Chapter 13
13Incident Response: A Practical Step-by-Step Guide
“Clients do not judge you by the incident but by how you handle it.”
However strong your defences, security incidents can happen. An incident such as a client campaign leak or ransomware encrypting your work can devastate your reputation and your revenue. The response makes the difference: a calm, organised one builds client trust, a chaotic one destroys it. This chapter offers a practical guide designed for the kinds of incidents creative professionals face.
What Is a Security Incident for a Creative Agency?
An incident is not only the massive breach you see in the news. It could be any of the following:
- Data breach: Unauthorised access to sensitive client or company data. Example: your server is breached and a client folder with product photos and marketing plans is accessed before release.
- Ransomware attack: Your files are encrypted and a ransom demanded to unlock them. Example: you clicked a malicious link and your entire portfolio, including current project files, is inaccessible before an important deadline.
- Social media account takeover: An attacker seizes your agency’s or client’s account and posts unauthorised content. Example: an upcoming campaign on Instagram is hijacked and offensive material posted, damaging the brand’s image.
- Intellectual property theft: Designs, scripts or source code stolen and used without permission. Example: a former contractor downloads your entire library of proprietary design templates to start a competing business.
- Denial of service (DoS): Your website or portfolio becomes unavailable to legitimate visitors because it is flooded with traffic.


Text in this figure
Contain · Isolate · change · Delete nothing · Assess · What and when · Where, what is exposed? · Escalate · Notify · form a team · Log with timestamps · Communicate · Client first · Honest and open · Review · Lessons learned · and action plan · The first 24 hours · After the storm · A calm, organised response builds client trust; chaos destroys it · Figure 18
The First 24 Hours: Immediate Action Checklist
The moments after discovery are critical, and your goal is to contain the damage and understand what happened. Follow the steps methodically.
Step one: contain the breach
- Disconnect the affected device: If a particular computer is infected, disconnect it from Wi-Fi and any network cable immediately.
- Isolate the network: If you suspect a wider compromise, consider temporarily switching off Wi-Fi for all devices until you know more.
- Change critical passwords: For compromised accounts immediately: cloud storage, social media and email. Start with admin accounts.
- Delete nothing: Suspicious files are evidence; keep them for the investigation.
Step two: assess the situation
- What happened?: For example: “files are encrypted” or “unauthorised posts on Instagram”.
- When did it happen?: Try to establish a timeline.
- Which systems and accounts are affected?: For example: “the main file server” or “the client’s account on X”.
- What data is at risk?: For example: “all Q3 project files” or “client X’s customer list”.
Step three: escalate and communicate internally
- Notify the right people: If you are a freelancer, that person is you. In an agency, notify the owner or designated team lead at once, and do not hide the problem or try to fix it alone.
- Form a response team: Even in a small agency: who is the technical lead investigating? Who handles client communication?
- Document everything: A timestamped log of every action, invaluable for the investigation and for communication later.
Communicating with Clients: Honesty and Transparency
How you communicate with a client during a crisis makes or breaks the relationship. The key is to be honest, transparent and proactive. When should you tell them? If the incident has any potential impact on the client’s data, project timeline or brand, tell them; it is far better for them to hear it from you than to discover it themselves. Deliver the message by phone or video call first, then follow up by email. Here are two templates to start from.
Initial notification template
Subject: Important security update regarding our project. Hello [Client name], I am writing to let you know about a security incident we discovered on [date]. We are still investigating, but I wanted to inform you as soon as possible as a precaution. What we know so far: [brief, factual description, e.g. “we detected unauthorised access to one of our internal servers”].
Our priority is securing our systems and understanding the full scope, and we have already: [one or two containment actions, e.g. “isolated the affected server and engaged a cybersecurity expert”]. We are treating this with the utmost seriousness, and I will send you another update by [time/date]. Kind regards, [Your name].
Follow-up update template
Subject: Update on the security incident of [date]. Hello [Client name], as promised, our investigation has found that [clear update on impact, e.g. “the folder containing initial design drafts for your project was accessed” or “your project files specifically were not accessed”].
We are implementing [remediation, e.g. “additional security monitoring across our network”] to prevent this from happening again. We sincerely regret this situation and remain committed to protecting your data; I am happy to answer any questions. Kind regards, [Your name].
2026 Update
Many data protection laws require reporting a personal data breach within a short deadline; the EU regulation, for instance, allows 72 hours to notify the supervisory authority. Know your legal deadline before you need it, and add it to your response plan.
After the Storm: The Post-Incident Review
Once the incident is resolved, hold a “lessons learned” session. The aim is not to blame anyone but to make the agency stronger. Bring everyone involved in the response into one room and ask the key questions:
- What was the root cause of the incident?
- What went well in our response?
- What did not go well, and where were our weaknesses?
- How could we have detected the incident sooner?
- What can we do to prevent this specific incident from happening again?
Then turn the answers into a concrete action plan with owners and deadlines. For example: “Enable two-factor authentication on all cloud accounts · Owner: [name] · Deadline: [date]”, and “Update the client contract template with a new security clause · Owner: [name] · Deadline: [date]”. By treating the incident as a learning opportunity, you turn a negative event into a catalyst for a more resilient and trustworthy business.
Lessons Learned
- 1An incident may be a breach, ransomware, an account takeover, IP theft or a denial of service.
- 2Contain first, and do not delete the evidence.
- 3Tell the client early and honestly, by call and then by email.
- 4The post-incident review looks for the cause, not a culprit.
Tip: use ← → to move between sections.

