Free for your firmVetted cybersecurity specialistsMatched in 24 hours
Threat realityFBI IC3 2025: $20.9B in reported U.S. cybercrime losses — a 26% jump year over year.
Self-check result · Act now

Act now: what to do in the next 24 hours

Score 26 or higher, or an incident already reported

Your answers point to an event already in progress, or exposure serious enough that every week of delay adds cost. This page is the plan we would give you in the first ten minutes of a call. Work top to bottom. Most of the first block you can do yourself, today, without spending anything.

Free for your firm — specialists cover the cost.
What this result means

This result does not mean you have been breached. It means the conditions that turn a small problem into an expensive one are present at the same time.

If something has already happened — ransomware, a misdirected payment, an account takeover, data you cannot account for — treat the clock as running. Regulated data such as health or payment records carries notification deadlines measured in days, not months.

The most expensive mistakes in the first day are almost always well-intentioned: wiping a machine, paying quickly, or emailing everyone about it. Preserve, contain, then decide.

Your first 30 days, in order

  1. 1

    Preserve evidence before you clean anything up

    Do not wipe, reimage, or 'just reinstall' an affected machine. Disconnect it from the network — unplug the cable, turn off Wi-Fi — but leave it powered on if you can. Logs and memory are what let an investigator tell you what was actually taken, which is what your insurer and any regulator will ask for.

    First hour You can do this yourself
  2. 2

    Force a password reset and revoke active sessions on email

    Reset passwords for any account you suspect, and separately sign out all active sessions — a reset alone often leaves the attacker's existing session live. Check email forwarding rules and inbox rules on every affected mailbox; hidden auto-forward rules are the most common thing left behind.

    First few hours You can do this yourself
  3. 3

    Turn on multi-factor login for every account that allows it

    Email first, then remote access, then banking and payroll. Use an authenticator app rather than SMS where you have the choice. This single change removes the most common entry point in small-firm incidents.

    Day one You can do this yourself
  4. 4

    Call your insurer before you call anyone else you'll pay

    Most cyber policies require you to notify them and to use their approved responders. Hiring your own firm first can reduce or void the claim. If you are not sure whether you have coverage, check general liability, professional liability, and any bundled business owner's policy — coverage is often buried.

    Day one You can do this yourself
  5. 5

    Verify one backup actually restores

    Pick a real file set and restore it somewhere isolated. Backups that exist but have never been restored are the single most common bad surprise in ransomware. If your backups are reachable from the same network and credentials as your live systems, assume they are also affected.

    First 48 hours Specialist help pays off here
  6. 6

    Freeze outbound payments and re-verify banking details by phone

    If any invoice, wire, or payroll change has moved recently, call the recipient on a number you already had — never a number in the email. Misdirected payment fraud is frequently recoverable in the first 72 hours and rarely after.

    First 48 hours You can do this yourself
  7. 7

    Get an incident specialist on a scoped engagement

    Containment, forensics, and the legal notification question are not a DIY project once regulated data is involved. What you want is someone who has run your exact scenario — your industry, your systems, your regulator — not a generalist learning on your incident.

    Week one Specialist help pays off here
  8. 8

    Establish who owns security going forward

    Name a person, give them an hour a week, and write down what they check. Firms that come out of an incident without doing this are usually back in one within two years.

    Weeks two to four You can do this yourself

What not to do in the first day

  • Do not pay a ransom before you know whether backups restore and whether your insurer will cover it. Payment does not remove notification obligations.
  • Do not send a firm-wide email describing the incident. Use phone or an out-of-band channel — attackers frequently still have mailbox access.
  • Do not wipe or reimage the affected machine to 'get back to work'. You are destroying the evidence that determines whether you have to notify anyone.
  • Do not promise clients or patients a scope of impact you have not verified. An early wrong number is much harder to walk back than a short delay.

What this usually costs

  • Independent cybersecurity consultants commonly bill $150-$400 per hour.
  • A scoped incident response engagement for a small firm typically starts in the low five figures; forensics with regulated data runs higher.
  • If you carry cyber insurance, much of the above may be covered — but only if you follow the policy's notification and approved-vendor conditions.
  • The diagnostic meeting through us is free to your firm. Specialists cover the cost, so nothing on the first call is billed to you.

Questions to ask any specialist you talk to

  • Have you handled this exact scenario in my industry, and how recently?
  • Who on your team actually does the work, and what are their hours?
  • What can you tell me in the first 48 hours, and what will take longer?
  • Will you work with my insurer's panel, or do you need to be retained separately?
  • What do you need from me today to start, and what does it cost if we stop after the assessment?

Get matched with someone who has handled this before

Tell us what came up in the self-check. We match you within 24 hours with a vetted specialist who has run your exact scenario. One meeting, free to your firm. Free for your firm — specialists cover the cost.

Book Your Free Meeting Now

Common questions

Should I call the FBI or law enforcement?

Reporting to the FBI's Internet Crime Complaint Center (IC3) is free and does not slow your recovery. For misdirected wire payments in particular, fast reporting materially improves the odds of a freeze or recall. Reporting does not replace any regulatory notification you may owe.

How fast do I have to notify people if health data is involved?

HIPAA breach notification timelines are counted from discovery and are short — this is exactly the question to put to a specialist and, if the data is regulated, to counsel, within the first days rather than the first month.

Can my current IT provider handle this?

Sometimes for containment, rarely for forensics or the notification decision. Incident response is a distinct discipline. Keeping your IT provider involved is right; making them the only party is usually not.

What does the free meeting actually cover?

A working diagnostic conversation: what happened as far as you know, what to preserve, what the realistic options and costs are, and what you should do next whether or not you hire anyone. It is free to your firm — specialists cover the cost.

This page is general guidance, not legal advice. If regulated data such as health or payment records may be involved, confirm your notification obligations with qualified counsel.