The Security Alert I Almost Ignored

A warning worth investigating

A hacker almost got us last week, and I almost missed it.

Those of you who have been following us for a while may remember that Sageplan started out as a GPS tracking company, and we still operate a small part of the existing business under the World Tracking Solutions brand. It’s now a small, generally quiet part of the overall business, so I was not too concerned when I saw a security notice come in from one of our monitoring tools stating that it had detected a problem.

It took me another day to get around to it, but when I looked at the website account, I saw clear indications that someone had tried to hack into the site.

We took immediate steps to lock them out and tighten the areas that needed attention. The incident also reminded me that security monitoring systems are only as good as the actions we take when they are triggered.

Experts are still human

We handle cybersecurity for ourselves and most of our clients, but expertise does not make us immune to attacks.  Over time, businesses accumulate websites, subscriptions, vendor accounts, plugins, users, and permission rules. It’s inevitable that the monitoring systems become fragmented, so it’s important to make sure we don’t lose visibility to the alerts that they generate.

And when an alert does appear, we want to have a consistent process in place to make sure the issue is addressed.

A practical cybersecurity alert response checklist

Every environment is different, but this is the kind of checklist I would want a small business owner to have in front of them when a security alert lands in the inbox.

1. Verify the alert before acting

Confirm that the message came from a legitimate source. If you are using third-party vendors for your monitoring, make sure the message actually came from them. Hackers have become very good at pretending to be trusted partners.

2. Record what triggered the review

Capture the alert, date, affected system, and any visible details. Good notes help you explain what happened and avoid relying on memory later.

3. Check for recent or unexpected changes

Review access for unfamiliar accounts, unexpected role changes, former employees, old vendors, and anyone who no longer needs elevated permissions. Do not remove an account blindly if doing so could destroy evidence or interrupt a critical service.

4. Contain the immediate risk

Disable or remove unauthorized access when appropriate, and isolate the affected system if possible. This is also the point to decide whether the situation requires qualified security support, especially if sensitive data, customer accounts, payment systems, or business-critical services may be involved.

5. Secure related credentials

For any system that may have been compromised, reset affected passwords, review multifactor authentication, sign out active sessions where the platform allows it, and check whether the same credentials were reused elsewhere.

If the application under question is connected to other systems in your business, review those connections as well. It’s also a good time to see if you can remove old apps that are no longer in use.

6. Decide whether notification or escalation is required

Depending on the systems and information involved, you may need to contact a technology provider, insurer, attorney, regulator, law enforcement agency, customer, or other stakeholder. Requirements vary, so obtain appropriate professional guidance.

7. Keep monitoring

A quiet system immediately after cleanup does not prove that the issue is fully resolved. Schedule periodic reviews of the system and stick to the schedule. The best checklist is the one your organization can actually repeat.

 

Remember: Cybersecurity is a mix of science and art

Even the best cybersecurity does not guarantee that you won’t see an issue. Technology changes, people change roles, vendors come and go, and older systems do not always receive the same attention as the systems we use every day. Cybersecurity is a moving target, and we have to stay vigilant to the reality that the hackers are always coming up with new ways to try and get into our systems.

In our case, a security warning led to an investigation, which led to corrective action. That is not a story about being perfect. It is a story about paying attention. For most small businesses, that is one of the most valuable cybersecurity habits to build.

If you need help building your own company habits, please feel free to schedule a free consultation with me. We can help you review your alert process and access controls, and build your own response checklist.