If something about your business technology feels wrong today, that instinct is worth taking seriously. Whether it is a computer behaving strangely, an employee flagging an unfamiliar login, or a client who received a suspicious email from your address, the worst possible response is to convince yourself it is probably nothing and wait.

How you respond in the first hour can significantly affect the outcome. Here is exactly what to do.
1. Do Not Touch Anything Yet
Before taking any action, call your IT provider. Deleting files, wiping devices, or attempting to fix things yourself before anyone has assessed the situation can destroy evidence that investigators need and make recovery considerably harder. If you do not have an IT provider you trust, that conversation starts at ekaru.com.
2. Disconnect Affected Devices From the Network
If you have identified a compromised device, unplug its ethernet cable or disable its Wi-Fi connection. Do not turn it off entirely as this can destroy forensic data, but isolating it from the network prevents the threat from spreading. If you are not sure which device is affected, your IT provider can help identify the scope before you start disconnecting things.
3. Change Your Passwords Immediately
From a clean unaffected device, change passwords on your most critical accounts starting with email, then financial accounts, then core business applications. Enable multi-factor authentication on everything that supports it. Avoid doing this from any device you suspect may be compromised.
4. Identify What Was Accessed
Once the immediate threat is contained, you need to understand what the attacker actually reached. Which systems, what data, and how long they had access are all questions that shape everything that follows including your legal obligations.
For small businesses in Massachusetts handling personal information, a breach may trigger notification requirements under 201 CMR 17.00, the Massachusetts Data Security Law. HIPAA, PCI, and other industry regulations may impose additional obligations with their own deadlines. Getting this wrong adds legal and financial exposure on top of the breach itself.
5. Notify the Right People
Your IT provider and a legal advisor should both be involved in deciding who to notify and when. Depending on the incident you may need to contact affected individuals, state regulators, law enforcement, and your cyber insurance carrier. Report cybercrime at ic3.gov and contact your insurer as early as possible since most policies require prompt notification and provide access to forensic and legal resources that reduce your costs significantly.
6. Preserve the Evidence
Do not delete anything that triggered your concern. Suspicious emails, login alerts, ransomware messages, and unusual account activity are all evidence. Screenshot anything unusual and let your IT provider preserve forensic data properly before anything is removed or overwritten.
7. Understand How It Happened
Once the crisis is behind you, understanding how the attacker got in is the most important question to answer. A phishing email, a compromised password, an unpatched vulnerability, or a former employee whose access was never removed are all common entry points. Closing that gap is what prevents the same incident from happening again.

What Happens When Businesses Wait
The damage from a cyberattack compounds with time. An attacker inside your network for days or weeks has had the opportunity to steal credentials, exfiltrate data, and position malware for later deployment. For small businesses in greater Boston the average cost of a data breach approaches $254,000, and that figure does not capture lost clients, reputational damage, or the operational disruption that continues long after the technical issues are resolved.
The businesses that recover are the ones that acted quickly and had preparation already in place. The ones that do not recover waited too long or discovered too late that their backup could not actually restore their data.
What To Do Right Now
The best time to prepare for a breach is before one happens. That means continuous monitoring, a tested backup plan, a basic incident response process, and cyber insurance that reflects your actual risk. Create a culture of cybersecurity awareness in your company so people are encouraged to "see something say something" rather than fearing "getting in trouble". Often its not obvious there's a problem immediately, so open communication is key. We've seen many recent incidents of Business eMail Compromise (BEC). The sooner someone raises the flag - "I think I clicked on something bad", the faster you'll get to remediating the problem.
At Ekaru we help small businesses across Westford, Acton, Chelmsford, Lowell, and greater Boston respond to cybersecurity incidents, recover from data loss, and build the foundations that reduce risk before something forces the conversation.
If you think something may have already gone wrong, call us today.