HOW TO RECOVER FROM DATA SECURITY BREACHES, DATA LOSS OR MALWARE ATTACKS

You KNOW you could have / should have done more to protect your business data… but now it's too late and your computers have been compromised.

What should you do in the event of a data security breach?

1. CALL IT DATA SECURITY PROFESSIONALS ASAP!

Just like a fire or medical emergency, time is of the essence. The attack may still be underway or causing further damage.

  • In the case of a virus or malware, the more people who open the email, the more computers will be infected.
  • Hackers can continue downloading files as long as they have open access. Less than 48 hours after a breach, the attacker will have control of a network – you need to act fast.
  • If the threat is coming from inside the building (an employee or contractor who either inadvertently or with ill intent caused the breach), you'll want your IT team to be able to clearly see the source of the issue.

You don't want a junior IT guy giving it his best shot. If you don't have an experienced IT partner, NOW is the time to find one! (Note, however, that just like calling 911 to summon a helicopter to medically evacuate you off a cliff and into to an emergency room, finding an IT partner during a data security crisis is likely to be both difficult and expensive.)

The risk here is that if you have under-trained IT personnel panicking and changing settings, it may be difficult for your IT team to understand what really happened and diagnose the root cause of the issue. Don't make the problem any worse than it is. Call in IT Professionals.

2. Assess and contain the damage.

Your IT professionals and senior leadership team need to set aside blame (at least for now) and be in tight communication about what happened and how to proceed in fixing the data security breach.

Hopefully you have a disaster recovery or business continuity plan in place, along with documentation of your passwords and backup of all your systems.

Your damage control team needs to decide:

  1. Is the breach contained?
  2. How severe is the damage?
  3. What steps do we need to take now?
  4. Who needs to know? If sensitive data was exposed, you're likely legally required to notify those who are potentially impacted and/or government agencies.
  5. How can we prevent this from happening in the future?

3. Take data restoration steps.

Every situation is unique. Some actions need to be taken immediately, while others may happen over the coming days, weeks and months. Depending on what happened, restoration from a data security breach could mean:

  • Restoring files from backup
  • Changing all passwords
  • Taking a system offline until security updates can be applied
  • Paying the ransom on the ransomware (which is a terrible idea, for so many reasons!)

4. Communicate.

First to employees and then to anyone affected outside your organization, you need to clearly communicate:

  • What happened
  • How you're fixing the issue
  • Any steps those impacted need to do to protect themselves

5. Get committed to data security.

Small businesses are not immune from cybersecurity attacks. With fewer resources to fight and recover from a data security breach, it's even more important for you to Integrate security into your platform. One component of our data security offerings is to use Microsoft 365 for:

  • Identity & access management
  • Threat protection
  • Information protection
  • Security management
  • Device and application management

We also believe strongly in user data security training.

Many employees share passwords, not considering the data security ramifications. In over 63% of data breaches, attackers gain access through weak, default, or stolen user credentials.  Your technology and people need to work together to keep your business protected from malicious cybersecurity attacks.

Beyond user training, there are a few other ways you can safeguard your business:

  • Multi-factor authentication
  • Leaked credential reporting and monitoring
  • Computer firewalls
  • Routine backup and recovery procedures
  • Regularly applying security updates

Microsoft 365 for Data Breach Recovery

One of the solutions we use in our data security practice is Microsoft 365, which has all the perks of Office 365, plus advanced security and device management tools. Microsoft 365 helps us both with remote network monitoring, but also for data breach recovery.

Here's some of what Microsoft 365 can doafter you've been breached:

  • Automatically investigate and mend endpoint threats
  • Recommend what to investigate and remediate
  • Investigate company-wide emails to remediate threats
  • Visualize a hacker's lateral movement
  • Recover OneDrive files
  • Remove ransomware

Call Us for Data Breach Prevention

We don't want to be your 911 IT emergency call. We want to be your day-to-day IT partner who keep your IT systems health and your systems secure with IT services like:

  • Continually monitoring network traffic for anomalies
  • Maintaining backups and testing restore procedures
  • Having a "red book" of system admin credentials and vendor contact information
  • Enforcing IT policies and procedures
  • Keeping hardware and software up-to-date

Don't wait until it's too late – give us a call today – 586.263.1775.

Frequently Asked Questions

What is the most common cause of data loss?

The most common cause of data loss is hardware failure – make sure you're always backing up your hardware! Other causes include; human error, software corruption, theft, and viruses.

What happens when there is a data breach?

A data breach puts ALL of your personal and financial records at risk. This makes you vulnerable to identify theft, compromises customer data, compromises employee data, loss or risk of intellectual data, and virus attacks.

How to protect yourself after a data breach?

Take data restoration steps:
1. Restore files from backup
2. Change all passwords
3. Take systems offline (if needed) until security updates can be added
4. Integrate security into your platform.

How serious is a data security breach?

A breach in your hardware will always be serious. It can lead to destruction, alteration, loss, or access to all personal data. Assessing the problem ASAP will lessen the blow.

For the last 20+ years, Ryan J Schave has owned and operated Eclipse Consulting, a technology consulting firm located in Metro Detroit Michigan. As a strategic IT thinker with a programming background, he looks for innovative and affordable ways for growing businesses to leverage technology to work more efficiently and profitably.