Cybersecurity · 06

Your Website Looks Compromised: 6 Things to Do in the First 24 Hours

Unexpected redirects, strange content or unusual mail are not a cue to delete things in a panic. Six steps to preserve evidence, limit impact and recover safely.

A server rack with colourful network cables, a real photo illustrating infrastructure to inspect during an incident.
Friday Works / Journal06 · 2026
ContentsTap to jump to a section
  1. 011. Verify the signal and preserve evidence
  2. 022. Contain impact before restoring
  3. 033. Restore from a clean point and test the cause
Summary
The one-minute brief
  • Do not delete logs or reinstall immediately; they may be the only evidence of cause.
  • Contain the impact by restricting risky access while keeping a copy for investigation.
  • Recovery is incomplete until the cause is patched, credentials are rotated and the site is retested.
01

1. Verify the signal and preserve evidence

Common signals include redirects, unfamiliar admin activity, injected content, unusual email volume or monitoring alerts. One signal does not prove an attack, but it is enough to start a documented investigation.

Record discovery time, relevant URLs, screenshots, error messages and recent changes. Preserve access logs, application logs and the current configuration before deleting or reinstalling anything. The first attempted fix can otherwise erase the cause.

CISA treats identification, containment and preservation as separate parts of incident response. For a business website, that means not rushing to make a site merely look normal again.

An unplugged network cable, backup drive, incident notebook and hardware key illustrating controlled incident response.
Illustration: contain carefully, retain a copy and record what happened.
In a security incident, the fastest action is not always the right action. Preserved evidence helps a team fix the real cause.
02

2. Contain impact before restoring

Revoke sessions, rotate passwords and API keys, and disable unnecessary accounts when credentials may be exposed. If malicious code may be running, consider maintenance mode or blocking the abused path based on customer and data impact, not only whether the page still opens.

Do not run a destructive clean-up tool against the only server copy. It may remove important files or change timestamps. If specialist help is not available, preserve the environment and restrict access first.

03

3. Restore from a clean point and test the cause

A backup is useful only when it predates the intrusion and can be restored. Update the platform, remove excess accounts and rotate related credentials. Check scheduled jobs, mail-forwarding rules and deployment keys as well.

Then retest important flows, inspect logs and document confirmed facts separately from assumptions. Honest incident notes prevent unnecessary panic and make follow-up work clearer.

FAQ

Frequently asked questions

Should we shut the website down as soon as we suspect an attack?

There is no universal answer. Restrict access when customer data or users may be at risk, but preserve evidence and weigh operational impact before changing the environment.

Is changing passwords enough?

No. It limits risk but does not identify the cause. Review accounts and keys, patch the weakness and monitor after recovery.

References

Sources used in this guide

We prioritise official guidance and primary technical sources. Visit each source for full context and the latest updates.

  1. 82% doanh nghiệp Việt muốn lập trung tâm điều hành an ninh mạngVnExpress
  2. Trend Micro tái định danh mảng an ninh mạng doanh nghiệpVnExpress
  3. Computer Security Incident Handling GuideNIST
  4. Cluttered server rack filled with colorful cables and networking equipment — Federal Bureau of Investigation, Public Domain (cropped)Wikimedia Commons

Written and reviewed by

Friday Works technology team

A perspective shaped by designing websites, building software, automating operations, integrating AI and assessing security for businesses.

Content is reviewed to reflect methods that can be applied in practice. We update it when the process, technology or underlying evidence changes materially.

About Friday Works