woman stressed because computer is encrypted with ransomware

What Should I Do If My Business Gets Hacked?

July 06, 20265 min read

Quick answer: Disconnect the affected device or system from the internet immediately. Call your IT provider. Don't pay any ransom before getting expert advice. Document everything you're seeing. Speed matters, but panic makes it worse.


If your business gets hacked, the first move is to isolate the problem. Pull the affected computer or server off your network — unplug the ethernet cable or disable Wi-Fi. This stops the attacker from spreading further into your systems while you figure out what happened.

After that, there's a right order to everything.

Step 1: Isolate first, then call for help

Don't start clicking through files to see what's missing. Don't restart machines hoping the problem goes away. Both can destroy evidence and make recovery harder.

Disconnect the compromised device. If you think the breach is wider — multiple computers affected, your server behaving strangely, employees unable to log in — take down the whole network segment if you can.

Then call your IT provider. If you don't have one, this is when you find out what that costs.

Step 2: Figure out what you're dealing with

Not every hack is the same, and the response depends on what actually happened.

  • Ransomware: Files are encrypted and you're seeing a ransom demand. Do not pay yet. Call a cybersecurity incident response professional first. Payment doesn't guarantee recovery, and there are often other options.

  • Phishing / credential theft: An employee clicked a link and entered their password somewhere. That account is compromised. Change credentials immediately and check for any forwarding rules set up in the email account.

  • Unauthorized access: Someone is in your systems who shouldn't be. Identify which accounts and cut access.

  • Data breach: Client or business data may have been taken. This has legal and notification implications depending on what was exposed.

In our work with firms across Western PA, phishing is the entry point in the majority of cases. One employee, one bad link, and the attacker is inside the network.

Step 3: Don't touch what you don't need to

Law enforcement, cyber-insurance adjusters, and forensic investigators all need to examine what happened. Deleting files, reinstalling systems, or wiping machines before anyone looks destroys the chain of evidence.

Write down what you're seeing. Screenshots, notes, timestamps. If your employees noticed anything unusual in the days before, document that too.

Step 4: Check your backups

This is where good backup hygiene pays off. If your files are backed up to a separate, isolated location and the backups weren't compromised, recovery becomes a technical problem instead of an existential one.

If your backups live on the same system that was hit, or you haven't tested restores in months, recovery gets much harder. That's not a reason to panic now, but it's the first thing to fix after you get through this.

Step 5: Notify the people who need to know

  • Your cyber-insurance carrier (if you have a policy, the claims process starts here — they often include incident response resources)

  • Legal counsel, especially if client data was involved

  • Affected clients, if their data was exposed (most states have breach notification laws with deadlines)

  • Law enforcement — the FBI's IC3 (Internet Crime Complaint Center) handles cybercrime reports

For AEC firms in the Pittsburgh area handling government contracts or working in any federally regulated space, there may be additional reporting requirements. Get legal guidance early.

Step 6: Recover carefully

Once your IT provider has assessed the damage, recovery can start. This usually means:

  1. Restoring from clean backups

  2. Rebuilding compromised systems from scratch, not just running an antivirus scan on them

  3. Resetting all affected credentials

  4. Patching whatever vulnerability let the attacker in

Don't bring systems back online until you know the entry point is closed. Rushing recovery just opens the door again.

What a hack actually costs an AEC firm

For engineering and construction businesses, a breach often hits hardest in two places: project files and email. CAD drawings, BIM models, specs, RFIs, submittals, client correspondence. If those are encrypted or stolen, you're not just dealing with downtime. You're dealing with missed deadlines, breach of contract exposure, and client trust that takes a long time to rebuild.

The firms that recover fastest had a backup they could actually restore, an IT provider they could call immediately, and a cyber-insurance policy that covered incident response. Those three things don't prevent attacks, but they determine how bad the outcome is.


FAQ

Should I pay the ransom? Don't pay before talking to a cybersecurity professional and your insurance carrier. Payment doesn't guarantee you'll get your files back, it may fund more attacks, and there are legal restrictions on paying certain threat actors. Explore your options first.

Do I need to tell my clients if my business gets hacked? It depends on what was exposed. If personal or client data was accessed, Pennsylvania's breach of personal information notification act and most state laws require notifying affected parties within a set timeframe. Get legal counsel involved early.

How long does recovery take? A single compromised email account might be resolved in hours. A ransomware attack that hit your file server and backups could take days to weeks. Tested backups and a response plan compress that timeline significantly.

What if I don't have an IT provider? Call a managed IT provider or a cybersecurity incident response firm. Don's Tech Rescue serves AEC firms throughout Western PA and can be reached at 412-974-2663 or [email protected]


If your business gets hit, you need someone you can call immediately. Don's Tech Rescue works with architecture, engineering, and construction firms across the Pittsburgh area to make sure the right systems are in place before something goes wrong, and to help if it does. Call 412-974-2663 or email [email protected]


Don Petrocelly

Don Petrocelly

Don is the Founder and Principle Consultant of Don's Tech Rescue.

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog

Ready to Get Your Tech Handled?

Start with a free Discovery Call and technology assessment. We'll look at your setup, office and job site, find the gaps, and give you a clear plan. No obligation, no pressure.

Proactive IT for AEC firms across Western Pennsylvania. We manage the tech your projects run on so you can run the job.

Services

  • Managed IT

  • Cybersecurity

  • Backup & Recovery

  • Network Management

  • Jobsite Connectivity

  • Micrsoft 365

Get in Touch

Copyright 2026. Don’s Tech Rescue. All Rights Reserved.