activity
Backups are critical at this stage. They should be protected and regularly tested to make sure information can actually be restored.
A backup that has never been tested should not automatically be considered a reliable recovery plan.
11. Communicate Carefully
Employees want to know whether they can work. Customers may want to know whether their information is safe. Leadership wants to know when operations will return to normal.
Communication should be accurate and based on confirmed information.
Avoid making statements too early about the cause or impact of an attack. Saying "no customer information was accessed" before the investigation is complete can create a bigger problem if that later proves incorrect.
Communicate what you know, what you are doing, and when people can expect another update.
12. Find Out How the Attack Happened
Once the immediate emergency has passed, ask an important question: How did the attacker get in?
Common causes include phishing, stolen credentials, unpatched software, weak passwords, compromised remote access, and poorly protected accounts.
The goal is not to blame an employee. It is to understand why one mistake or technical weakness was able to become a serious incident.
For example, if an employee clicked a phishing link, ask whether MFA was enabled, whether the email could have been detected earlier, and whether the account had unnecessary privileges.
Good cybersecurity uses multiple layers so that one mistake does not automatically become a business crisis.
13. Learn From the Incident
After recovery, conduct a simple post-incident review.
Ask:
- How quickly did we detect the attack?
- Did employees know who to call?
- Were our backups usable?
- Did we know which systems contained sensitive information?
- Was MFA enabled on critical accounts?
- Did our insurance respond as expected?
- How long did recovery take?
- What should we change?
Use the answers to improve your security and incident response plan.
Prepare Before You Get Hacked
The worst time to create an incident response plan is while someone is actively attacking your business.
Every small and mid-sized business should know who makes decisions during an incident, who to call for emergency IT support, how systems will be isolated, where backups are stored, who contacts the insurer, and how the business will operate if critical systems are unavailable.
The plan does not need to be hundreds of pages long. It needs to be clear, accessible, tested, and understood by the people who will use it.
Strong authentication, reliable backups, software patching, security monitoring, employee training, and an incident response plan cannot make a business impossible to hack. They can make the difference between a contained incident and a prolonged business crisis.
What Should You Do If You Think Your Business Has Been Hacked?
Act quickly, but do not panic. Contact your IT or cybersecurity provider, contain the incident appropriately, preserve evidence, secure critical accounts, and determine the scope of the compromise. Once the immediate threat is addressed, focus on safe recovery and understanding how the attack happened.
At Digital Sky Solutions, we help businesses in Victoria, Vancouver, and across British Columbia strengthen their IT environments and prepare for cybersecurity incidents before they become emergencies.
Our cybersecurity and managed IT services help businesses put practical safeguards, monitoring, planning, and IT support in place.
If you are unsure how prepared your business would be for a cyberattack, contact us today. We can help you assess your IT environment, identify areas of risk, and develop a practical plan to improve your resilience.


