IIf you believe your organisation has suffered a cybersecurity breach, you need to act quickly and deliberately. The first 24 hours matter more than any security tooling you buy later.
This guide explains exactly what to do, in what order, and why.
Step 1: Confirm whether this is a real incident (first 30 minutes)
Before taking drastic action, establish whether something has actually gone wrong.
Look for:
- Login alerts you do not recognise
- Unexpected password resets or MFA prompts
- Accounts locked or behaving oddly
- Devices showing unusual behaviour or performance issues
- Reports from staff that “something feels off”
Action:
- Identify which user or device triggered concern
- Note the time and symptoms
- Do not reset passwords or wipe devices yet
If you are unsure, assume caution and move to containment.
Step 2: Contain the issue without destroying evidence (30 to 90 minutes)
Your goal is to stop spread, not to fix everything immediately.
Do this:
- Isolate affected devices from the network if possible
- Temporarily disable compromised user accounts
- Pause remote access or VPN connections if they are involved
- Preserve logs and device state
Do not do this (yet):
- Do not wipe machines
- Do not reimage devices
- Do not rotate every password across the business
- Do not uninstall security tools
Those actions can erase forensic data and make it harder to understand what happened.
Step 3: Establish the scope of the breach (1 to 4 hours)
Now you need answers, not assumptions.
Confirm:
- Which users were affected
- Which devices were involved
- What systems were accessed
- Whether data was viewed, changed, or extracted
- Whether the threat is still active
For Apple environments, this usually involves reviewing:
- Apple Business Manager activity
- MDM logs and device compliance
- Identity and access logs
- Endpoint protection alerts
This is where generic MSPs often struggle. Apple environments require Apple-specific visibility.
Step 4: Decide who needs to know
Not every incident requires public disclosure, but silence can create risk.
You should determine:
- Whether staff need instructions or restrictions
- Whether clients or partners are impacted
- Whether regulatory notification may be required
Communicate facts only. Avoid speculation. Set expectations for updates.
A short, clear message is better than a long, uncertain one.
Step 5: Close the security gap
Once the immediate threat is controlled, fix what allowed it to happen.
Common root causes include:
- Over-permissioned user accounts
- Poor device enrollment or unmanaged Macs
- Inconsistent MDM configuration
- Identity systems not fully enforced
- Security tools designed for Windows, not macOS
This is where most organisations fall down. They treat the symptom and leave the structure untouched.
The fix should reduce future risk, not just patch the current incident.
Step 6: Stabilise and rebuild with intent
A properly handled incident should leave you stronger than before.
That usually includes:
- Standardised Apple device management
- Clear access policies by role
- Improved monitoring and alerting
- A documented incident response plan
Security should feel calm and predictable, not reactive.
If this is happening right now…
If you are actively dealing with a suspected breach or feel out of your depth, stop and get support.
Dr Logic provides incident response and recovery for Apple-first organisations, helping you stabilise the situation quickly and rebuild with confidence.
We focus on:
- Apple-native security
- Calm, structured response
- Long-term resilience, not panic fixes
If this is happening right now, contact Dr Logic for immediate guidance. You may also like to save a copy of our quick reference sheet and share it with your team (in the hopes that you never have to use it!)



















































