“What do I do if…” — real situations, and where we would begin. The first step, the reasoning underneath, and an honest read on how worried you should be.
Not to frighten you into a call. Where a risk is overblown, we say so plainly.
Growing something and protecting it are the same job. Both are here.
Built from situations people actually bring us. Send us yours and it gets added.
If something is happening right now and money is moving or systems are locked — filter to “Happening now” below, then call someone. Not deciding alone is the most underrated control there is.
This page is general education, written from our own experience and from published research. It is not advice about your specific situation, your systems, your contracts or your legal obligations — and it cannot be, because we cannot see any of those.
Treat every scenario as a starting point for your own research, not an instruction. Verify anything consequential independently, and where money, data, staff or regulators are involved, get qualified professional help before you act. You proceed at your own risk, and responsibility for the outcome stays with you.
Situations differ in ways that change the right answer completely. Something that is correct for a sole trader can be wrong for a regulated practice with an insurance policy and a notification duty.
Ordered roughly by how fast you need to move. The red ones are where minutes matter.
1. Disconnect, do not power off. Unplug the network cable, switch off Wi-Fi. Leave the machines running — shutting down destroys evidence that investigators need, and some variants do further damage on reboot.
2. Photograph the ransom screen with your phone. The note, any ID or reference on it, the file extensions. You will need this.
3. Call your cyber-insurance provider before you call anyone else. Most policies require you to use their approved incident responders. Bringing in your own IT firm first can void the claim entirely.
4. Do not pay, and do not decide alone. Not yet, and not in the first hour.
The instinct is to fix it fast and quietly. Almost every expensive mistake in a ransomware incident comes from that instinct — powering machines off, wiping and rebuilding, paying early, or calling a responder your insurer has not approved.
The insurance point is the one that surprises people most. Cyber policies typically name a panel of firms you must use. Organisations regularly do the sensible-seeming thing, call their usual IT support, and discover weeks later that the claim will not pay.
We are not going to tell you never to pay, because that decision belongs to you and your counsel, and sometimes an organisation genuinely has no other route to survival. We will tell you what paying does not do: it does not un-steal the data, it does not remove your notification obligations, and decryption tools supplied by attackers are frequently slow and incomplete.
1. Do not act on the call. Not even partially. Not “just start the paperwork so we are ready.”
2. Hang up and call back on the number you already have. Not a number given during the call. Not one in the email that follows. The one that was in your phone yesterday.
3. If you cannot reach him, tell one other person. The point is not permission — a second human breaks the spell. Every version of this attack depends on you being alone with the decision.
Voice cloning now needs only seconds of source audio — a podcast, a conference talk, a voicemail greeting, a video on your own website. It is cheap, fast, and no longer reliably distinguishable by ear. Recognising a voice has stopped being a control.
Notice what the attack actually runs on, because it is not the audio. It is urgency, authority and secrecy. The request is always time-critical, always from someone you would not push back on, and almost always framed as confidential — a deal not yet announced, something the team must not hear about. That framing exists for one reason: to stop you checking.
Agree a verification habit now, while nothing is happening. Two things, both free:
And say this out loud to your staff: nobody will ever be disciplined for slowing down a payment to check. If your culture punishes hesitation, you have built the vulnerability yourself.
1. Do not pay it. Do not reply to it. Replying tells them a human is reading, and the reply goes to them, not your supplier.
2. Phone your supplier on the number you had before this email arrived. From your records, a previous invoice, or their website you navigated to yourself. Never the number on the new invoice.
3. Ask one specific question: “Have your banking details changed?” Almost always, the answer is no and they have no idea this is happening.
Because it probably is right — it is often a real invoice. Either your supplier’s mailbox has been compromised and someone is watching the thread, or a genuine invoice was intercepted, the bank details swapped, and the whole thing resent from a lookalike address.
