Security Incident Handling for Individuals
Home > 
Security Incident Handling for Individuals
< back

Security Incident Handling for Individuals

If you encounter a security incident, such as when your malware scanning software alerts you that your computer has been infected with a malware, you should follow these steps:

Keep calm! Disconnect your computer from the Internet and stop any further work with the machine, e.g. stop sending emails or typing a document.
Determine the type of problem and extent of the impact on your system. Try to identify the source or cause of the problem, such as the opening of a suspicious email.
Take notes; log down events clearly and tidily and write down all the facts, e.g. the date and time the incident occurred, what actually happened, who is related to the incident, etc.
Get advice from appropriate organisations if necessary
Use other communication channels to get help, such as making phone calls. Don't use the Internet as this may disperse the malware again.
Collect records of the incident if possible, e.g. system logs or error logs. If necessary, make a full backup of compromised computer or system as soon as you find it a real incident and store the backup in a secure place.
Contain the problem: conduct an impact assessment of the incident on your data and information to see if anything has already been damaged by or infected. Move critical data to other media (or other systems) which are separate from the compromised system or network. Shut down or isolate the compromised host or system temporarily to prevent further damage to other interconnected systems and to prevent the compromised system from being used to launch an attack on other connected systems.
Eliminate or mitigate the cause of the incident, e.g. eliminate all backdoor and malicious programs installed by attackers, apply patches or fixes to vulnerabilities found on the operating system or your software, correct any improper settings and update your passwords. In the case of a malware infection, inoculate the malware from all infected systems and media following the advice of your anti-malware software vendor.
Restore your computer or system to its normal operating state, e.g. re-install deleted/damaged files from trusted sources and use backups that are confirmed clean and updated before the incident occurred. Verify that the restoration operation was successful and that the computer is back to its normal operating condition.
Strengthen existing protection, such as updating anti-malware definition file, installing a personal firewall, removing all unwanted emails, reconfiguring your browser, disconnecting from the Internet when not required, and so on.

Prevention is always better than cure. Click here to learn more about protecting your information and data.