Security

A co-op’s first steps in a cyber incident

Coordinate the first hour: trusted communication, careful containment, preserved evidence and timely assessment of personal-data risks.

In this guide

If your co-op suspects an account takeover, ransomware or unauthorised access to member information, start by coordinating people and preserving options. The first hour is about limiting harm, establishing facts and getting appropriate help. It is not the time for indiscriminate wiping or rebuilding systems from memory.

Appoint an authorised incident lead and a person to keep a timeline. In a small co-op these may be the same person initially. Use known contact details for your technical provider, insurer where relevant and organisational decision-makers. If email may be compromised, establish a trusted alternative communication route.

First: establish control of the response

  1. Record when the issue was noticed, who noticed it and what they observed.
  2. Identify the affected service, device or account without assuming the whole extent is known.
  3. Contact technical help through a verified route and state the practical impact.
  4. Stop exposed financial actions and contact the bank promptly if a payment or bank access may be affected.
  5. Ask people to report related symptoms to the incident lead rather than making uncoordinated changes.
  6. Protect urgent operational needs, such as safe access to essential contact information.

Keep facts separate from hypotheses. “Three people cannot open files” is an observation; “all data has been stolen” is a conclusion that needs evidence. Clear records help the technical investigation and reduce confusing messages to members.

Contain with care and preserve evidence

The NCSC response and recovery guide provides a framework for preparing and managing an incident. Follow expert advice for the affected system. An actively affected device may need network isolation, while a compromised cloud account may need sign-in blocked, sessions revoked and connected access reviewed.

Use a known-clean device and trusted administrator route for recovery work. If you are unsure how to isolate a system without affecting safety or destroying evidence, describe the situation to your provider and obtain instructions. Do not reconnect a suspicious device simply to see whether it now works.

Preserve original messages, relevant logs and a record of actions. Avoid deleting the account, clearing logs, repeatedly restarting equipment or restoring over the affected system without a considered plan. Restrict access to incident evidence because it can contain personal information and sensitive configuration.

An illustrative compromised treasurer mailbox may require review of forwarding rules, delegated access, active sessions and third-party applications as well as a password change. Use the payment-fraud process for any related supplier requests.

Assess personal-data implications promptly

The ICO's personal-data breach guidance says a reportable breach must be notified without undue delay and no later than 72 hours after becoming aware of it. Notification is required unless the breach is unlikely to result in a risk to people's rights and freedoms. If there is likely high risk, affected individuals must also be informed without undue delay.

Record all personal-data breaches and the reasons for reporting decisions. Where information is incomplete, the ICO allows required information to be supplied in phases without undue further delay. Do not wait for a perfect technical report before assessing the notification obligation.

Assign this assessment to the responsible organisational person with appropriate advice. Consider who is affected, what information is involved, whether it was accessed, altered or unavailable and the potential consequences for those people. Use the current ICO guidance and reporting tools for the actual circumstances.

Prepare controlled recovery and the next update

Before restoring, establish a credible recovery point, address the route of compromise and decide how recent legitimate work will be reconciled. Test restoration in an appropriate safe environment. The backup guide explains why a successful backup job does not prove recovery is ready.

Prepare a short update stating confirmed impact, actions underway, what people should do and when they will hear more. Avoid speculation or claims that everything is resolved before verification. Agree who may communicate externally.

After immediate containment, arrange a review of causes, recovery evidence and improvements. Keep the incident record and update the operating instructions while the experience is fresh. Use the digital handover tool to keep current contacts and recovery responsibilities accessible before another incident occurs.

Suggest a correction or improvement →