Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

What to Do Before (And After) a Data Breach

What to Do Before (And After) a Data Breach

One of the biggest myths out there related to cybersecurity is that criminals only go after the big enterprises. Why should they care about your small operation, anyway? In reality, cybercriminals love to attack small businesses to take advantage of their weaker security infrastructures. If you’re not careful, this could lead to serious losses for your business stemming from a loss of trust, legal fees, and operational downtime.

Today, we’re going over what you should do before a data breach, as well as what to do afterward, so you can be as prepared as possible for cyberattacks.

What to Do Before a Data Breach

Develop an Incident Response Plan

If you want to be ready for a cyberattack, it starts by building a plan. You need to build an Incident Response Plan (IRP), a physical or digital document that details what happens in the event of a data breach. This includes resources beyond IT, including your legal counsel, any insurance providers, and your head of communications. With all this at your fingertips, you should be able to execute your plan in a second, should anything bad occur.

Implement the 3-2-1 Backup Rule

On the off-chance your business suffers a data breach, you'll want to have backups and restoration procedures in place. We recommend the 3-2-1 rule, where you maintain three copies of your data, on two different media types, with one off-site copy. Keep in mind this is the bare minimum of what you should accept; we also like to add in having an immutable backup that cannot be edited or changed, just for good measure.

What to Do After a Data Breach

Isolate the Affected Systems

Your first thought, in the event of a data breach, should be to contain the threat. Disconnect the device from the Internet and your physical infrastructure, but do not turn the computer off; experts will need to look at the device to see what the hackers were up to, and turning it off could erase vital evidence. Finally, disable remote access and shut down any VPNs or remote desktop protocols.

Conduct a Forensic Investigation

Now that your systems are isolated, it’s time to root out the cause of the breach and take action. We recommend you work with security professionals, like Voyage Technology, to find out how the attacker got in, like an unpatched software vulnerability or a phished password. If you work with us, we’ll also look for which specific files were accessed or exported, as well as how long the hacker was present on your systems and which accounts have been compromised.

Practice Transparency In Your Communication Strategy

A data breach is devastating in its own right, but it can be just as bad for your reputation if you try to cover it up. You need to effectively communicate to your clients and customers that you are not a liability due to your security breach. We recommend you follow a simple framework in your client-facing communication: start with what happened, explain what you are doing to address it, and what your clients should do in their own response.

Reset All Credentials Across the Organization

If a hacker makes it into your infrastructure, they’ll likely try to use a backdoor to break in again. Use the “nuclear” password option and force password changes across the organization, and be sure to log everyone out of all accounts and devices globally. Furthermore, enable multi-factor authentication for all accounts to prevent a secondary breach.

Is your business adequately protected from and prepared for a cyberattack? Voyage Technology can help you develop the appropriate response strategy, but hopefully it doesn’t come to that. Learn more today about how to minimize your risk by calling us at 800.618.9844.

