Stay calm: what not to do in the heat of the moment
Discovering you may be the target of a cyberattack — a ransom note on screen, unusual activity flagged by an employee, a call from your bank or a partner about suspicious behavior — almost always triggers a panic response. That's human, but it's also when the worst decisions get made fastest. Two reflexes to avoid at all costs: immediately powering off or wiping every affected machine, which can destroy information needed to understand what happened; and paying a ransom in a rush, without assessing the situation, hoping it will instantly fix everything. Taking a few minutes to breathe and follow a structured approach, rather than reacting purely on instinct, often changes how the rest of the incident plays out.
Isolate without destroying: cut access, preserve evidence
The first useful technical step is to isolate the affected systems from the rest of the network — unplugging the network cable or turning off Wi-Fi on a suspicious machine, for instance — without necessarily shutting it down completely. This prevents the problem from spreading to other devices while preserving traces (log files, running processes) that will later help figure out how the incident started and how far it went. If you're unsure what to do, it's safer to cautiously isolate several systems than to leave even one exposed. Also note the time you noticed the problem and anything visible at the time (an on-screen message, unusual behavior) — details recorded in the moment are often valuable to whoever handles the response afterward.
Name one crisis lead and take stock of what's affected
A crisis is easier to manage when one person clearly owns the decisions, even if several people are involved in the response. In an SME, that role usually falls to the owner or a manager designated ahead of time. That person should quickly try to build a first picture: which systems appear affected, what data might be involved (customer data, financial data, employee data), and how long the situation has been going on. Perfect answers aren't needed at this stage — the goal is to give anyone, internal or external, who helps handle the incident a clear starting point.
Legal obligations and communication: think about these early
If customer, employee, or partner personal data appears to be involved, consider the obligations that follow, particularly under Law 09-08 on personal data protection, which can require notifying the CNDP depending on the nature of the incident. On the communication side, the temptation is sometimes to stay silent until "everything is fixed" — but a client or partner who learns of an incident through another channel loses more trust than one informed transparently and in a controlled way. It's better to prepare a clear, factual, measured message once the situation is reasonably well understood, rather than communicating in a rush or staying quiet for too long.
Bring in help, then learn from the incident
If the company has no internal technical team capable of running a full investigation, bringing in an outside specialist quickly is usually the most cost-effective decision, even though it's an immediate expense. An outside perspective helps identify the source of the attack faster, properly secure systems before bringing them back online, and avoid restarting operations that are still vulnerable. Once the incident is under control, take the time for a proper debrief: how the intrusion became possible, what measures could have limited its impact, and what to put in place going forward. EBH Security supports Moroccan businesses through this kind of process, from an initial free audit through to concrete recommendations for reducing future risk.