Something is wrong right now.
If your email has been taken over, your files are encrypted, or money has left the building, call. Everything on this page is written for the person who has to act tonight and is not an IT specialist.
Call now 833-DNS-ONITThe next ten minutes
Do these before you call anyone, including us. They take minutes and they limit the damage.
- 01
Do not delete anything
Not the phishing email, not the strange login alert, not the forwarding rule you just found. It is evidence, and both the investigation and your insurance claim depend on it. Screenshot it. Do not delete it.
- 02
Change the password and end the sessions
A password change on its own does not remove an attacker who already has a valid session. Somebody has to sign the account out everywhere as well. If you do not know how, that is the first thing we will do.
- 03
Stop the money before you stop anything else
If an invoice was paid or bank details were changed, call your bank now and ask for a recall. Recovery odds fall by the hour and this is the one step that cannot wait for a technician.
- 04
Tell your people, briefly
One message: do not act on emailed payment requests until further notice, and report anything odd. Most second-stage losses happen because the rest of the organisation carried on as normal.
What happens when you call
No triage queue and no ticket number. You get an engineer, and the first hour is about stopping it, not explaining it.
The first hour
Contain. We cut the attacker's access: sessions revoked, credentials reset, malicious mail rules and app consents removed, affected machines isolated from the network. We are not investigating yet. We are closing the door.
The first day
Establish what happened and what was reached. Which account, when, from where, what was read, what was sent, whether anything was downloaded. You get told what we know and what we do not, in plain language, as we learn it.
The first week
Close the way in, and put in what would have caught it. That usually means conditional access, blocking legacy sign-in methods, tightening who can consent to applications, and monitoring that would have raised this on day one. Then a written summary you can give a board, an insurer or an auditor.
If you have cyber insurance, call them early
Calling your insurer early matters more than most people realise. Cyber policies commonly require you to notify the carrier promptly, and many require that forensics and breach counsel come from their approved panel. Bringing in your own people first, however capable, can reduce or void what the policy pays.
So make that call early, and do not let it delay containment. The two are not in conflict: shutting an attacker out is not the same as starting a forensic investigation, and no carrier expects you to leave the door open while you find your policy number.
We work alongside carriers and their panel firms regularly. If your insurer appoints a forensics team, we support them with access, logs and history. We do not compete with them.
If this started in email, and it usually does
The most common incident we see is not ransomware. It is a session token stolen through a convincing sign-in page, which lets an attacker straight past multi-factor authentication because they inherit an already-approved session. Your MFA was on and it did not help.
What that looks like from the inside: a mailbox rule forwarding or deleting invoices, an application you never approved holding permission to read mail, sign-in attempts from somewhere you have no staff, and often a payment request that looks exactly like the ones you normally get.
Containment is specific and it is not just a password reset. Revoke the sessions and refresh tokens, audit and strip mail rules, review every application consent granted to that account, check which MFA methods were registered and when, and block the legacy sign-in protocols that skip modern controls entirely. The steps are the same on Microsoft 365 and Google Workspace; only the console changes.
You do not have to be a client
You can call us in an active incident whether or not we manage your technology, and we would rather you did than lose an hour deciding.
Being straight about how it works: an engagement starts with a paid emergency onboarding. We need access, an understanding of what you run, and our tooling in place before containment is anything more than guesswork. It is quick, it happens at the same time as the first response, so nothing waits on it, and we will tell you what it costs before you commit.
There is no requirement to become a managed client afterwards. Plenty do. Plenty go back to their own arrangements with a written account of what happened and what to fix, which is a perfectly good outcome.
If you are reading this because something is happening right now, stop and call. The page will still be here afterwards.
833-DNS-ONIT