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips IT Services Internet Malware Privacy Workplace Tips Phishing IT Support Google Email Computer Workplace Strategy Small Business Ransomware Backup Collaboration Hosted Solutions Managed Service Users AI Mobile Device Productivity Saving Money Microsoft Quick Tips Passwords Communication Cybersecurity Smartphone Data Backup Disaster Recovery Data Recovery Upgrade Android VoIP Business Management Smartphones Mobile Devices communications Windows Browser Social Media Managed IT Services Microsoft Office Current Events Network Tech Term Internet of Things Remote Miscellaneous Information Training Artificial Intelligence Facebook Holiday Automation Outsourced IT Compliance Gadgets Cloud Computing Covid-19 Managed Service Provider Remote Work Server IT Support Encryption Spam Employee/Employer Relationship Office Windows 10 Business Continuity Data Management Government Bandwidth Windows 10 Virtualization Blockchain Wi-Fi Vendor Business Technology Managed Services Data Security Apps Two-factor Authentication Tip of the week Mobile Office Chrome Mobile Device Management Budget Gmail Voice over Internet Protocol Apple Networking WiFi App Employer-Employee Relationship BYOD Conferencing Password Managed IT Services How To BDR HIPAA Computing Physical Security Applications Information Technology Hacker Access Control Avoiding Downtime Office 365 Marketing Augmented Reality 2FA Retail Storage Bring Your Own Device Healthcare Big Data Operating System Router Risk Management Virtual Private Network Computers Health Help Desk Analytics Website Office Tips Document Management Managed IT Service Excel Firewall Telephone Scam Data loss Remote Workers The Internet of Things Cooperation Social Free Resource Going Green Patch Management Save Money Project Management Windows 7 Remote Monitoring End of Support Vulnerability Vendor Management Microsoft 365 Cybercrime Solutions Customer Service Display Printer Paperless Office Infrastructure Monitoring Windows 11 Data Storage Money Saving Time Supply Chain Humor Word Video Conferencing Managed Services Provider Professional Services Maintenance Virtual Machines Downloads Antivirus Sports Mouse Licensing Safety Administration Entertainment iPhone Vulnerabilities Robot Data Privacy Telephone System Cost Management Images 101 Settings Wireless Printing Content Filtering Multi-Factor Authentication Mobility IT Management Customer Relationship Management YouTube Meetings VPN Cryptocurrency Modem Hacking User Tip Processor Presentation Employees Computer Repair Mobile Security Integration Virtual Desktop Data storage LiFi Wireless Technology Smart Technology Outlook Holidays Machine Learning Screen Reader Hard Drives Writing Distributed Denial of Service Hypervisor Displays Lenovo PowerPoint Service Level Agreement Domains Shopping Virtual Reality Computing Infrastructure Optimization Employer/Employee Relationships Outsourcing Hacks Server Management Scary Stories Private Cloud Identity Identity Theft Smart Tech Refrigeration PCI DSS Fun Navigation Superfish Bookmark Workplace Deep Learning Download Public Speaking Gig Economy Twitter Alerts Internet Service Provider Teamwork Hiring/Firing Lithium-ion battery Error Education Connectivity Regulations Compliance Social Engineering Break Fix Entrepreneur Evernote Paperless Browsers Co-managed IT Upload Remote Computing Memes Net Neutrality Multi-Factor Security SQL Server Technology Care Mobile Computing Social Network Tablet IoT Undo Financial Data Search Dark Web History Business Communications Scams Best Practice Trends Smartwatch Alert IT Procurement Dark Data Google Calendar Azure Hybrid Work Managed IT Customer Resource management Buisness File Sharing Regulations IT solutions Star Wars Telework How To Microsoft Excel Cyber security Tech Human Resources Legal Data Analysis Cables Business Growth Gamification CES Notifications Staff Communitications Application Supply Chain Management Legislation Travel Social Networking Techology Fileless Malware Google Maps FinTech Cortana Term Google Apps IT Maintenance Alt Codes Content IBM Wearable Technology IT Assessment Downtime Unified Threat Management Motherboard Flexibility Comparison Value Business Intelligence Health IT Unified Threat Management Directions Hosted Solution Assessment Organization Permissions Shortcuts Ransmoware Typing Digital Security Cameras Smart Devices Remote Working Network Congestion Specifications Memory Vendors Google Drive User Error Microchip Internet Exlporer Competition Knowledge Fraud Data Breach Google Play Be Proactive Workforce Username Videos Electronic Health Records Point of Sale 5G Black Friday Wasting Time Threats Google Docs Unified Communications Database Experience Trend Micro Security Cameras Workplace Strategies Software as a Service Meta Bitcoin Network Management Running Cable Tech Support IT Technicians User Cookies Monitors Cyber Monday Managing Costs Amazon Google Wallet Proxy Server SSID Tactics Hotspot eCommerce Surveillance Virtual Assistant Outsource IT Windows 8 IP Address Laptop Websites Mirgation Nanotechnology Virtual Machine Environment Media Drones Medical IT SharePoint Addiction Reviews Electronic Medical Records Language Development Transportation Small Businesses Management Halloween Chatbots Recovery

Blog Archive