That is why the usual advice fails here. The logo is correct, the amount is correct, the reference matches a real job, and the tone is right because earlier messages were there to copy. The only wrong detail is the one that moves the money.
Look hard at the domain. A letter swapped, a hyphen added, .co instead of .ca, or rn where an m should be. On a phone, in a hurry, these are effectively invisible — which is the entire point.
Any change to bank details gets verified by voice, on a known number, every single time. No exceptions for regular suppliers, urgency, or a plausible explanation about switching banks. Write it down, tell whoever pays invoices, and make it boring.
Do not open the attachment, and do not click anything in it. The invoice may not be the point — the attachment often is.
Check whether anyone in your organisation ordered anything before assuming it is fake. Then delete it, or report it to your IT provider if you have one.
Malware delivery. The attachment is the payload and the invoice is just a reason to open it. Anything that asks you to “enable content” or “enable macros” is this, every time, with no exceptions worth considering.
Or simple opportunism. Plausible invoices for modest amounts sent in volume, betting that a busy finance person pays without checking. Domain renewals, directory listings and office supplies are the classics, and the amounts are deliberately small enough not to trigger scrutiny.
If someone already opened the attachment, treat it as a possible infection rather than a nuisance: disconnect that machine from the network, and get it looked at before it goes back on.
1. Do not click the link. Not to check it, not to “cancel the request”. That button is the whole attack if the email is fake.
2. Go to the service directly — type the address yourself or use your own bookmark — and sign in normally. If there is a genuine problem, you will see it there.
3. While you are in there, change the password and check what devices are signed in. If this is a real reset request, someone knows your address and is actively trying.
The commonest case. The email is a lure, the link goes to a convincing copy of the login page, and typing your password there hands it straight over. Read the domain after the @ rather than the display name, and remember the padlock on the fake site means nothing — certificates are free.
This one gets dismissed as spam far too easily. A genuine reset email you did not request means somebody typed your address into that login page and clicked “forgot password”. It is not an attack that succeeded — it is an attack in progress, and you are being told about it.
If it keeps happening, treat it as targeting rather than noise.
1. Give it nothing. No passwords, no card numbers, no verification codes. A legitimate assistant never needs any of these — not to “confirm your identity”, not to “continue”.
2. Do not follow links it produces, and do not run commands or scripts it tells you to run.
3. Start a completely new conversation. Do not carry the old one on. Whatever is steering it lives in that thread.
This is usually prompt injection. Instructions get hidden inside content the assistant reads on your behalf — a web page it browsed, a document you uploaded, an email it summarised. The assistant cannot reliably tell the difference between your instructions and instructions buried in the material, so it follows both.
That is why the behaviour change is often sudden and tied to a moment: right after it opened a link, read a file, or processed a message. The text may be invisible to you — white on white, or tucked in metadata.
Work out what that assistant was connected to. If it has access to your email, files or calendar through an integration, the exposure is far larger than a strange conversation. Review connected apps and revoke anything you do not actively need.
Look back at what you pasted earlier in that thread. If client data, credentials or anything confidential went in before the behaviour changed, treat it as potentially disclosed and handle it accordingly.
Then report it to the vendor. These get fixed when people report them.
Bin it. Both of them. Do not plug it in “just to see whose it is”, not even on an old laptop, not even one you think does not matter.
If it turned up somewhere it should not have — inside a locked office, on a reception desk, in a bag — tell someone before you throw it away. That is a different conversation.
Researchers have repeatedly scattered USB drives in car parks and measured how many get plugged into work machines. It keeps working, because curiosity is the exploit. Wanting to find the owner is a perfectly decent instinct, and it is the instinct being used.
Worse, a hostile drive need not behave like a drive at all. Devices exist that are physically identical to a memory stick but announce themselves to the computer as a keyboard, then type commands faster than you can read. Nothing warns you, because as far as the machine knows, somebody is typing.
Malicious cables are real and sold openly as penetration-testing tools, with the electronics hidden inside the moulded connector. They are indistinguishable from an ordinary cable by eye or by weight.
