Your Nigerian Business Just Got Hacked. Here's What to Do in the First 30 Minutes.
Most Nigerian businesses have no incident response plan. When a breach happens they improvise. That improvisation is expensive.
Here's what to actually do. 🛡️🇳🇬
THE FIRST 30 MINUTES — CONTAIN:
🚫 DON'T panic and delete everything. You need the evidence. Deleting destroys your ability to investigate.
🔌 Disconnect — don't shut down — compromised systems from the network. Shutdown destroys forensic memory. Disconnect preserves it.
📸 Screenshot everything unusual. Note exact times. Document what you see. This is evidence.
📞 Call your IT/security contact. Not email. Phone. Now.
🔑 Change ALL admin credentials on systems that appear uncompromised.
THE FIRST 4 HOURS — ASSESS:
🔍 What systems were compromised? 🔍 What data was accessed? 🔍 How did attacker get in? 🔍 How long have they had access?
📞 Alert:
CEO and leadership
Legal counsel — NDPR obligations start now
Your bank if financial accounts involved
THE 72-HOUR CLOCK — NDPR:
⏰ NDPR requires you notify NITDA within 72 hours of discovering a breach.
Clock started when you discovered it. Not when investigation is complete.
Email: [email protected]
Also notify affected customers honestly. What happened. What was taken. What they should do.
THE RECOVERY:
✅ Restore from CLEAN TESTED backups ✅ PATCH the vulnerability BEFORE going online ✅ Verify security controls are active ✅ Penetration test restored systems ✅ Document everything for post-review
THE HONEST TRUTH:
Businesses that recover fast had a plan. Businesses that suffer catastrophic damage were making it up as they went.
Build your incident response plan BEFORE you need it.
ZikarelHub LTD — Nigeria's #1 software and digital agency — helps Nigerian businesses build incident response plans, implement security controls and recover when incidents occur.
We don't just respond to incidents. We help prevent them.
🔗 zikarelhub.tech/cybersecurity-nigeria 💬 wa.me/2349110336685












