Incident response
The week after a phishing click: UK SME cleanup checklist
A plain-English week-one cleanup for UK SME owners after containment: finish password resets, re-enrol MFA, tidy the vault, and choose restore from backup over risky file recovery.
The first hour after a phishing click is about containment. The next seven days are about finishing the job without panic shopping.
This guide follows OwnerSec's first-hour phishing checklist. Use that page first if the device is still online, sessions are still open, or money might move. Come here when the blaze is contained and you need a calm cleanup plan.
It is for UK owner-managers with roughly 5 to 50 people and no security team. It is a checklist, not a guarantee. If customer personal data clearly left the building, or payments already moved, keep your bank and specialist advice in parallel.
What "cleanup" means this week
Cleanup is not a new laptop by default. Cleanup is:
- Finish identity resets for anything exposed or reused.
- Re-enrol MFA so old phone methods and stolen sessions die.
- Put shared secrets into a company vault with named owners.
- Decide restore from backup versus file recovery on an isolated machine.
- Close quiet damage: mailbox rules, odd payees, connected apps.
Write one line that still names the incident. Who clicked. What they opened. Which device. Roughly when. Keep working that same incident until the list below is done.
Days 1 to 2: finish password resets
Hour one usually resets the account typed into a fake page. The rest of the reuse trail often waits. Do not leave it.
- Confirm the Microsoft 365 or Google Workspace password is unique and already rotated.
- Revoke sessions again after the reset. Sign-out everywhere is cheap insurance.
- Open the company password manager. Search for the old password string if the tool allows it. Rotate every hit.
- Rotate shared secrets that person could open: office@ style logins, supplier portals, social ads, domain registrar, hosting.
- Banking, payroll, Xero, FreeAgent, Sage, and payment tools next if those lived in the same browser profile.
- Put every new secret in the vault. Do not paste new passwords into WhatsApp or a group chat.
You do not need to reset every password in the firm on day one. You do need to reset what was exposed, reused, or shared with the affected person.
If you still have no company vault, this week is the moment to start one. Named accounts beat a spreadsheet. See OwnerSec's password manager guide and stop password reuse checklist.
Days 2 to 3: MFA re-enrol
Turning MFA on once is not enough after a phishing click. Treat the affected person's sign-in methods as dirty until you replace them.
- Remove old authenticator entries, SMS numbers you no longer trust, and unused backup methods for that account.
- Enrol a fresh authenticator app on a phone the person still controls.
- Generate new backup codes. Store them in the company vault with the owner and one deputy. Not in a camera roll. Not in chat.
- If MFA was off for email, turn it on for every human account this week. Prefer an app over SMS where the product allows it.
- Do the same for the password manager admin account. The vault is now the soft underbelly if MFA is weak there.
For Microsoft 365 steps, use the MFA for Microsoft 365 beginners guide. For staff phones and Google Workspace, use the authenticator apps checklist.
Tell people to deny approval prompts they did not just request. A prompt that appears while nobody is signing in is a reason to stop and tell the owner.
Days 3 to 4: vault hygiene
A vault full of old shared passwords is only slightly better than a sticky note. After phishing, clean the mess.
- Move remaining shared founder passwords into shared folders with a named owner.
- Replace "everyone knows the office Gmail password" with a shared mailbox plus personal accounts. See the shared-login guide.
- Remove leavers and the affected person from items they no longer need.
- Turn MFA on for the vault itself.
- Record who can invite users, export the vault, and reset other people's access.
NordPass Business is a sensible option for a small UK team that wants shared folders and a cash-priced plan you can check on the vendor site. OwnerSec has a live affiliate link. Commission does not change the order of this checklist. Containment and resets come first. The vault is how you keep the cleanup tidy.
1Password and Bitwarden remain fair alternatives. The habit matters more than the logo: unique passwords, MFA on the vault, named owners for shared items.
Days 4 to 5: restore from backup vs file recovery
Owners often jump straight to recovery software. That is the wrong default.
Prefer restore from a known-good backup when:
- You have a recent backup that was not sitting only on the infected laptop.
- You have already tested a restore once this year, even a small one.
- Files look encrypted, renamed, or held to ransom.
- You cannot trust the disk because malware may still be present.
Isolate first. Then restore clean copies onto a clean machine or a rebuilt one. OwnerSec's backup and ransomware restore test guide covers 3-2-1 thinking and a quiet quarterly drill.
Consider file-recovery software only when:
- The device is already offline and isolated.
- You have no usable backup for those specific files.
- You need deleted or damaged files, not a live ransomware negotiation.
- You accept that success is not guaranteed.
Do not install recovery tools onto a still-connected infected PC and hope. Do not treat recovery software as a substitute for backups. If ransomware symptoms are active, disconnect other machines on the same network and get advice. Paying a ransom is not a first plan.
Quiet damage still worth a second look
Phishing often aims at inbox fraud, not fireworks. Later in the week, check again:
- Mailbox rules and forwarding you might have missed on day one.
- Connected apps and OAuth grants the user does not recognise.
- Sent items with "new bank details" language.
- Payee changes in the bank or accounting tool. Call the bank on a number from your card or statement, not from an email.
- Domain DNS and email authentication if the phishing trail pointed at hosting or registrar access.
If finance staff got the same mail, use the invoice fraud checklist. Keep the payment freeze until a named person clears unusual requests.
One-week cleanup checklist
Copy this into a note the owner can see.
Day 1
- Confirm device still isolated or rebuilt path booked
- Cloud password rotated; sessions revoked again
- Reuse search started in the password manager
Day 2
- Shared secrets and high-value portals rotated into the vault
- Old MFA methods removed for the affected account
- Fresh authenticator app and new backup codes stored in the vault
Days 3 to 4
- Vault hygiene: named owners, leavers removed, MFA on the vault
- Mailbox rules, OAuth apps, and payees checked a second time
- Staff told to deny unexpected MFA prompts
Days 5 to 7
- Restore from known-good backup where files matter, or isolated file recovery only if no backup exists
- Endpoint console checked; rebuild or malware scan completed
- One restore test booked for later this month if you skipped it before
- Short incident note kept for insurers, buyers, or Cyber Essentials questionnaires
What this week does not finish
- It does not make the firm "fully secure".
- It does not replace Cyber Essentials certification. See the Cyber Essentials beginners guide.
- It does not replace endpoint protection with a console you can open. See the cheap endpoint guide.
- It does not decide ICO notification for you. If personal data may have left, get proper advice on the clock that applies to you.
FAQ
- Is the first-hour checklist enough on its own?
- No. The first hour contains the blaze. This week finishes resets, MFA re-enrol, vault hygiene, and the restore decision.
- When is file recovery safe?
- Only after isolation, and only when you lack a known-good backup for those files. Prefer restore from backup when you have one.
- Do we reset every password in the firm?
- Reset what was exposed or reused first. Then shared secrets and high-value portals. A full firm wipe is rarely the first move.
- Should we re-enrol MFA if it was already on?
- Yes for the affected account when a fake login, stolen session, or lost phone is in play. Remove old methods and store new backup codes in the vault.
- Is Recoverit a backup product?
- No. It is file-recovery software for deleted or damaged files after containment. Tested backups remain the primary recovery path.
Bottom line
Contain first with the first-hour guide. Then spend the week finishing identity work, re-enrolling MFA, cleaning the vault, and restoring from a backup you trust. Use file recovery only on an isolated machine when that backup does not exist. Book a quiet restore drill so the next incident is shorter.
Written for UK SME owners. More guides · How we make money · Pages-ready draft only (held)