We will be straight with you though: we are not aware of documented cases of these being used against ordinary consumers. They are a professional tool, and the likelihood that the mystery cable in your drawer is one of them is low.
Because of a principle worth carrying beyond this page:
When doing the safe thing costs you nothing, you do not need strong evidence to justify it. When it costs you money or attention, you do.
Binning a cable you never owned costs nothing. That is why this advice is easy, and why we give it confidently despite thin evidence — whereas we tell you not to worry about airport charging points, because avoiding those costs you something real for a threat nobody has documented.
The other half. Same format — what to do first, the reasoning underneath, and an honest read on how hard it actually is.
1. Check you went through Goodstack. Google’s validation partner is Goodstack (formerly Percent) — not TechSoup, despite a lot of advice online still saying so. If you started somewhere else, that alone can stall the whole application.
2. Get the actual rejection reason in writing rather than working from a summary. “Not to spec” covers several very different problems with very different fixes.
Fix HTTPS first, because nothing else is assessable without it. Then make the homepage answer three questions plainly: who you are, who you help, and what happens next. Then reapply.
Getting approved is the easy half. Keeping it is where charities lose the grant — a 5% click-through minimum, active conversion tracking, no single-word keywords, and an account that has to actually be managed. A meaningful share of approved organisations lose it within a year to rules nobody walked them through.
So before you celebrate approval, decide who is going to run it. An unmanaged Ad Grant does not sit idle; it gets suspended.
Before touching any code, write down what counts as a win. A booked call? A form sent? A phone number tapped? A donation? You cannot measure a conversion you have not defined, and most tracking setups fail here rather than technically.
Then install one container, not five separate snippets. Google Tag Manager gives you a single piece of code on the site and everything else configured inside it.
A snippet or tag is a small piece of code a platform gives you to paste into your site so it can see what visitors do. A conversion is you telling that platform which action was worth something. A container holds all of them so you are not pasting code every time.
Cookie consent. If you serve visitors in regions with consent requirements, tags must respect the choice made. Bolting consent on afterwards is far more painful than planning for it.
Untested tracking. Broken conversion tracking is the most common root cause we find behind “our marketing does not work”. It is worse than none, because it produces confident numbers that are wrong.
Plainly: you pay other people commission for sales they send you. They promote, you pay only when something actually sells, and tracking links tell you who sent what.
The honest answer on timing: if the holiday season is weeks away, this is not your lever. Affiliate programmes take months to recruit and build trust. Set it up now for next season and use something faster for this one.
Affiliates must clearly disclose that links are paid. In Canada this sits under the Competition Act’s rules on misleading representations, and the Competition Bureau has been increasingly active on undisclosed influencer and affiliate promotion. Enforcement can land on the brand, not only the affiliate — put disclosure requirements in your terms and actually check compliance.
Works well for products with healthy margin, clear appeal and an existing audience of reviewers or creators in the category. Works badly for services, anything with a long or consultative sales cycle, or thin-margin goods.
If you want revenue this holiday season, the faster levers are your existing email list, your Google Business Profile, and making sure the checkout actually works on a phone. Unglamorous, and they pay this month.
1. Do not open a second Google Ads account. This is the single most damaging instinct, and it is the one almost everybody has. Creating a new account to get around a suspension is itself a policy violation and can turn a fixable problem into a permanent one.
2. Find out which kind of suspension this is. Sign in and read the notice at the top of the account. A policy suspension names the rule. An inactivity or programme-compliance pause is a different animal with a different fix.
3. Do not reapply or appeal until you have actually fixed something. A rejected appeal is a worse position than an unfiled one.
Fix the cause before you touch the appeal. Remove the offending keywords, rebuild the ad groups around specific intent phrases, get conversion tracking verified and firing, set your geography properly. Then submit the reactivation request and say plainly what was wrong and what you changed.
