Retaking command of your hacked software

Retaking command of your hacked software

Once a Web site has been hacked, what are the proper steps for re-taking control my system?

    Requires Free Membership to View

    When you register, you'll receive targeted emails designed to keep you informed of the most relevant information on Agile development, application security, testing & QA, software requirements, and more.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSoftwareQuality.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSoftwareQuality.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

You actually have several options: 1) you can run around screaming like your hair's on fire and react to the situation (only to make things worse), 2) you could unplug the system and restore it from backup (and hope your backups go far back enough), or 3) you could launch a formal forensics investigation involving forensics investigators from private firms or even law enforcement if it's bad enough. The thing is you have to plan ahead for this type of situation so you're well-prepared when the time comes. This requires working with the right people in your organization (IT, security, HR, PR, customer service, operations, and legal) to put together an incident response plan that makes sense for your business.

This was first published in September 2009