FAQ
IT Emergency and Cybersecurity Questions, Answered
By BC Networks. Reviewed by Dave Brewer, Founder and CEO. Last updated .
BC Networks is a managed IT support and cybersecurity company in San Jose, California, serving Silicon Valley and Bay Area businesses since 1989. We work mainly with companies of about 50 to 250 employees. These are plain-English answers to the questions business owners ask us most, starting with what to do in an emergency.
Emergencies: What to Do Right Now
My network is down. Who do I call?
Call your IT support provider first. If you have a managed IT provider, they should already be monitoring your network and can often see the problem remotely. If you do not have one, call a local managed IT company that offers 24/7 help desk support and can send an engineer on-site if needed.
Before or while you call, a few quick checks help narrow it down:
- Check whether the problem is everyone or just one person. If only one computer is offline, restart it and check its cable or Wi-Fi.
- Look at your internet modem and firewall. Note which lights are off, red, or blinking. Your provider will ask.
- Check your internet service provider's status page or call them from a cell phone to see if there is an outage in your area.
- Restart the modem first, then the firewall or router, waiting a couple of minutes between each. Do not reset anything to factory settings.
- If you see anything strange, like ransom messages or files you cannot open, stop and treat it as a security incident instead.
BC Networks' help desk and security monitoring operate 24/7. San Jose and Bay Area businesses can call (408) 243-1100.
Who do I call for emergency IT support in San Jose?
For emergency IT support in San Jose, call a local managed IT and cybersecurity provider that runs a 24/7 help desk and can send engineers on-site. BC Networks is headquartered at 1735 Technology Drive in San Jose, has served Silicon Valley businesses since 1989, and runs its help desk and security monitoring around the clock.
When you call any provider in an emergency, have this ready:
- What stopped working and when it started.
- How many people or locations are affected.
- Any error messages, ransom notes, or strange emails (take a photo with your phone).
- What has changed recently, such as new software, a power outage, or a new employee.
- Your cyber insurance policy number, if you think it is a security incident.
BC Networks supports businesses in San Jose, Santa Clara, Sunnyvale, Mountain View, Palo Alto, Cupertino, Campbell, Los Gatos, Milpitas, Fremont, Redwood City, and San Francisco. Call (408) 243-1100.
Does BC Networks help businesses that are not already clients in an emergency? Yes. Call the main line, (408) 243-1100. After-hours emergency service is available and is built into the BC Networks phone and voicemail system, so urgent calls are handled outside office hours too.
I think we've been hacked. What should I do first?
Isolate the affected computers from the network, but do not turn them off or wipe them. Then call your IT or security provider and your cyber insurance carrier. Acting quickly limits the damage, and leaving machines powered on preserves evidence that investigators and insurers may need.
First steps, in order:
- Disconnect, do not power off. Unplug the network cable and turn off Wi-Fi on affected machines. Shutting down can erase clues stored in memory.
- Do not delete anything or reinstall. Wiping a machine destroys evidence and can void insurance coverage.
- Change passwords from a clean device. Use a computer or phone you know is not affected. Start with email, banking, and administrator accounts, and turn on multi-factor authentication (MFA) if it is not already on.
- Call your IT or security provider. They can check how far the attack spread and contain it.
- Notify your cyber insurance carrier. Many policies require prompt notice and may require you to use approved response firms. Read your policy or call your broker.
- Write down what you saw. Note times, messages, and who noticed what. Screenshots or phone photos help.
BC Networks' incident response service covers containment, coordination with forensics firms, and guidance on California breach notification rules. If you think your San Jose business has been hacked, call (408) 243-1100.
We got hit with ransomware. Should we pay?
The FBI advises businesses not to pay ransoms, because paying does not guarantee you get your data back and it funds more attacks. The decision is not yours alone, though. Talk to your cyber insurance carrier, legal counsel, and incident response team before any contact with the attackers.