Expect it to take time. Reviews are not instant and chasing does not speed them up.
Then fix the reason it happened. A suspension is nearly always the account telling you it was never set up to the programme’s rules in the first place. Reinstating it without changing how it is run buys you a few months.
You are right that you did not need one. Twenty years of business on reputation and word of mouth is a genuine asset, and most companies with beautiful websites would trade them for it. Nobody should tell you otherwise, and anyone who opens by suggesting you have been doing it wrong is selling, not advising.
What changed is not websites. It is what people do before they call you. They look you up first — to check you are real, still trading, and the same business somebody just recommended. When there is nothing to find, some of them stop there. You never hear about those, which is exactly why the gap is invisible.
Not a big build. Not a monthly retainer for content nobody reads. For a great many established businesses, a properly completed Google Business Profile plus one honest page — who you are, what you do, where, how to reach you, a few real photos, a handful of real reviews — captures most of the value. Anyone quoting a large project before asking what you actually want more of is guessing.
And a bad site is worse than none. A neglected page with a dead phone number, 2019 prices, or a contact form that goes nowhere actively costs you work. If you are not going to keep it current, keep it small enough that it stays true.
Register your own domain name and put your email on it, even if the site can wait. It is a small annual cost, it is yours, and it prevents somebody else registering your business name later.
Real things people have said to us, close to word for word. Some are emergencies. Most are the quieter kind — a question someone carried around for a year because nobody gave them a straight answer, or one they are living with this week and have not said out loud yet.
Several of these sit across both halves of the job at once, and are labelled Grow + Protect. Those show up under either filter, because the problem genuinely does.
Hit a term you do not know? The glossary explains every word on this site in plain English — written on the assumption that nobody is born knowing this.
Start with what is true here, because most of it is. “Fine so far” is real evidence and it deserves respect — you have run a business for years without an incident, which plenty of far better-resourced organisations cannot claim. And Windows Defender is genuinely good now. Anyone who tells you it is worthless is selling something.
The gap is not that you were wrong. It is that “nothing has happened” and “we are not exposed” feel like the same sentence, and they are not. One is a record. The other is a forecast.
What changed is not that threats got cleverer. It is that they got automated and indiscriminate. Most attacks on small organisations are not aimed at you — nobody chose you. Scanners sweep the whole internet for a known weakness and take whatever answers. Being small used to mean being uninteresting. Automation removed that protection, because the cost of trying you fell to nearly nothing.
Defender handles the file-on-the-disk problem well. It does not cover the three things that actually cause bad weeks: someone signing in as you with a working password, a backup nobody tested, and an account you forgot to switch off. Those are not virus problems, so no antivirus was ever going to catch them.
Word of mouth built this. Keep it — but notice that it is a single channel you do not control, and its capacity is capped by how many people happen to know you. That is concentration risk in commercial clothing. It is the same shape of exposure as one customer being 60% of revenue, and it is fine right up until the week a key referrer retires.
That is most of the risk, and none of it is a project. If someone is quoting you a monthly retainer before they have asked whether your backup restores, they are selling a product rather than answering your question.
Mostly, no — and a great deal of what you are seeing is theatre. Plenty of businesses announce AI adoption and change almost nothing about how they work. Some are worse off, having added a tool nobody governs.
But two real things hide inside the question, and they pull in opposite directions: a genuine efficiency gain on repetitive work, and a visibility shift that is happening whether or not you adopt anything. Those deserve separate answers.
Narrow, boring, repetitive text work. First drafts, summarising a long document, turning notes into something sendable, rewriting the same reply for the hundredth time. The gain is real but unglamorous, and it is measured in hours rather than transformation.
Anything promising strategy, judgement, or replacing a person who knows your customers. And anything sold as an “AI platform” that is a normal product with a new label on the pricing page.
