Incident response

What to do after a cybersecurity incident in South Africa

The first response should preserve evidence, contain further harm, restore carefully, and identify any notification or contractual duties. Use this as an operational checklist, not a legal opinion or forensic substitute.

Independent guidance: Compare current provider terms, ownership, support, and exit requirements before buying. Clearly labelled affiliate links may earn us a commission.

Stabilise without destroying evidence

Record what was observed, when it happened, which accounts or devices are affected, what changed, and who was notified. Avoid wiping, reinstalling, or repeatedly logging into a compromised system before an appropriate technical review.

Contain access that is clearly compromised, but keep a written record of the action, time, person, and reason. If there is immediate danger to people or physical systems, use the appropriate emergency route first.

Protect the business while investigating

Use a clean device or verified account to change priority credentials, revoke active sessions, check administrator changes, and confirm that backups are available. Do not restore blindly into an environment that may still be compromised.

Keep essential business decisions moving through a trusted channel and warn staff about suspicious payment, password-reset, or supplier-change requests.

Scope the affected information

Identify systems, accounts, devices, records, customers, employees, suppliers, and time periods that may be involved. Preserve relevant logs, messages, email headers, invoices, access records, and the incident timeline.

Do not assume that the first visible symptom is the full scope. A compromised mailbox, endpoint, or administrator account can create access to other systems. Bring in qualified technical help when the boundary is unclear.

Check notification obligations

If personal information may have been accessed or acquired by an unauthorised person, assess the POPIA security-compromise notification process and any contractual or sector-specific obligations.

The Information Regulator guidance, the responsible information officer, and qualified legal advice should control the notification decision. Do not publish a generic deadline or promise that a situation does or does not require notification.

Recover from a known state

Confirm that the threat is contained, administrator access is controlled, devices are patched, and the chosen recovery copy is trustworthy before restoring. Prioritise the systems and data the business needs to operate safely.

Record what was restored, when, by whom, from which copy, and how the result was tested. Recovery is not complete when a login works; verify mail, files, payments, backups, and other critical workflows.

Communicate carefully

Name one person to coordinate staff, customers, suppliers, insurers, technical providers, and authorities where required. Keep messages factual, dated, and limited to what has been verified.

Warn staff about ongoing scams and give them one trusted reporting route. Do not ask them to investigate a suspicious device or message in ways that destroy evidence or increase exposure.

Close the loop

After recovery, document the root cause, affected systems, actions taken, lessons learned, and changes to prevent recurrence. Update passwords, access, device controls, backup tests, supplier terms, and training where the incident exposed a weakness.

Test the revised controls instead of treating the incident report as the final step. Keep the final record under business control and restrict sensitive personal information.

Use commercial support responsibly

An IT-support provider can help with hardening, endpoint protection, backup design, monitoring, or response coordination. Compare scope, response time, ownership, confidentiality, exclusions, and exit terms before sharing incident details.

A referral link is not a forensic service, legal advice, or a guarantee of recovery. Confirm the provider’s current coverage and terms before engaging it.

Sources and further reading

Back to all guides Compare support options Compare software Compare hosting