Most of our guides are about prevention. This one is for when prevention has failed. The difference between a scare and a disaster usually comes down to how quickly and calmly you act in the first hour. Keep this guide somewhere easy to find under pressure: print it, save it, or put it in your staff handbook, so nobody has to work out a plan from scratch on the worst day.
First, recognise it
You cannot respond to something you have not noticed. Common warning signs include:
- You or a member of staff typed a password into a page you now have doubts about.
- Colleagues or parents are getting odd emails that appear to come from you.
- You are suddenly locked out of an account that worked yesterday.
- Your email is sending messages you did not write, or rules are quietly forwarding or deleting mail.
- Money has moved, or a supplier says your bank details have changed when they have not.
- A computer is running slowly, behaving oddly or showing a message demanding payment to unlock your files.
Any one of these is enough to act on. You do not need to be certain it is an attack. Treating a false alarm seriously is far better than dismissing a real one. Our guide to spotting phishing emails explains how most of these start.
The first hour: act fast, stay calm
Speed matters more than perfection. Work through these steps in order.
- Change the password of the affected account straight away, from a device you trust, not the one you think might be compromised. If you are locked out, contact whoever runs your IT immediately. If the same password is used anywhere else, change it there too. Our guide to strong Windows passwords explains how to stop that happening again.
- Sign out all sessions and turn on two-factor authentication. In Microsoft 365, the account can be signed out everywhere at once, which throws the attacker out even if they still have the password. Two-factor authentication then stops them getting back in.
- Tell your IT supplier now. They can see what was accessed, lock things down and check whether other accounts are affected. If we look after your systems, ring us straight away. There is no need to apologise.
- Check for hidden email rules and forwarding. Attackers often set up rules that forward your mail to them or hide replies, so they keep watching after you change the password. Your IT supplier will check, but you should know this happens.
- If money is involved, ring your bank on a number from your card or the bank's official website, never one from an email or text. The faster you call, the better the chance of stopping or recovering a payment.
If you see a ransom demand
If a computer shows a message demanding payment to unlock your files, that is ransomware. Do not pay, and do not keep using the device. Disconnect it from the network by unplugging the cable and turning off Wi-Fi, leave it alone and get expert help.
The NCSC and UK law enforcement do not encourage paying ransoms. There is no guarantee you will get your data back, the machine stays infected and paying can mark you out as someone who pays. A recent backup kept away from your main systems is what gets you back on your feet; see our backup and disaster recovery service.
Then: contain and assess
Once the immediate problem is under control, work out how far it spread and what was exposed. Was it one account or several? Was personal data involved, such as children's records, parent details or staff information? Which devices need checking or wiping? Your IT supplier leads on this, but you are a partner in it, because you know your setting and your data better than anyone.
Reporting: who to tell
Report Fraud
Report Fraud has replaced Action Fraud as the national service for reporting fraud and cyber crime in England, Wales and Northern Ireland. Report online at reportfraud.police.uk or call 0300 123 2040. If a cyber attack is happening right now, ring that number rather than reporting online. In Scotland, call Police Scotland on 101.
The NCSC
The National Cyber Security Centre has practical guidance on recovering a hacked account and a small business guide to response and recovery. Both are worth reading now, before you need them.
The ICO: the 72-hour rule
This is where a nursery breach is different from a shop's. If personal data has been, or may have been, exposed, data protection law applies. If the breach is likely to put people's rights and freedoms at risk, you must report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Not every breach has to be reported, but when children's data is involved it almost always will be. If the risk to people is high, you must also tell the affected parents and staff without undue delay.
Do not wait for the full picture before you report. The ICO expects you to send what you know within the deadline and follow up with more later. A nursery that reports promptly, openly and with a clear account of what it has done is treated far more kindly than one that hides a breach and is found out later. If you are not sure whether something is reportable, treat it as if it is and get advice quickly. Your IT supplier can help establish what was exposed.
Ofsted or Care Inspectorate Wales
Childcare providers must tell their regulator about significant events. In England, Ofsted lists a stolen device containing children's information as an example, and says the greater the risk to children, the more likely you should notify. Tell Ofsted as soon as reasonably possible and within 14 days. In Wales, Care Inspectorate Wales expects notification of incidents affecting children's welfare in advance where possible, or within 14 days. If in doubt, ask your regulator.
Afterwards: learn from it
Once things settle, spend twenty minutes on the step most people skip: how did they get in? A clicked link, a reused password, or an account that was not closed when someone left? Close that gap so it cannot happen again. Our leavers checklist and guide to access control cover the most common ones.
Write down what happened and what you did. It helps if questions come up later, and it makes any future response quicker and calmer. If any terms here are unfamiliar, see our jargon buster.
This guide covers practical steps, not legal advice. Every breach is different, so take professional advice for your situation.
The one thing to take away
In the first hour, in this order: change the password, sign out everywhere, turn on 2FA and call your IT supplier. Remember the 72-hour clock if children's or parents' data may be exposed, and report to Report Fraud and your regulator too. Above all, make it completely safe for staff to raise the alarm the moment they suspect something. The fastest reports come from people who are not afraid of getting into trouble.