Prioritise accounts, updates, backups, reporting, and recovery in a manageable order. A small team also buys services, and the same checklist habit protects it when it hires outside help; trust signals to check before hiring a marketing provider is the version of this list for that purchase. This guide starts with actions that are low-risk, reversible where possible, and useful even when the exact cause is still uncertain. If there is an immediate financial, workplace, safety, or legal concern, use the responsible provider or local authority’s current process.
First ten minutes
- 01Pause before deleting or resetting
A rushed clean-up can remove the detail that makes recovery easier.
- 02Record the time, what changed, and the account or device involved
A short note is often more useful than a perfect reconstruction later.
- 03Use a trusted route to the relevant provider or team owner
Open saved bookmarks, device settings, or official support pages rather than links from an alert.
What to preserve
Keep the message, notice, filename, time, affected address or device name, and screenshots of unusual settings if doing so is safe. Do not send passwords, recovery codes, private keys, or unredacted identity documents to an unverified contact. A record supports a provider or team that needs to understand what happened.
Escalate when
Escalate when access cannot be recovered through an official route, a payment method or sensitive data may be involved, the event affects a workplace, or you are being pressured to act quickly. The appropriate destination might be an account provider, bank, employer, insurer, qualified incident responder, or public reporting route in your jurisdiction.
Recovery path
After containment, review recovery options, active sessions, forwarding rules, software updates, backups, and credentials reused elsewhere. Make one change at a time when you can, then write down what was changed. That record helps you avoid repeating work and gives a small team a usable handover.
A baseline covers a firm's own accounts, and the same first moves apply to the accounts behind a congregation's site. Securing a church website takes the checklist through a volunteer team's registrar, DNS and giving platform logins.
Small teams that run on tight budgets often share more than an office: they share a transmitter, a schedule, and a small audience that trusts them. If your organization is considering a low power FM radio station, the security baseline still applies. Passwords, backups, and a written plan for who holds the keys matter just as much when the signal is local. The FCC rules, the paperwork, and the daily operation of a community station are covered in our guide to low power FM radio, which pairs well with the checklist above.
Related dispatches
Church website security for volunteer teams · Small business grants in Scotland and the records they require · Cybersecurity incident first steps · How Security, Applied works
