Emergency IT · same-day
My business has been hacked — emergency help across Dorset
Take a breath — you've come to the right place. We give local businesses in Bournemouth, Poole, Christchurch and across Dorset fast, same-day help to contain a live cyber attack, get you back working and lock the door behind whoever got in. Rated 4.9 on Google.
- ● Same-day local response
- ● Windows & Microsoft 365 specialists
- ● Remote-first, on-site when needed
What To Do · Right Now
First 10 minutes: what to do before you call
If you think your business has been hacked, the next few minutes matter. Work through this calmly — you don't need to be technical, and you can call us on 01202 775566 at any point and we'll talk you through it live.
- Isolate the affected device from the network. Unplug the network cable and turn off its Wi-Fi. Do not switch the machine off if you can see a ransomware note or files being encrypted — powering down can destroy evidence and, in some cases, the only chance of recovery. Just disconnect it from the internet and other computers.
- Stop using any compromised accounts. If an email account, Microsoft 365 login, server or online banking has been accessed, stop sending from it and don't act on any instructions in it.
- Change passwords from a clean device — a different, un-affected computer or your phone on mobile data, not the hacked machine. Start with email and Microsoft 365, then anything that shared that password. Turn on multi-factor authentication (MFA) as you go.
- Tell your bank immediately if any money or payment details are involved — a diverted invoice, a fraudulent transfer, or card details exposed. Time is critical for recovering funds.
- Preserve the evidence. Don't wipe, reinstall or 'clean up' the affected device or server. Take photos of any ransom note or suspicious message on your phone.
- Warn your staff not to open anything unusual, click links in emails that appear to come from you or a colleague, or pay any invoice without verbally confirming it.
- Then call us on 01202 775566 and we'll take it from there.
We are not forensic investigators or lawyers, and we won't pretend to be. What we do is get your business contained, recovered and secure — fast — and point you to the right authorities where you need them.
// NEED THIS FIXED RIGHT NOW?
Skip the DIY — call 01202 775566 and we can be looking at your screen within minutes. You watch everything we do, and most problems on this page are fixed in one short remote session. (Mon–Fri, 9am–5pm.)
How We Help · Contain & Recover
How we get you back working — and secure
Once you call, we move quickly and methodically. Most of it we can start remotely within minutes using Splashtop SOS — we phone you first, connect only with your permission, you watch the whole session on screen, and access ends the moment we're done. If hands-on work is needed, we come to you across Bournemouth, Poole, Christchurch and Dorset the same day where we can.
- Rapid triage — we work out what's actually happening: email compromise, ransomware, a breached account, a compromised server, or a diverted payment.
- Contain and isolate — we stop the spread across your network, cut off the attacker's access and secure the accounts and systems they got into.
- Find how they got in — a phished password, a dodgy email rule, malware, an exposed server or a weak login — so we're fixing the cause, not just the symptom.
- Remove the malware and the access — clean the affected machines and servers, kill rogue mailbox rules and forwarding, and revoke sessions and app permissions the attacker set up.
- Reset credentials and enforce MFA across email, Microsoft 365 and your key business systems, so a stolen password alone can't get anyone back in.
- Restore from a clean backup where files, mailboxes or servers have been encrypted or lost — checking the backup itself is clean first.
- Harden everything afterwards — MFA everywhere, proper email security, tested backups and staff training — so it's far harder for this to happen again.
We're Windows and Microsoft 365 specialists who look after servers, networks, email, security and backups for local businesses — so account breaches and email compromise are very much our home ground.
Report It · The Right Authorities
Who to report the attack to
Alongside the technical recovery, there are people you should tell. We'll remind you of these and help you gather what you need — but the reports themselves are yours to make.
- Action Fraud — report cyber crime and fraud (including diverted payments and business email compromise) to Action Fraud on 0300 123 2040, the UK's national reporting centre. If money has been taken, tell your bank first.
- Your bank — straight away if any payment, transfer or card detail is involved, so they can try to stop or recover funds.
