Incident
response
However well you prepare, it can still happen — and then the damage is decided by what you do in the first hours. This episode is the course's emergency drill: five complete scenarios with exact steps in the right order, the phone numbers you need and the deadlines that apply. Save this page — it's written to be read in the middle of the blast.
First: breathe. Then: act in the right order
Incidents are made worse by panic and prolonged by shame. Both are natural — and both cost. Save this page; it's written to be read during an ongoing incident. Key contacts (Sweden — substitute your national equivalents):
CERT-SE (national CSIRT): +46 10-240 40 40 · cert.se
Police: 114 14 · polisen.se (always report crimes)
IMY (data protection authority): imy.se (data incidents, 72 hours)
Your bank: the number on the back of your card — never numbers from emails/texts
No More Ransom: nomoreransom.org (free decryption)
Scenario 1 — Your account is hijacked
You can't get in, friends receive strange messages, or unknown logins appear.
- Reclaim the account via the service's recovery flow (Google · facebook.com/hacked). The backup codes from episode 3 exist exactly for this.
- Change the password + log out all devices — the setting exists on every major service and ejects the attacker's sessions.
- Assess the damage: forwarding rules in the mailbox (a classic thief's trick), changed recovery details, sent messages, connected apps.
- If it was the email account: assume every account that can be reset through it is at risk — change passwords on the most important ones (bank, social media).
- Warn your contacts via another channel, and enable 2FA if it was missing.
Scenario 2 — Ransomware on the computer
- Disconnect from the network immediately (cable out, WiFi off) — stop the spread to NAS, cloud sync and other devices.
- Don't pay. Payment guarantees nothing and funds the next wave — that's also the official government line.
- Identify the variant at No More Ransom (Crypto Sheriff) — free decryption tools exist for many families.
- Report to the police and preferably to your national CSIRT — it aids the mapping even when nothing can be done acutely.
- Recover: reinstall the system, restore files from backup (episode 9 — the version before the encryption). Without backup: keep the encrypted files; tools sometimes appear years later.
Scenario 3 — A data breach at the company
- Contain: disable affected accounts/systems, rotate keys and passwords that may be exposed. Don't delete logs — they're evidence.
- Document from minute one: timestamps, what was seen, what was done. Needed for the authority, police, insurance and your own analysis.
- The 72-hour clock: if the incident involves personal data with risk to individuals, it must be reported to the data protection authority (IMY in Sweden) within 72 hours (episode 14). Better a report that proves unnecessary than the opposite.
- Call in support: CERT-SE (+46 10-240 40 40) supports Swedish organisations during serious incidents. Report the breach to the police.
- Inform affected customers/users honestly and concretely: what happened, what you've done, what they should do. Covering up always makes it worse — legally and in trust.
Scenario 4 — You gave details to a phishing site
The short version of episode 4, in order of action:
- Passwords: change immediately on the affected service + everywhere it was reused.
- Card/bank: call the bank via the back of your card, block, dispute.
- e-ID/signing: contact the bank at once — block if needed.
- Log out all sessions on the account and check for changed settings.
- Report to the police — and forgive yourself. AI phishing fools professionals (episode 4); a fast response is what counts.
Scenario 5 — The device is stolen
The full checklist is in episode 8 — the short version: lock/track remotely → block the SIM → change the email password first → file a police report with the IMEI → wipe remotely. Thanks to disk encryption (episode 9) and the screen lock (episode 8), the contents are unreadable to the thief — if the groundwork was done.
Afterwards: root cause and follow-up
Once the smoke clears, the incident is a free security audit — use it:
- The root cause, not the symptom: "the password leaked" is a symptom. Why did it work? Reused? No 2FA? An unpatched device? Fix the root cause, or the incident repeats.
- The chain: walk through what the attacker reached and could have reached — it reveals the next weak link.
- Update your protection: one item in your plan (episode 18) per incident. Victims who follow up usually come out more secure than before.
- Watch the aftermath: leaked data surfaces much later — the HIBP monitoring from episode 12, and vigilance against targeted scams ("we're calling from the bank about the breach…").
Sources
Want to dig deeper? These are the sources behind this episode.
- CERT-SE — cert.se — Sweden's national CSIRT, incident support: +46 10-240 40 40.
- Swedish Police — If you're the victim of crime — reporting cybercrime and fraud.
- IMY — imy.se — reporting personal data incidents within 72 hours.
- Europol et al. — No More Ransom — identify ransomware and get free decryption tools.
- CISA et al. — StopRansomware — consolidated government guidance.
- MSB — msb.se — incident response support for organisations.
- Google — Account recovery — reclaiming hijacked Google accounts.
- Meta — facebook.com/hacked — reclaiming hijacked Facebook/Instagram accounts.
- Troy Hunt — Have I Been Pwned — monitoring the aftermath of breaches.
Episode 17 — Ongoing security routines
The checklists that keep the protection alive — daily, monthly, quarterly and yearly.