Cybersecurity
Suspected Data Breach: What to Do First
A practical first-day response plan for small businesses that think an account, device, or business system has been compromised.

The first hour is about control, not certainty
A suspicious sign-in alert, a vendor message about unusual activity, a lost laptop, or files that suddenly cannot be opened can all make an ordinary day feel chaotic. The right first response is not to decide immediately whether it is a reportable breach. It is to prevent a possible problem from spreading while preserving enough information to understand what happened.
Recent cybersecurity incidents have shown how an intrusion can affect operations beyond the system initially targeted. Boston Scientific disclosed in August 2026 that a cybersecurity incident disrupted access to certain operating systems and business applications, including manufacturing and order processing. Small businesses should not assume that being smaller makes every event smaller. One compromised email or administrator account can touch invoices, cloud files, customer messages, and connected software quickly.
1. Contain the situation without destroying evidence
If a computer appears compromised, disconnect it from Wi-Fi or the network. Do not turn it into a long investigation by clicking through alerts, running unfamiliar cleanup tools, or deleting suspicious files. If an account is involved, use a known-clean device to change the password, revoke active sessions where possible, and turn on multi-factor authentication if it was not already enabled.
Write down what was noticed, when it was noticed, which person or account was involved, and what actions were taken. Save suspicious emails, screenshots of alerts, and unusual messages. This basic record helps your IT provider, insurer, legal adviser, or law enforcement understand the timeline without asking staff to reconstruct it from memory later.
2. Call the people who can make the next decision
Your response list should name the business owner, an IT contact, cyber insurance carrier, bank or payment processor contact, and legal adviser if your business has one. In a real event, staff should know exactly who has authority to shut down access, contact a vendor, approve spending, or communicate with customers. That prevents the very common problem of several people taking separate actions without a shared picture.
The FBI and CISA advise organizations to report ransomware incidents and to preserve relevant information. Their guidance also emphasizes practical protections such as multi-factor authentication and timely patching. Treat a report as a request for help, not an admission of fault. Early information can make containment and recovery more effective.
3. Protect money-moving accounts first
Prioritize email, banking, payroll, payment processors, domain accounts, cloud administrators, and any account that can reset other passwords. Review forwarding rules in email, recently added users, connected applications, administrator roles, and changes to payment details. Business email compromise often succeeds because a criminal quietly monitors messages or changes where money is sent, not because a screen announces a dramatic attack.
Ask employees to verify any sudden payment change, new bank account, gift-card request, or request for a multi-factor code through a known, separate contact method. A phone call to a familiar number is dull, which is precisely why it works. Do not use the phone number in the suspicious email.
4. Be careful with customer and employee information
A compromise does not automatically mean every record was exposed. Before you notify people or make a public statement, work with qualified advisers to determine what systems were involved, what data may have been accessed, and which obligations apply. Texas businesses may have notification duties when certain sensitive personal information is acquired by an unauthorized person, and the details depend on the facts. The Texas Attorney General provides breach reporting information, but it is not a substitute for legal advice on a specific incident.
Be direct with affected people once you know what you can truthfully say. Explain what happened, the information involved, steps already taken, and practical measures they can take. Avoid minimizing the event, but do not speculate. Clear and accurate communication protects trust better than a fast message that later has to be corrected.
5. Restore deliberately
Before reconnecting a device or restoring a backup, make sure the original route into the environment is closed. That may mean patching software, removing a malicious inbox rule, resetting credentials, replacing a router password, or reviewing an external vendor connection. Restore priority systems first, validate that they work, then bring the rest back in a controlled order.
This is why tested backups matter. The CISA ransomware guidance stresses maintaining offline or otherwise protected backups and testing restoration procedures. A backup that has never been restored is an assumption, not a recovery plan. OnQuest can help review backup coverage and the order in which your business needs systems returned.
6. Turn the event into a tighter routine
After the immediate work settles, hold a short review. What allowed the issue to reach the business? Which alert was missed? Which person did not know whom to call? Which account had more access than it needed? The goal is not blame. It is to make the next incident less likely and less disruptive.
The most valuable fixes are often basic: individual accounts, multi-factor authentication, updates, endpoint protection, a password manager, limited administrator rights, a clean offboarding routine, and staff who feel comfortable asking before they act. These practices also make it easier to handle vendor outages and day-to-day device problems without creating extra risk.
How OnQuest helps
OnQuest provides cybersecurity support for small businesses that want more confidence around email, devices, accounts, awareness training, and recovery planning. We help turn broad security advice into routines your team can realistically keep up with.
If an account, device, or business system is showing signs of compromise, use the fastest available support route for your business. If you want to reduce the chance of being caught unprepared, book a free IT Health Check and start with the systems that would create the biggest disruption.
Sources: Boston Scientific's incident update, CISA's ransomware guide, and the Texas Attorney General's data security breach reporting guidance.
Frequently asked questions
What should a small business do first during a technology outage?
Confirm which service is affected, use the approved backup process, notify the people who need to know, and record what happened. Do not create unapproved workarounds that expose business or customer information.
When should I call IT support about a suspicious account or device?
Call as soon as you notice unusual access, a suspicious payment request, unexpected password-reset activity, ransomware symptoms, or a lost device that had business access. Early action gives you more options.

