🆘 Emergency Response Guides

Incident Response Center

When something goes wrong, you need clear steps — not panic. These guides walk you through exactly what to do, who to call, and how to recover. Print them. Bookmark them. Hope you never need them.

Emergency Quick Reference

Ransomware?

Disconnect network cable immediately. Do not pay without consulting law enforcement.

Website hacked?

Enable maintenance mode. Change all admin passwords from a clean device.

Phishing link clicked?

Disconnect device. Reset passwords. Scan for malware. 15-minute window.

Ransomware Attack — Complete Response Guide

High Urgency

Your screens just locked and there's a ransom note. Step-by-step: isolate infected devices, assess the damage, decide whether to pay, and restore from backups.

1. Disconnect from network immediately 2. Identify the ransomware strain 3. Check backup integrity 4. Report to authorities 5. Restore & harden systems

Website Hacked or Defaced — Recovery Process

High Urgency

Your website is showing strange content, redirecting to spam, or flagged by Google. How to take it offline, clean the infection, restore, and prevent reinfection.

1. Take site offline or enable maintenance mode 2. Scan for malware & backdoors 3. Restore from clean backup 4. Update all plugins/themes/core 5. Request Google review

Employee Clicked a Phishing Link — Now What?

Medium-High Urgency

A team member just clicked a suspicious link or opened an attachment. The clock is ticking. What to do in the first 15 minutes to contain the damage.

1. Disconnect device from network 2. Reset all passwords from a clean device 3. Scan for malware 4. Check for data exfiltration 5. Report & document

Customer Data Breach — Notification & Compliance

High Urgency

Customer data was exposed. Who do you need to tell, how fast, and in what format? Breach notification laws by jurisdiction, plus notification letter templates.

1. Contain the breach immediately 2. Document exactly what was exposed 3. Determine legal notification requirements 4. Notify affected customers 5. Report to regulators

Third-Party Vendor Data Breach

Medium Urgency

A vendor or supplier you share data with was breached. Assess your exposure, activate contractual protections, and protect your customers.

1. Confirm breach scope with vendor 2. Identify what data of yours was exposed 3. Review vendor contract & SLA 4. Notify your customers if required 5. Reassess vendor security requirements