We’ve said it before in our social posts: what you do after a hack is almost as important as preventing it in the first place. Prevention gets all the attention. Response gets you through the day it actually happens.
So for this post, we wanted to walk through it. Not in the abstract — step by step, the way it would actually unfold on an ordinary Tuesday.
The Scenario
This is fictional, but it’s fictional in the most boring, believable way possible — because that’s how it really happens.
It’s 9:40 on a Tuesday morning. You’re two coffees in, juggling a client call in twenty minutes, and an email lands from a printing vendor you’ve used before — the one who does your event materials. Subject line: “Invoice #4471 — Past Due, Please Review Today.” The logo is right. The signature name is someone you’ve actually emailed before. The only thing off, if you’d slowed down enough to notice, is that the email address is one character different from the real one, and the greeting says “Hi there” instead of your name.
You don’t slow down. You click the link to “review the invoice.” It drops you on a login page that looks exactly like your email provider’s — same layout, same colors, a little blurrier than it should be if you looked closely. You type in your email address and password. The page spins for a second, then redirects you to a generic “document not found” error. Annoying, but you shrug it off — probably just a broken link — and go into your call.
That’s it. That’s the whole moment. Ten seconds, and the hacker now has your email credentials.
By 11:15, the first sign shows up, and it doesn’t look like a hack — it looks like a typo. A client texts you: “Hey, did you mean to send me an invoice for a totally different project? Also the payment link looks weird.” You didn’t send anything to that client today.
At 2:30, you noticed the login alert from your email provider: a sign-in from a browser and location you don’t recognize, timestamped an hour after you clicked the link.
By 3:00, you check your sent folder and find four emails you didn’t write — one to a client with a fake payment link, one to your bookkeeper asking to “confirm the new banking details,” and two more to contacts pulled straight from your address book.
That’s the moment it stops being a hunch and becomes a confirmed compromise.
This is the part people don’t like to admit: it’s not usually a sophisticated technical exploit. It’s a moment of being human — tired, rushed, trusting someone who’s spent time making themselves look trustworthy. Social engineering works because it’s built to get past your judgment, not your firewall.
Okay. Now What.
So it’s 3:05, and you know for sure. This is the part that matters most, and it’s the part almost nobody plans for ahead of time. Here’s the order of operations.
1. Quarantine the machine
Disconnect it from the internet — Wi-Fi off, ethernet unplugged. Don’t shut it down yet (you may need what’s running for scope assessment later), but stop it from talking to anything else on your network or the internet.
2. Figure out what you were actually doing
You already know the email account is compromised — that one’s not in question anymore. So the password on that account changes immediately, no debate. But that’s the floor, not the whole picture. Ask:
- Were you logged into any other email addresses at the time — a second business inbox, a personal account, a shared team address? If it was open in the same browser or on the same device, assume it needs the same treatment.
- What else was logged in and active on that machine at the moment you clicked — your CRM, a shared drive, a client portal, your bank, a payment processor?
Anything that was logged in at the time is now a question mark, whether or not you can prove it was touched.
3. Change passwords — for the compromised account, anything logged in at the time, and anything that shares that password
Start with the email account you know was hit. Then work through every account that was actively logged in on that device when it happened — change those passwords too, even if you don’t have proof they were accessed, because “logged in at the time” is close enough to “exposed” to treat it that way. If any of those accounts share a password with something else (a vendor tool, a personal account, anything), change that password everywhere it’s reused — one phished login can cascade fast when passwords are shared across accounts. Turn on multi-factor authentication anywhere it isn’t already on.
4. Determine the scope of the damage
This is the least comfortable step because it takes real time, but it’s the one you can’t skip. Check the audit log — most business email and cloud storage platforms keep one, and it’s the real record of what actually happened, not just what you happen to notice. Ask:
- What data lives in the account that was compromised?
