You've Been Hacked — The First 5 Steps to Take Right Now
A calm, practical survival guide for the first hour of a security incident.
By PITOWINGS Team
Discovering that your business has been hacked is frightening, and the instinct to panic — or to immediately wipe everything — often makes things worse. The first hour matters enormously. Here are the five steps our forensics team recommends, in order.
1. Contain — but do not destroy
Isolate affected systems from the network to stop the attacker spreading: disconnect network cables, disable Wi-Fi, or move a machine to a quarantine VLAN. Do not power off or wipe systems, and do not start deleting files. Powering down can erase crucial evidence held in memory, and premature clean-up can destroy the trail that reveals how the attacker got in — and whether they are still inside.
2. Preserve the evidence
Everything you touch should be logged. Note the time you noticed the incident, take photographs or screenshots of what you see, and preserve system logs before they roll over and disappear. If you have the capability, capture forensic images and memory dumps of affected devices. This evidence is what lets investigators trace the root cause — and it is what regulators, insurers and courts will later ask for.
The most expensive mistake in a breach is not the attack itself — it is destroying the evidence that would have told you how far it spread.
3. Assess the scope
Try to understand what has actually happened before reacting publicly. What systems are affected? Was personal or financial data accessed? Is the attacker still active? Resist the urge to guess — early assumptions are often wrong, and forensic analysis frequently reveals the breach began weeks before it was noticed.
4. Notify the right people
Inform your internal leadership and, if you have one, your incident-response partner. Depending on your sector and the data involved, you may have legal obligations to report — for example to CERT-In, to SEBI within its required window, or to affected individuals under the DPDP Act. Handling notification correctly protects you legally; getting it wrong can add penalties on top of the breach.
5. Recover and learn
Only rebuild from known-clean backups once you understand how the attacker got in — otherwise you may restore the very vulnerability they used. After recovery, run a post-incident review: what was the root cause, what would have caught it earlier, and what needs to change. Every incident, handled well, makes the next one far less likely.
Be ready before it happens
The businesses that survive breaches well are the ones that prepared. PITOWINGS provides both rapid incident response when an attack is underway and proactive forensic readiness — so you have a tested plan, preserved logs and a team on call before you ever need them.
PITOWINGS Team
Predictive cybersecurity experts — VAPT, SOC, forensics & J.I.M.M.Y.
Keep reading
What is VAPT? A Simple Guide for Indian Businesses (2026)
A simple, jargon-free guide to Vulnerability Assessment and Penetration Testing — what it is, when you need it, and what to expect.
Read more →SEBI CSCRF Compliance: A Practical Checklist for Regulated Entities
A clear checklist for regulated entities working through SEBI's Cybersecurity and Cyber Resilience Framework.
Read more →In-House SOC vs Managed SOC: A Cost Comparison for Indian SMEs
Which model actually makes sense for Indian SMEs — and how to decide.
Read more →