What to do instead of rushing to pay:
- Isolate infected machines by unplugging network cables and turning off Wi-Fi. Leave them powered on.
- Do not contact the attackers yourself. Insurers and response firms often handle any communication.
- Call your cyber insurance carrier right away. Many policies require prompt notice and set rules for what happens next.
- Check your backups carefully. Backups that are offline or separate from your network are often the fastest way back. Your IT provider should confirm they are clean before restoring.
- Report the attack to the FBI at ic3.gov.
- Ask your attorney about notification duties. If personal data was exposed, California law may require you to notify affected people.
The best protection against a ransom demand is having tested backups before it happens. BC Networks helps San Jose businesses with ransomware response and recovery planning. Call (408) 243-1100.
An employee clicked a phishing link. What now?
Act fast but calmly. Disconnect the employee's computer from the network, have them change their password from a different device, and call your IT provider to check for malware or a stolen login. Most phishing damage happens when a stolen password goes unnoticed, so speed matters more than blame.
Steps to take in the first hour:
- Disconnect the computer from Wi-Fi and the network. Keep it powered on.
- Reset the employee's password from a clean device, and sign them out of all sessions in Microsoft 365 or Google Workspace.
- Confirm MFA is on for that account. If they entered an MFA code on the fake page, tell your IT provider.
- Check the mailbox for new rules that forward or delete email. Attackers often add these.
- Warn the rest of the team so no one else clicks the same message, and report it to your IT provider so it can be blocked.
- Thank the employee for reporting it. People who feel safe reporting mistakes report them faster.
BC Networks provides email security, phishing protection, and security awareness training for Bay Area businesses. If someone on your team just clicked a bad link, call (408) 243-1100.
Our email was compromised and is sending spam. How do we stop it?
Reset the account's password from a clean device, sign the account out of every session, turn on multi-factor authentication, and remove any forwarding rules the attacker created. Then call your IT provider to check whether other accounts or data were accessed. A compromised mailbox is often the start of invoice fraud.
What to do:
- Reset the password from a computer or phone you trust, and use a new password that is not used anywhere else.
- Sign out all sessions in your Microsoft 365 or Google Workspace admin center.
- Turn on MFA for that account and every other account that lacks it.
- Look for inbox rules and forwarding that send mail to outside addresses or hide replies. Delete them.
- Warn your contacts. Tell customers and vendors not to act on recent emails from that address, especially payment or bank change requests.
- Have your IT provider review sign-in logs to see what the attacker accessed and for how long.
BC Networks manages Microsoft 365 security and email protection for San Jose businesses. If your email is sending spam right now, call (408) 243-1100.
Our server crashed. What should we do?
Do not keep restarting it or try repairs you are unsure about. Write down any error messages, check whether power, cooling, or storage lights show a problem, and call your IT provider. Repeated restarts on a failing drive can turn a recoverable problem into data loss.
Steps to take:
- Note what you see. Photograph error screens and any warning lights on the server.
- Check the basics. Is the power strip or battery backup (UPS) on? Is the server room unusually hot?
- Avoid repeated reboots if you hear clicking or grinding, or if you see disk errors.
- Tell your team what is affected and what workarounds exist, such as using cloud copies of files.
- Confirm when your last good backup ran. Your IT provider will need this to plan recovery.
BC Networks provides server management, backup, and disaster recovery for businesses across the Bay Area, with local engineers for on-site support. Call (408) 243-1100.
Why does our Wi-Fi keep dropping across the office?
Office-wide Wi-Fi drops usually come from overloaded or outdated wireless access points, interference, poor placement, a failing firewall or switch, or an internet connection problem. If it happens to everyone at once, the cause is usually central equipment or the internet line, not individual laptops.
How to narrow it down:
- Check if wired computers drop too. If they do, the problem is likely your internet service or firewall, not Wi-Fi.
- Note when it happens. Drops at busy times suggest too many devices per access point. Random drops suggest failing hardware or interference.