This is the part that has nothing to do with whether you adopt a tool. People increasingly ask an assistant for a recommendation instead of scrolling a results page, and those answers are assembled from sources the model can find, read and quote. If your business is thinly documented online, you are not losing that comparison — you were never a candidate in it.
So the defensive move is not buying AI. It is making sure clear, accurate, specific information about what you do exists somewhere machine-readable. That is closer to writing a good page than to adopting a platform.
Decide what must never be pasted in, and say so out loud, before anyone starts. Client records, anything covered by a confidentiality clause, payroll, credentials. The most common AI incident in small organisations is not a rogue model — it is a well-meaning employee pasting something sensitive into a personal account nobody knew existed.
1. Change the password and sign out every session. Changing the password alone is not enough — an attacker with an active session stays in. Look for “sign out everywhere” or “revoke sessions”.
2. Check for mail rules and forwarding you did not create. This is the step people skip, and it is the one that matters most. A rule quietly copying your mail outward, or filing anything containing “invoice” into a folder you never open, means they intended to stay. Remove them and note what they were.
3. Read the Sent and Deleted folders. What went out, and to whom? If anything asked a customer or supplier to change bank details, phone those people now — do not email them.
4. Check the recovery email and phone number on the account. Changing these is usually the first thing done once inside.
This is business email compromise, and it costs organisations more than ransomware does. There is no malware to find and nothing looks broken — someone simply signed in as you and read your mail until they understood how your money moves. Then they sent one message, from a real address, at a plausible moment.
That is why it defeats staff training. The email is genuine. It comes from the right person, continues a real thread, and uses the right vocabulary.
Assume anything in that mailbox was read. If it held client records, contracts, or personal information, you may have a notification obligation — that is a question for your lawyer and, if you carry it, your insurer. Tell the insurer early; policies often require prompt notice, and a delay can matter more than the incident.
Restore something this week. Not check the dashboard, not confirm the green tick — take one real file, or better a database, and bring it back. Time how long it takes and write the number down.
Until you have done that, you do not have a backup. You have a hypothesis. That is not a slogan — a meaningful share of the failed recoveries we hear about involve a backup that had been running, and reporting success, for months.
Get one copy out of reach. Offline, or immutable — meaning it cannot be altered or deleted for a set period even by someone holding valid credentials. This single property is what makes the difference between a bad week and an existential event.
Answer two questions in plain numbers. How much work can we afford to lose — an hour, a day? And how long can we be down before this becomes serious? Those two answers drive every other decision, and most organisations have never been asked them.
Then test on a schedule and keep the evidence. Quarterly is reasonable for most small organisations. Note what you restored, how long it took, and what broke. That record is also what an insurer or a board will ask for.
Cloud file sync is not a backup. It is a mirror, and it faithfully mirrors encryption and deletion. Versioning and recycle bins help, but they have limits and attackers know exactly what they are.
The honest answer is that most organisations do not know, and the number using these tools is higher than leadership thinks. This is called shadow AI, and the pattern is consistent: capable people solving real problems with a tool nobody told them not to use.
The exposure is rarely malice. It is a personal account — outside your tenant, outside your logging, with settings and retention you do not control and cannot audit.
Whatever someone was already struggling to write. Contracts being summarised. Client emails being softened. Spreadsheets pasted wholesale to ask what a pattern means. Source code. Draft board papers. Almost always the thing that was hardest to do, which is usually the thing that was most sensitive.
A ban moves the activity onto phones and personal laptops, where you have no visibility at all. You trade a manageable problem for an invisible one, and you lose the ability to help people do it safely.
AI features are arriving switched on inside tools you already pay for — note-takers joining meetings, assistants summarising mailboxes, features added in an update nobody read. So “we do not use AI” is frequently untrue by the time it is said. Worth checking what is enabled by default across your existing subscriptions.
This is almost never a marketing problem. It is a measurement problem, and it is the single most common thing we are asked about on the Grow side.
