Diagnosis
We pin down the actual cause: a break-in, a hosting provider failure, a failed update, an expired domain, a full disk or a suspended account.
We always follow one order: contain the damage, bring the site back, eliminate the cause. Skipping any step means a repeat performance a few weeks later.
We pin down the actual cause: a break-in, a hosting provider failure, a failed update, an expired domain, a full disk or a suspended account.
When a site is spreading malicious code or redirecting visitors, we put it behind a maintenance page returning a 503 code so it stops harming customers and the reputation of your domain.
We compare files against original versions, search the database for injected scripts and look for hidden administrator accounts, suspicious cron jobs and webshell files.
From your backup or, if there is none, from snapshots held by the host, cached pages in search engines and the Internet Archive. Much of the content can often be rescued.
With the threat removed, we ask Google for a review through Search Console, remove spam URLs from the index and check whether the domain has landed on email blocklists.
Up-to-date software, fresh credentials everywhere (admin panel, FTP, database, hosting, email), unused accounts removed and a backup that actually works going forward.
Timing depends on the scale of the compromise and whether a backup exists. With no backup it drags on, and no honest firm can promise full recovery.
A review of the site, hosting and logs. We gauge the damage and find out what copies exist.
The site goes into maintenance mode, all credentials are replaced and attacker access is severed.
A clean installation, restored content and data, tests of forms, payments and login. The site goes back online.
Current versions, regular off-server backups and file change monitoring. At the end you receive a report describing the incident.
Where an intruder may have reached personal data, the breach must be notified within 72 hours to the President of UODO, the Polish data protection authority. That includes shop customer records, user accounts and form submissions. While we work we log what happened, when, and what data might have leaked. Your DPO or lawyer gets material for the risk assessment and any notification, rather than rebuilding events from memory.
Usually a good deal, though rarely all of it. Many hosts retain snapshots covering recent days or weeks and release them on request. After that we check search engine caches, the Internet Archive and files on the computers of your editors. Structure and copy can often be recovered; orders from the last few days sometimes cannot.
Common symptoms: visitors on smartphones land on unknown sites, Google lists pages you did not publish, your host suspends the account over spam, or browsers display a warning. Occasionally all you notice is organic traffic falling off a cliff.
Rarely. Attackers are often inside for weeks before anyone notices, so yesterday’s copy already contains their backdoor. Restoring without finding the hole means the whole thing repeats within days.
Once the site is clean and a review has been submitted in Search Console, the decision rests with Google and usually comes within a few days. Should Google detect malicious code a second time, the next review takes longer, which is why we never clean just the surface but hunt down every backdoor.
For most companies reporting through incydent.cert.pl is voluntary, but worth doing, especially if your site was used for phishing. Entities covered by the Polish national cybersecurity system act have their own reporting duties, and we help prepare the technical description of the incident.
Describe the problem and when you first noticed it. We reply within one working day, and if you have a contract with us, your plan's response time applies.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.