PITOWINGS — Secure Everywhere
All articles
Forensics6 May 2026·6 min read

You've Been Hacked — The First 5 Steps to Take Right Now

A calm, practical survival guide for the first hour of a security incident.

By PITOWINGS Team

ForensicsPITOWINGS

Discovering that your business has been hacked is frightening, and the instinct to panic — or to immediately wipe everything — often makes things worse. The first hour matters enormously. Here are the five steps our forensics team recommends, in order.

1. Contain — but do not destroy

Isolate affected systems from the network to stop the attacker spreading: disconnect network cables, disable Wi-Fi, or move a machine to a quarantine VLAN. Do not power off or wipe systems, and do not start deleting files. Powering down can erase crucial evidence held in memory, and premature clean-up can destroy the trail that reveals how the attacker got in — and whether they are still inside.

2. Preserve the evidence

Everything you touch should be logged. Note the time you noticed the incident, take photographs or screenshots of what you see, and preserve system logs before they roll over and disappear. If you have the capability, capture forensic images and memory dumps of affected devices. This evidence is what lets investigators trace the root cause — and it is what regulators, insurers and courts will later ask for.

The most expensive mistake in a breach is not the attack itself — it is destroying the evidence that would have told you how far it spread.

3. Assess the scope

Try to understand what has actually happened before reacting publicly. What systems are affected? Was personal or financial data accessed? Is the attacker still active? Resist the urge to guess — early assumptions are often wrong, and forensic analysis frequently reveals the breach began weeks before it was noticed.

4. Notify the right people

Inform your internal leadership and, if you have one, your incident-response partner. Depending on your sector and the data involved, you may have legal obligations to report — for example to CERT-In, to SEBI within its required window, or to affected individuals under the DPDP Act. Handling notification correctly protects you legally; getting it wrong can add penalties on top of the breach.

5. Recover and learn

Only rebuild from known-clean backups once you understand how the attacker got in — otherwise you may restore the very vulnerability they used. After recovery, run a post-incident review: what was the root cause, what would have caught it earlier, and what needs to change. Every incident, handled well, makes the next one far less likely.

Be ready before it happens

The businesses that survive breaches well are the ones that prepared. PITOWINGS provides both rapid incident response when an attack is underway and proactive forensic readiness — so you have a tested plan, preserved logs and a team on call before you ever need them.

P

PITOWINGS Team

Predictive cybersecurity experts — VAPT, SOC, forensics & J.I.M.M.Y.

Keep reading

Ready to make your business un-hackable?

Book a free, no-obligation consultation. We'll review your setup, explain your biggest risks in plain language, and show you exactly how to fix them.