- The ICO — if personal data (customer, staff or supplier information) may have been lost or exposed, a personal-data breach must be considered for reporting to the Information Commissioner's Office, generally within 72 hours of you becoming aware of it. Not every incident is reportable, but the 72-hour clock means you should assess it quickly.
- Your insurer — if you hold cyber insurance, check your policy's notification requirements early, as some have their own incident procedures.
We're not lawyers or insurers, so treat the above as practical pointers rather than legal advice — but we'll make sure you know who to contact and when.
Why 365 Techies · Local & Honest
A local, honest team when it matters most
When your business has been hacked you want someone calm, close and straight with you — not a call centre. We're a family-run Dorset IT firm, trading since 1995, a Microsoft Partner and rated 4.9 on Google, supporting businesses across Bournemouth, Poole, Christchurch and Dorset.
We're honest about what we are: fast, same-day, remote-first local help that gets your business contained, recovered and properly secured. We work Monday to Friday, 9am to 5pm — we don't claim a 24/7 hotline we can't stand behind. What we do promise is a real person who knows Windows, Microsoft 365 and servers, who'll pick up the phone, and who'll stay with you until you're working safely again.
After the emergency, we can keep you protected with ongoing cybersecurity support, help you achieve Cyber Essentials, and put staff training in place — all on rolling monthly, cancel-anytime plans with no long lock-in.
// RELATED
Related help: our ongoing cybersecurity support, dealing with business email compromise, achieving Cyber Essentials, and security awareness training to stop the next attack. Need us now? Get in touch or call 01202 775566.
FAMILY-RUN SINCE 1995 · ★ 4.9 ON GOOGLE · 200+ COMPUTERS UNDER OUR CARE · NO FIX, NO FEE · SAME-DAY REMOTE SUPPORT
// GOOD QUESTIONS
Frequently asked
My business has been hacked — what should I do first?
Disconnect the affected device from your network and the internet, but don't switch it off if ransomware is actively running. Stop using any compromised accounts, change passwords from a clean device and turn on MFA, and tell your bank straight away if any money or payments are involved. Preserve the evidence rather than wiping anything, then call us on 01202 775566.
Should I turn off the computer if I see a ransomware note?
No — not straight away. Powering the machine off can destroy evidence and, in some cases, the best chance of recovery. Instead, disconnect it from the network and Wi-Fi to stop the spread, leave it on, photograph the ransom note with your phone, and call us so we can advise before you do anything else.
How quickly can you help if we're being attacked right now?
We offer same-day help and can usually begin remote triage within minutes using Splashtop SOS — we phone first, connect only with your permission, and you watch the whole session. If on-site work is needed we come to you across Bournemouth, Poole, Christchurch and Dorset the same day where we can. Our hours are Monday to Friday, 9am to 5pm.
Do you do forensic investigation or handle the legal side?
No. We're not forensic investigators, lawyers or insurers, and we won't pretend to be. What we do is practical incident response — contain the attack, remove the access, recover your data and harden your systems — and point you to the right authorities, such as Action Fraud on 0300 123 2040 and the ICO for a personal-data breach.
Do I need to report the attack to anyone?
Usually, yes. Report cyber crime and fraud to Action Fraud on 0300 123 2040, and tell your bank immediately if money or payments are involved. If personal data may have been exposed, a breach must be considered for reporting to the ICO, generally within 72 hours of you becoming aware. We'll help you work out what applies.
Can you stop this happening again?
Yes — that's a core part of the job. Once you're recovered we harden everything: MFA everywhere, stronger email security, tested backups and staff awareness training. We can also help you achieve Cyber Essentials and put you on ongoing cybersecurity support so someone's watching your back with no long lock-in contract.
Under attack right now? Call us — we'll pick up.
Fast, same-day local help from a family-run Dorset firm rated 4.9 on Google. We connect remotely in minutes with your permission, contain the attack and get you working again. Phone 01202 775566, Mon–Fri 9am–5pm.
01202 775566 · help@365techies.co.uk · MON–FRI 9AM–5PM