In most cases one of three things is true: conversion tracking was never installed correctly, enquiries arrive by routes nobody counts — phone calls, walk-ins, replies to a personal inbox — or the numbers exist but sit in four dashboards that disagree with each other. You are not failing to read the data. There is no single version of it to read.
Define one thing that counts as a win — a booked call, a submitted form, a completed sale. Then check it is actually being recorded. Broken or missing conversion tracking is so common that we treat it as the default assumption until proven otherwise, and until it is fixed every other number on this list is decoration.
Not a dashboard with forty numbers. Three numbers you trust: how many enquiries arrived, where they came from, and what a customer costs you to acquire. Most organisations we meet cannot answer the third, which is the one that decides whether any of the spending is sensible.
Once this is measured properly, you will probably discover that something you have been paying for monthly is producing very little. That is the point, and it is usually uncomfortable — often the thing that looks busiest is the thing contributing least.
The question is almost never really about technology. It is about whether anyone is accountable. A board asking this is asking whether someone owns the risk. An insurer is asking whether you qualify for the price they quoted. A client is asking whether you are a safe link in their own supply chain.
Those three want different evidence, and the most common mistake is answering with a list of products. “We have antivirus and a firewall” reads, to all three audiences, as though nobody is in charge.
Treat the application as a technical questionnaire with contractual weight, because that is what it is. Questions about multi-factor authentication, backups, endpoint protection and patching are conditions, not curiosity. Answering optimistically is the genuinely dangerous move — a claim can be challenged on the basis of what you attested to. If you are not certain, verify before you tick.
Expect a questionnaire that was written for a company twenty times your size. It is reasonable to answer “not applicable at our scale, and here is what we do instead”. Do not invent a policy to fill a box. If you claim one, you may be asked to produce it and to show it is followed.
One page covering the four points above. That page is worth more than any tool purchase, because it is what turns scattered good practice into something you can show. Being able to evidence what you do is now part of doing it.
This page grows from real situations, not from a list we invented. If something happened to you and it is not here, tell us — anonymised, no detail we would ever publish, and we will write it up so the next person finds an answer instead of a panic.
If money is moving right now, stop reading and phone your bank — use the word fraud. Then report it to the Canadian Anti-Fraud Centre. Speed matters more than getting the sequence perfect.
Several of these are questions people carried around for months without getting a straight answer. If one of them is yours, book a free conversation or just email the question. No pitch, no obligation.
And we will tell you if you do not need us. Some of what is on this page you can do yourself in an afternoon, and we would rather say so than sell you something.
Redefine LogicWe help small businesses, nonprofits and co-ops grow safely — marketing that brings people in, security that protects what you build.
© 2026 Redefine Logic Media™. All rights reserved.
Redefine Logic Mediaâ„¢ is committed to making this website usable by as many people as possible, regardless of ability or the technology they browse with. We treat accessibility as ongoing work rather than a one-time task.
We aim to meet the Web Content Accessibility Guidelines (WCAG) 2.2 at Level AA. We test with keyboard-only navigation, screen readers and automated tooling, and we fix issues as we find them. We are not claiming full conformance across every page — where we fall short, we want to know.
This site includes an accessibility toolbar that lets you adjust the page to suit how you read and navigate. It changes only how the page is presented in your browser; it does not send your choices anywhere, and it does not replace the underlying accessible markup of the site.
The toolbar can:
This site is built to work with screen readers such as NVDA, JAWS, VoiceOver and TalkBack, and to be fully operable with a keyboard alone. If you use assistive technology and something does not work as expected, that is a bug on our side, not yours — please tell us.
Some third-party content — embedded maps, videos, payment forms and social feeds — is outside our direct control and may not meet the same standard. Where we can, we provide an accessible alternative. Where we cannot, we will help you get the same information another way.
If you hit something on this site you cannot use, please get in touch through the contact details on this site. Tell us the page and what went wrong, and we will respond and work with you on an accessible alternative.
Accessibility toolbar by Redefine Logic Media.