Containment
A full copy of the infected state, every credential changed, sessions closed and a maintenance page if needed.
When a site has been hacked, the temptation is to delete whatever looks odd, change the admin password and move on. It almost never works: attackers usually leave several ways back in, some outside the site itself, in FTP, the hosting account or a scheduled task, and they return within days. Take an Alicante estate agency that finds on Monday that its site redirects to a casino, Google lists thousands of Japanese pages under its domain and the host has suspended the account for spamming. Getting it running again is urgent, but so is understanding what happened, or the clean-up only lasts until the following weekend.
Recovery covers the site, the hosting and the email, because an attack rarely stays in one place. These are the tasks.
A full copy of the infected state, every credential changed, sessions closed and a maintenance page if needed.
Logs, modification dates, added users and scheduled tasks, vulnerable versions and any possible access to personal data.
Core, plugins and theme reinstalled from official sources, the database sanitised and content verified, or a clean backup restored.
The vulnerability fixed, abandoned plugins removed, two-factor sign-in and filtering rules placed in front of the site.
Blacklist checks, delisting requests, SPF, DKIM and DMARC verification and a review request in Google Search Console.
A report with timeline, scope and actions taken, useful for deciding on AEPD notification, for the insurer or for a police report.
We start as soon as we have access. An information site is usually back the same day; a shop compromised for weeks needs longer.
A full copy of the current state as evidence, every credential changed and a joint decision on whether the site goes offline or shows a maintenance page.
Rather than hunting through files one by one, we rebuild the site from official components and verified content, or from an earlier clean backup.
The entry point fixed, two-factor sign-in for administrators, hosting and email reviewed, and filtering rules added.
Review requests in Google Search Console and on blocklists, junk pages removed from the index and a final report on what happened with recommendations.
Email is often the second casualty. A compromised host that sends spam ends up on blacklists, and for days the company's normal email, invoices included, lands in customers' spam folders or never arrives. So alongside the website we check whether the domain and server appear on blocklists, request delisting and verify SPF, DKIM and DMARC.
If the attack may have affected personal data and poses a risk to people, the GDPR requires the breach to be notified to the AEPD within 72 hours of becoming aware of it. We provide the technical facts to assess the risk; the decision and notification rest with your company as controller.
That depends on how far the attack reached and the state of your backups. A small information site is often sorted in a few hours; a shop with live orders and no backups takes considerably more. Work is billed at €75 per hour + VAT, with an estimate as soon as the initial diagnosis is done.
Many policies cover recovery and require the incident to be documented. We keep a copy of the infected state and prepare a technical report with dates, scope and actions, which is usually what insurers ask for. Check your policy first in case it names a required supplier.
Yes. You can file a report with the Policía Nacional or the Guardia Civil, and our technical report serves as supporting evidence. INCIBE also offers businesses free guidance on what to do after an incident.
Keep updates current, run few plugins, require two-factor sign-in for administrators, store backups off the server and use monitoring that alerts you before visitors notice. That is exactly what a care plan covers, making it the natural next step after an incident.
Tell us what you are seeing and when it started. Include your host and the platform the site runs on so work can begin immediately.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.