Limit the damage
Disconnect a device if malware is suspected, but do not wipe it. Stop remote-access sessions and suspicious calls. If business email in Stirling is involved, warn anyone who approves invoices or supplier changes.
+44 (0)1743 668200Plain-English cyber recovery support for people and small businesses across Stirling. Contain the incident first, then secure accounts and plan recovery.
Businesses working across cities, rural communities, tourism, energy and professional services can be disrupted by one compromised mailbox or reused password. In Stirling, investigate unexpected Microsoft 365 sign-ins, new mailbox forwarding rules and supplier bank details changing without verification promptly.
An incident may begin with a convincing call, a fake sign-in page, a supplier invoice, stolen browser credentials or an unpatched device. Write down what each person saw and when it happened. A reliable timeline is more useful than guessing how an attacker got in.
Disconnect a device if malware is suspected, but do not wipe it. Stop remote-access sessions and suspicious calls. If business email in Stirling is involved, warn anyone who approves invoices or supplier changes.
Use a separate phone or computer to contact your bank, IT provider and account services. Type known addresses yourself and avoid links in the message that caused concern.
Start with email, Microsoft 365 or Google Workspace, banking, domain names and website administration. Reset unique passwords, review recovery details, remove unknown sessions and enable MFA.
An account compromise rarely stays inside one inbox. Attackers may study real conversations, imitate trusted contacts or wait until a genuine payment is due. Review sent items, deleted items, forwarding rules, delegated access, administrator roles and sign-in locations.
Ask staff to report unusual prompts without blame. Tell them which route to use if normal email cannot be trusted. Check laptops, phones and shared computers for unfamiliar browser extensions or remote tools.
Confirm backups exist, are separate from the affected system and can be restored before deleting or rebuilding anything. Keep screenshots, email headers, phone numbers, URLs, bank messages and login alerts.
Businesses coordinating with customers or suppliers across South Lanarkshire, West Dunbartonshire, Aberdeen should check any shared accounts and payment processes too. Record each password reset, device isolation and bank call so recovery work is not repeated or missed.
If personal data may have been exposed, assess whether the relevant regulator and affected people need to be told. Check your cyber-insurance terms before taking actions that may affect a claim.
The aim is to regain control, understand the likely exposure and reduce the chance of a follow-up attack. Recovery should leave accounts, devices and working practices safer than they were before the incident.
If money has moved, call your bank immediately and ask whether a transfer can be stopped or recalled. Report through Police Scotland scams and fraud guidance. Use NCSC guidance for independent prevention and recovery guidance.
Keep reference numbers and note who was contacted. Reporting does not replace containment. Secure accounts and devices at the same time using a route the suspected attacker cannot monitor.
Disconnect affected devices safely, pause payments, preserve messages and screenshots, then use a separate trusted device to secure important accounts.
Contact your bank immediately if money may be at risk. Use Police Scotland scams and fraud guidance for the appropriate official reporting route.
Yes. Initial containment, account checks and recovery planning can often start remotely. We will explain if a device needs hands-on investigation.
Not before evidence and recovery options have been checked. Wiping too early can remove useful logs, messages and other evidence.
Tell us what happened, which accounts or devices are affected and whether money or customer data may be at risk.