Active security incident

If you suspect that someone has access to a company account, server or files, the first hours decide how much you will know later. This page gives the order of containment and evidence preservation. We do not run a continuous monitoring centre: the first-contact target applies on business days.

First steps when you suspect a breach

When a breach is suspected the order is containment, evidence preservation, credential rotation — not cleanup.

  1. Isolate: disconnect the device or server from the network but leave it powered on. Disconnection stops the spread; shutting down destroys evidence that exists only in memory.
  2. Preserve evidence: keep logs, messages, alerts and file names as they are. Note the time and who observed what.
  3. Rotate credentials from a clean device, starting with administrator accounts, email and remote access, and terminate active sessions.

What not to do: do not delete logs and messages to “clean” the system, do not reformat the disk before evidence is copied, and do not reply to an extortion message on your own.

Responding to ransomware

With ransomware, the priority is keeping the backups intact and stopping encryption from spreading to shared storage.

  1. Disconnect affected machines from the network and from shared storage, without shutting them down.
  2. Check that backups are reachable and intact, from an account other than the one that was compromised.
  3. Record what was encrypted, since when, and which business functions stopped.
  4. Inform management, legal counsel and, where one exists, the data protection officer, before any contact with the attacker.
  5. Decide the restore order: which systems are needed first, from which backup, and into which clean environment.

Restoring onto a machine that has not been cleaned restores the problem too. Before data goes back, you need to know how the access was obtained.

Company data leak

When a leak is suspected, the first question is which data became accessible and over what period — not how many files exist in total.

Record which accounts and which storage were reachable and what categories of data they hold, especially personal data of customers or staff. Involve your legal counsel and data protection officer early: their decisions carry deadlines.

Do not announce a scope before confirming it. A public statement corrected twice costs more than an accurate one issued slightly later.

Preserving evidence

Evidence is preserved by copying, not by using: copies of logs, mailboxes and affected disks are stored separately before any remediation begins.

Keep an incident log with times, actions and who performed them. Note how long logs are retained on each system — in many environments the window is days, and what is lost does not come back.

Copies are held on storage outside the compromised environment, with a note of who created them and when.

Breach notification: Articles 33 and 34

Articles 33 and 34 of the GDPR set out notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, together with communication to the individuals themselves when the risk to their rights is high.

In Greece the supervisory authority is the Hellenic Data Protection Authority. Whether a specific incident triggers an obligation to notify is decided by your legal counsel or data protection officer, based on the data and the risk.

Our role here is technical: we deliver a timeline, the scope of access and evidence in a form usable in the notification. We do not draft the text sent to the authority and we do not decide whether it is owed.

What Bytesoft takes on

We take on the technical investigation: containment, analysis of how access was obtained, a record of what was affected, safe restoration, and hardening so the same door does not reopen.

We do not recover encrypted files without a valid backup or a publicly available decryption tool, we do not negotiate with attackers, we do not draft legal documents, and we do not certify that no data left when the logs do not support that.

Response time: first contact is targeted on business days — with no 24/7 cover outside a contract. If you need continuous availability, that is agreed in writing before an incident, not during one.

Frequently asked questions

How quickly do you respond to an active incident?

First contact is targeted on business days. We do not run a continuous monitoring centre, so out-of-hours cover exists only where it was agreed in writing before the incident.

Should I pay the ransom?

The decision is not technical and is not ours to make. It sits with management and your legal counsel, based on whether a valid backup exists, what data is involved and which restrictions apply. Payment guarantees neither restoration nor deletion of copied data.

Do I need a lawyer or the authorities?

Involve your legal counsel early, because notification deadlines run from the moment the breach becomes known. Reporting to law enforcement and notifying the supervisory authority are their decisions, not ours.

What do you need from us to start?

One contact point who can approve actions, a description of what was observed and when, a list of affected systems, and access to logs and backups. We do not touch systems without written authorisation.

After containment, the cause is closed with assessment and hardening: vulnerability assessment and hardening after an incident.

If the incident involves a public site or online shop: step-by-step recovery of a compromised website.

Last updated: 2026-09-05