Jiss Tech insights
Your Small Business Got Hacked: The First 72 Hours
A practical, hour-by-hour recovery order for small businesses after a breach — containment, assessment, restoring from backups, and rebuilding stronger — based on real incident-recovery work.
A client once came to us the morning after a breach: systems locked, staff unable to work, customers asking questions — and no usable backups. Within a week we had rebuilt their systems from scratch and had them back up and running, with stronger security than before. That outcome was possible because the right things happened in the right order. This is the order — including what to do when the backups you were counting on do not exist.
Hour 0–4: Contain, don't clean
- Disconnect affected machines from the network — but do not wipe or "fix" them yet.
- Change passwords for critical accounts (email, banking, admin) from a known-clean device.
- Turn on multi-factor authentication anywhere it is not already on.
- Start a simple log: what you noticed, when, and what you did. It matters later for insurance and legal.
The instinct to immediately reinstall everything destroys the evidence you need to understand how the attacker got in. If you rebuild without knowing the entry point, you are often rebuilding the vulnerability too.
Hour 4–24: Assess the blast radius
With help from someone who does this professionally, work out what was actually touched: which systems, which data, which accounts. Check whether backups are intact and — critically — whether they are recent and restorable. This is also the moment to loop in your cyber insurance carrier if you have one, and to ask counsel whether notification obligations apply. Most states, New Jersey included, have breach-notification requirements when personal data is exposed.
Day 1–3: Restore from backups, not from hope
Recovery that lasts comes from clean systems with the entry point closed. The best case is restoring verified backups. But if you discover your backups are missing, stale, or were reachable by the attacker — as happens far more often than owners expect — recovery means rebuilding from scratch: reconstructing systems and data from whatever clean sources remain, patching what let the attacker in, and tightening account permissions as you go. In the engagement mentioned above there were no usable backups at all; a from-scratch rebuild still had the business running inside a week, and it came back stronger, with monitored, tested backups in place so the next incident — if there is one — is an inconvenience instead of a crisis.
Whatever state your backups are in, do not pay a ransom as your first move. Talk to a professional and, where appropriate, law enforcement first — payment guarantees nothing and marks you as a payer.
The week after: rebuild stronger, not just back
- MFA everywhere, starting with email and remote access.
- Automatic updates for operating systems and the software you actually run.
- Least-privilege accounts — staff get access to what they need, not everything.
- Backups that are automatic, off-site, and restore-tested on a schedule — not assumed.
- A one-page incident plan, so next time the first four hours are calm instead of chaos.
The honest takeaway
Almost every small-business breach we have seen exploited something unglamorous: an unpatched system, a shared password, a backup nobody had tested. The businesses that recover in days rather than months are not the ones with the biggest budgets — they are the ones where backups were real and someone knew the order of operations. If you are reading this on a good day, the cheapest time to prepare is now.
Take the next step
Before or after an incident, we can help
We have rebuilt a hacked business from scratch — no backups — in under a week, and hardened plenty more so they never face that. Tell us where you stand and we will give you a clear next step.