- What does the audit log show the attacker actually did — emails sent, files opened, files downloaded or shared, permission changes? Don’t just check the sent folder; an attacker who’s thinking ahead will delete what they sent from there to cover their tracks, so an empty sent folder doesn’t mean nothing happened. And if your email is tied to Google Drive or another shared storage, that needs the same look — a sent folder only ever shows you email, and it’s the one record they can tamper with. An audit log shows you everywhere they went, and it’s much harder for them to touch.
- Is there client, vendor, or employee data in there — contracts, financial details, personal information?
The honest answer might be “we’re not fully sure yet,” and that’s fine. It’s better to say that internally, keep digging, and update people as you learn more than to guess wrong in either direction.
5. Communicate internally, too
Your team needs to know what happened, in plain language, without blame. The goal isn’t to find out who clicked — plenty of smart, careful people fall for a good phishing email, that’s the whole design of it. The goal is making sure everyone knows what to watch for going forward and that reporting a suspicious email or “I think I clicked something” is met with speed and support, not embarrassment.
This is also where you prepare for the next step. If customers are going to be asking questions — and they will — give every employee the same written statement to use, word for word, before any of them are ever asked. Not everyone paraphrasing it in their own way, not everyone guessing at what’s okay to say. One approved message, so that no matter who a customer happens to reach, they hear the same accurate answer instead of five slightly different versions that start to sound like something’s being hidden.
6. If client data was exposed, you need to tell them
This is the step people most want to avoid, and it’s the one that matters most for trust. If there’s any real chance client data was accessed — even if you’re not 100% sure — they need to hear it from you, not find out later. This is where that written statement your team already agreed on comes in: a short, honest, factual message that covers what happened, what you know so far, what you’re doing about it, and what they should watch for on their end.
Before you send anything, check whether you’re bound to more than just good judgment here. Some client contracts and vendor agreements spell out exactly how and when you’re required to notify them of a breach. And depending on what kind of data was exposed and where your clients are located, there may be regulatory notification requirements too — timelines, specific language, or a specific authority you’re required to report to. This is worth a quick legal check rather than a guess, because missing a contractual or regulatory deadline turns one problem into two.
Silence, or a delayed disclosure, does far more damage to the relationship than the incident itself usually does.
The Bigger Point
Notice how much of this only worked because the signs showed up fast — a client texting within a couple hours, a login alert that actually got read. That speed is the whole point.
The biggest issue in a scenario like this was never really the click itself. Clicks happen — to careful people, to smart people, to people who know better. The biggest issue is how long it takes you to find out. If those signs had trickled in over weeks instead of hours, or worse, if nobody had been paying attention at all, this could have gone undetected for months. And a breach you don’t discover for months is a different problem entirely — by then, logs have rolled over and aged out, the audit trail is thin or gone, nobody remembers what was normal activity versus what wasn’t, and you’re left trying to reconstruct what happened instead of actually knowing. At that point, figuring out the real scope of the damage isn’t just hard. It can be flatly impossible.
That’s why detection matters as much as, if not more than, the response steps themselves. None of this requires you to be a cybersecurity expert. It requires you to have thought about it before the Tuesday it happens — because in the moment, adrenaline is not a great decision-making tool, and the clock is already working against you.
If you don’t have an answer right now for “how would we even know if this happened to us,” that’s the gap worth closing. It doesn’t need to be complicated. It needs to exist, and your team needs to know where to find it.
Prevention matters. But how quickly you find out is what determines whether this becomes a bad afternoon or a business-ending event.
And you don’t have to figure it out alone.
If you want a second set of eyes on where your business is actually exposed right now — before it’s a Tuesday afternoon scramble — that’s exactly what a Critical Services Security Assessment is for. We look at your real setup and tell you, in plain language, where the risk actually is.
If what you want is ongoing support — a place to ask “wait, is this email legit?” in real time, and a group of other female founders who get it — that’s what the Security Besties Community is for.
Either way, we’re here. You don’t have to be the expert. That’s our job.






