The Cybersecurity Course · Episode 16
Read time ~9 min · No prior knowledge

Incident
response

However well you prepare, it can still happen — and then the damage is decided by what you do in the first hours. This episode is the course's emergency drill: five complete scenarios with exact steps in the right order, the phone numbers you need and the deadlines that apply. Save this page — it's written to be read in the middle of the blast.

Contents
  1. First: breathe. Then: act in the right order
  2. Scenario 1 — Your account is hijacked
  3. Scenario 2 — Ransomware on the computer
  4. Scenario 3 — A data breach at the company
  5. Scenario 4 — You gave details to a phishing site
  6. Scenario 5 — The device is stolen
  7. Afterwards: root cause and follow-up
  8. Sources

First: breathe. Then: act in the right order

Incidents are made worse by panic and prolonged by shame. Both are natural — and both cost. Save this page; it's written to be read during an ongoing incident. Key contacts (Sweden — substitute your national equivalents):

Key contacts CERT-SE (national CSIRT): +46 10-240 40 40 · cert.se Police: 114 14 · polisen.se (always report crimes) IMY (data protection authority): imy.se (data incidents, 72 hours) Your bank: the number on the back of your card — never numbers from emails/texts No More Ransom: nomoreransom.org (free decryption)

Scenario 1 — Your account is hijacked

You can't get in, friends receive strange messages, or unknown logins appear.

  1. Reclaim the account via the service's recovery flow (Google · facebook.com/hacked). The backup codes from episode 3 exist exactly for this.
  2. Change the password + log out all devices — the setting exists on every major service and ejects the attacker's sessions.
  3. Assess the damage: forwarding rules in the mailbox (a classic thief's trick), changed recovery details, sent messages, connected apps.
  4. If it was the email account: assume every account that can be reset through it is at risk — change passwords on the most important ones (bank, social media).
  5. Warn your contacts via another channel, and enable 2FA if it was missing.

Scenario 2 — Ransomware on the computer

  1. Disconnect from the network immediately (cable out, WiFi off) — stop the spread to NAS, cloud sync and other devices.
  2. Don't pay. Payment guarantees nothing and funds the next wave — that's also the official government line.
  3. Identify the variant at No More Ransom (Crypto Sheriff) — free decryption tools exist for many families.
  4. Report to the police and preferably to your national CSIRT — it aids the mapping even when nothing can be done acutely.
  5. Recover: reinstall the system, restore files from backup (episode 9 — the version before the encryption). Without backup: keep the encrypted files; tools sometimes appear years later.

Scenario 3 — A data breach at the company

  1. Contain: disable affected accounts/systems, rotate keys and passwords that may be exposed. Don't delete logs — they're evidence.
  2. Document from minute one: timestamps, what was seen, what was done. Needed for the authority, police, insurance and your own analysis.
  3. The 72-hour clock: if the incident involves personal data with risk to individuals, it must be reported to the data protection authority (IMY in Sweden) within 72 hours (episode 14). Better a report that proves unnecessary than the opposite.
  4. Call in support: CERT-SE (+46 10-240 40 40) supports Swedish organisations during serious incidents. Report the breach to the police.
  5. Inform affected customers/users honestly and concretely: what happened, what you've done, what they should do. Covering up always makes it worse — legally and in trust.

Scenario 4 — You gave details to a phishing site

The short version of episode 4, in order of action:

  1. Passwords: change immediately on the affected service + everywhere it was reused.
  2. Card/bank: call the bank via the back of your card, block, dispute.
  3. e-ID/signing: contact the bank at once — block if needed.
  4. Log out all sessions on the account and check for changed settings.
  5. Report to the police — and forgive yourself. AI phishing fools professionals (episode 4); a fast response is what counts.

Scenario 5 — The device is stolen

The full checklist is in episode 8 — the short version: lock/track remotely → block the SIM → change the email password first → file a police report with the IMEI → wipe remotely. Thanks to disk encryption (episode 9) and the screen lock (episode 8), the contents are unreadable to the thief — if the groundwork was done.

Afterwards: root cause and follow-up

Once the smoke clears, the incident is a free security audit — use it:

Next time Security isn't a project but a routine. Episode 17 packages everything the course has built into running checklists — daily, monthly, quarterly and yearly — plus the three actions that apply if you only have energy for anything at all.

Sources

Want to dig deeper? These are the sources behind this episode.

  1. CERT-SE — cert.se — Sweden's national CSIRT, incident support: +46 10-240 40 40.
  2. Swedish Police — If you're the victim of crime — reporting cybercrime and fraud.
  3. IMY — imy.se — reporting personal data incidents within 72 hours.
  4. Europol et al. — No More Ransom — identify ransomware and get free decryption tools.
  5. CISA et al. — StopRansomware — consolidated government guidance.
  6. MSB — msb.se — incident response support for organisations.
  7. Google — Account recovery — reclaiming hijacked Google accounts.
  8. Meta — facebook.com/hacked — reclaiming hijacked Facebook/Instagram accounts.
  9. Troy Hunt — Have I Been Pwned — monitoring the aftermath of breaches.
Next episode

Episode 17 — Ongoing security routines

The checklists that keep the protection alive — daily, monthly, quarterly and yearly.