I’ve suffered a cyber security breach. What should I do?

A pair of spectacles rests in front of a computer screen displaying colourful programming code and technical diagrams, hinting at a recent cyber security breach with the code reflected clearly in the lenses.

IIf you believe your organisation has suffered a cybersecurity breach, you need to act quickly and deliberately. The first 24 hours matter more than any security tooling you buy later.

This guide explains exactly what to do, in what order, and why.

Step 1: Confirm whether this is a real incident (first 30 minutes)

Before taking drastic action, establish whether something has actually gone wrong.

Look for:

  • Login alerts you do not recognise
  • Unexpected password resets or MFA prompts
  • Accounts locked or behaving oddly
  • Devices showing unusual behaviour or performance issues
  • Reports from staff that “something feels off”

Action:

  • Identify which user or device triggered concern
  • Note the time and symptoms
  • Do not reset passwords or wipe devices yet

If you are unsure, assume caution and move to containment.

Step 2: Contain the issue without destroying evidence (30 to 90 minutes)

Your goal is to stop spread, not to fix everything immediately.

Do this:

  • Isolate affected devices from the network if possible
  • Temporarily disable compromised user accounts
  • Pause remote access or VPN connections if they are involved
  • Preserve logs and device state

Do not do this (yet):

  • Do not wipe machines
  • Do not reimage devices
  • Do not rotate every password across the business
  • Do not uninstall security tools

Those actions can erase forensic data and make it harder to understand what happened.

Step 3: Establish the scope of the breach (1 to 4 hours)

Now you need answers, not assumptions.

Confirm:

  • Which users were affected
  • Which devices were involved
  • What systems were accessed
  • Whether data was viewed, changed, or extracted
  • Whether the threat is still active

For Apple environments, this usually involves reviewing:

  • Apple Business Manager activity
  • MDM logs and device compliance
  • Identity and access logs
  • Endpoint protection alerts

This is where generic MSPs often struggle. Apple environments require Apple-specific visibility.

Step 4: Decide who needs to know

Not every incident requires public disclosure, but silence can create risk.

You should determine:

  • Whether staff need instructions or restrictions
  • Whether clients or partners are impacted
  • Whether regulatory notification may be required

Communicate facts only. Avoid speculation. Set expectations for updates.

A short, clear message is better than a long, uncertain one.

Step 5: Close the security gap

Once the immediate threat is controlled, fix what allowed it to happen.

Common root causes include:

  • Over-permissioned user accounts
  • Poor device enrollment or unmanaged Macs
  • Inconsistent MDM configuration
  • Identity systems not fully enforced
  • Security tools designed for Windows, not macOS

This is where most organisations fall down. They treat the symptom and leave the structure untouched.

The fix should reduce future risk, not just patch the current incident.

Step 6: Stabilise and rebuild with intent

A properly handled incident should leave you stronger than before.

That usually includes:

  • Standardised Apple device management
  • Clear access policies by role
  • Improved monitoring and alerting
  • A documented incident response plan

Security should feel calm and predictable, not reactive.

If this is happening right now…

If you are actively dealing with a suspected breach or feel out of your depth, stop and get support.

Dr Logic provides incident response and recovery for Apple-first organisations, helping you stabilise the situation quickly and rebuild with confidence.

We focus on:

  • Apple-native security
  • Calm, structured response
  • Long-term resilience, not panic fixes

If this is happening right now, contact Dr Logic for immediate guidance. You may also like to save a copy of our quick reference sheet and share it with your team (in the hopes that you never have to use it!)

A man with light brown hair, glasses, and a beard smiles at the camera. He is wearing a black shirt with the logo “DR Logic.” The background shows tall, modern glass buildings.
Shaun

CTO

Shaun is Chief Technology Officer at Dr Logic, overseeing the technical direction of the business and the infrastructure that underpins client environments. He brings hands-on experience across Apple device management, cloud architecture, and enterprise IT strategy, and his articles focus on the technology decisions that help growing businesses scale securely and efficiently.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.