What to Do When Your Business Gets Hacked

Man on a corded phone at a wooden desk, laptop showing a bar chart.

What to Do When Your Business Gets Hacked

Oklahoma law requires any business that exposes a resident’s personal information in a data breach to notify the state Attorney General’s office without unreasonable delay, a deadline most Broken Arrow and Tulsa business owners only learn about after they’ve already been hacked. That legal clock starts the moment a breach is discovered, running in parallel with the technical response, which is exactly why knowing what to do when your business gets hacked, calmly and in the right order, matters more than most owners realize until the moment it actually happens. A locally owned distribution company in the Tulsa area learned this firsthand when it opened its shared drive one morning to find every folder renamed with a ransom note instead of a file extension. The technical damage was only half the problem; knowing what came next was the other half.

The single biggest mistake in that first window is panic-driven action: shutting down every computer, wiping a machine to “clean it,” or going quiet and hoping the problem resolves itself. None of those instincts help, and some of them destroy evidence you will need later.

The First Hour: Contain Without Destroying Evidence

Disconnect affected devices from the network rather than powering them off. Unplug the ethernet cable or disable Wi-Fi, but leave the machine running. Powering down can destroy evidence in memory that a forensic investigation would otherwise be able to use. Isolate at the network level too, disconnecting affected systems from shared drives, servers, and cloud accounts so the attack cannot spread further while you assess the scope.

Switch to a communication channel the attacker cannot see. If email or chat systems may be compromised, coordinate your response by phone or in person, not through the same systems that might be watched.

Assemble Your Response and Assess the Damage

Identify who is handling what: someone managing the technical response, someone managing communication with staff and customers, and someone tracking the legal and notification requirements. A business without a dedicated IT security team should have an outside provider they can call immediately, rather than figuring out who to call while the clock is running.

Once systems are contained, assess what was actually affected. Which systems were compromised. What kind of data was involved, especially anything involving customer information, financial records, or employee data. When the attack likely started, based on unusual login times, unfamiliar user accounts, or file modification timestamps. CISA’s stop ransomware guide outlines this kind of detection and analysis phase as the foundation for everything that follows, since acting on incomplete information about scope often leads to reopening systems too early.

Remove the Threat and Begin Recovery

Once the scope is understood, remove the malicious access: reset every password with any connection to the affected systems, not just the obviously compromised accounts, and revoke any suspicious active sessions or API tokens. Patch the vulnerability that allowed the breach, whether that was an unpatched piece of software, a phished credential from an employee who fell for one of the phishing attacks that cause the majority of these incidents, or an exposed remote access port. Only then begin restoring from a backup you know predates the attack, ideally one you have already tested and trust. Restoring from a backup taken after the breach began can simply reintroduce the same compromise.

Who You Need to Notify, and When

Notification obligations depend on what data was involved and where your customers live. Oklahoma businesses fall under state requirements, and the Oklahoma breach law requires notifying the Attorney General’s office without unreasonable delay when a breach exposes residents’ personal information. The FTC’s breach response guide lays out the broader federal expectations: securing operations first, fixing the vulnerabilities that allowed the breach, and then notifying affected individuals, law enforcement, and any relevant regulators, generally in that order.

Consider reporting the incident to the FBI’s Internet Crime Complaint Center as well. The internet crime report published by IC3 recorded 880,418 complaints and more than 12.5 billion dollars in losses in a single year, and business email compromise alone accounted for nearly 2.9 billion of that figure, which shows how common and how costly these incidents have become even outside major cities.

A short list of who to contact keeps the notification process from being missed under pressure.

  • The Oklahoma Attorney General’s office, if Oklahoma residents’ personal data was exposed.
  • The FBI’s Internet Crime Complaint Center, to formally report the incident.
  • Your cyber insurance provider, if you carry a policy, as early as possible in the process.
  • Affected customers or clients, once the scope is understood and legal counsel has reviewed the notification language.
  • Your banking or payment processor, if financial account access may have been compromised.

Why Choose CamTech for Incident Response

Recovering from a hack is not the moment to be evaluating a new IT provider for the first time. CamTech’s cybersecurity service includes the pieces that actually change how fast a business recovers: dark web scanning that flags exposed credentials before they are used in an attack, firewall and DNS filtering that limit how far an intrusion can spread, and phishing simulation training that reduces how often an employee clicks the link that starts all of this in the first place.

As a Microsoft Gold Partner serving Broken Arrow and the wider Tulsa region, CamTech’s team has walked local businesses through exactly the kind of morning that distribution company had, and the difference between a bad week and a bad day usually comes down to whether someone already knew the containment steps cold before the attack happened. That preparation is what the FTC’s small business cybersecurity guidance points to as well: businesses that already have a plan and a provider on call recover measurably faster than those improvising for the first time mid-incident. If your business does not currently have an IT provider who could answer a call like that at 7 AM or 9 PM, that is worth fixing before you need it.

If your business has been hacked right now, do not wait. Contact us today for immediate help, or reach out for a free consultation on getting your incident response plan in place before the next attempt.

What to Do in the First Hour vs the First Week

Timeframe Priority Action Why It Comes First
First hour Disconnect affected devices without powering them off Stops the spread while preserving evidence
First few hours Assemble your response team and assess scope Prevents acting on incomplete information
Same day Reset passwords and patch the vulnerability Removes the attacker’s access before recovery starts
Within days Restore from a verified, pre-breach backup Avoids reintroducing the same compromise
First week Notify regulators, affected customers, and law enforcement Meets legal obligations and rebuilds trust

Each action in this table follows the same order laid out in the sections above: containment first, assessment second, removal of the threat and recovery third, and formal notification once the scope and legal obligations are clear.

Conclusion

The businesses that recover fastest from being hacked are not the ones that never get attacked, they are the ones that already know the order of operations before it happens: contain without destroying evidence, assess the real scope, remove the threat, restore from a trusted backup, and notify the right people. For a Broken Arrow or Tulsa business, having that plan in place, and a team who can execute it at any hour, is the difference between a bad day and a bad year. Reach out to CamTech for a free consultation, whether you are dealing with an incident right now or want to be ready before the next attempt.

Whether you’re dealing with an active incident or want to be ready before one happens, contact CamTech today for a free consultation.

 

Common Questions About Getting Hacked

 

Should I turn off my computer if I think it was hacked?

 

No, disconnect it from the network instead of powering it off. Turning off the device can erase evidence in memory that would otherwise help identify how the attack happened and what it accessed.

Do I have to report a hack to the police or a government agency?

 

It depends on what was compromised. If personal information about Oklahoma residents was exposed, state law generally requires notifying the Attorney General’s office, and reporting the incident to the FBI’s Internet Crime Complaint Center is also recommended even when not strictly required.

How do I know if my business data was actually stolen versus just accessed?

 

This usually requires a technical investigation of system logs, file access timestamps, and network traffic to determine what an attacker actually viewed, copied, or exported, rather than simply what they had the ability to reach.

Can I restore from backup immediately after being hacked?

 

Only after removing the attacker’s access and confirming the backup predates the breach. Restoring too early, or from a backup that already contains the compromise, can bring the same vulnerability right back online.

How long does it typically take to recover from a business hack?

 

Recovery time varies widely based on the scope of the attack and how prepared the business was beforehand. A business with tested backups and a documented response plan typically recovers in days, while one without either can be down for weeks.

 

No Comments

Sorry, the comment form is closed at this time.