- Look at the age of your equipment. Consumer-grade routers and older access points often struggle with a full office.
- Restart the access points and firewall once, and see if the problem returns.
- Ask for a wireless survey. An IT provider can map coverage and interference and recommend placement or upgrades.
BC Networks provides network monitoring, troubleshooting, and on-site support for San Jose area offices. If your Wi-Fi is costing your team time, call (408) 243-1100.
We paid a fake invoice or wired money to a scammer. What do we do?
Call your bank immediately and ask them to recall or freeze the wire. The first few hours matter most. Then report it to the FBI at ic3.gov, notify your cyber insurance carrier, and have your IT provider check whether an email account was compromised, since fake invoices often come from hijacked mailboxes.
Steps to take:
- Call your bank's fraud line now. Give them the transfer details and ask for a wire recall.
- File a report at ic3.gov. The FBI works with banks to try to freeze funds.
- Notify your cyber insurance carrier. Some policies cover this kind of fraud. Check your policy or ask your broker.
- Check your email accounts. Your IT provider should look for suspicious sign-ins and forwarding rules on everyone involved.
- Set a callback rule going forward. Any request to change bank details gets confirmed by phone, using a number you already had on file.
BC Networks helps San Jose businesses secure email and set up controls that make payment fraud harder. Call (408) 243-1100 if you think an account was involved.
A laptop with company data was lost or stolen. What should we do?
Change the passwords for every account used on that laptop, from a different device, and ask your IT provider to lock or wipe it remotely if device management is set up. Then figure out what data was on it. If it held personal information and was not encrypted, California breach notification rules may apply.
Steps to take:
- Report it to your IT provider right away so they can lock, locate, or wipe the device.
- Reset passwords for email, cloud apps, VPN, and any saved logins, and sign the device out of all sessions.
- Find out if the drive was encrypted. Encryption greatly reduces the risk of a stolen laptop.
- File a police report if it was stolen. Insurers often ask for one.
- Talk to your attorney if customer or employee personal data was on the device.
BC Networks manages device encryption and mobile device management for Bay Area businesses so a lost laptop is an inconvenience, not a crisis. Call (408) 243-1100.
Do we have to tell customers about a data breach in California?
Often, yes. California Civil Code Section 1798.82 requires businesses to notify California residents when certain unencrypted personal information is, or is reasonably believed to be, acquired by an unauthorized person. Your industry and contracts may add other duties. An attorney should make the final call.
What to do if you suspect a breach:
- Contain the incident first with your IT or security provider.
- Figure out what data was involved. Names combined with Social Security numbers, driver's license numbers, financial account details, medical information, or login credentials are common triggers.
- Bring in legal counsel early. They decide who must be notified and when.
- Notify your cyber insurance carrier. Many policies help pay for notification and legal costs.
- Keep records of what happened and what you did about it.
BC Networks' incident response service includes guidance on California breach notification and coordination with your legal counsel and insurer. Call (408) 243-1100.
Cybersecurity: Prevention and Peace of Mind
How do I know if my business has been hacked?
Common signs include password reset emails you did not request, customers receiving strange emails from your address, unfamiliar sign-ins or inbox rules, computers suddenly running slow or showing pop-ups, files you cannot open, and security alerts you do not recognize. Many breaches have no obvious signs, which is why monitoring matters.
Warning signs to watch for:
- Employees locked out of accounts or seeing failed login alerts.
- Contacts replying to emails you never sent.
- New email forwarding rules or unknown apps connected to Microsoft 365 or Google Workspace.
- Antivirus or security tools turned off without explanation.
- Unexpected money transfers or changes to vendor bank details.
If you are not sure, a 24/7 security operations center can spot activity that people miss. BC Networks offers a free 15-minute cybersecurity risk assessment for San Jose businesses. Call (408) 243-1100.
What is MFA, and do we really need it?
Multi-factor authentication (MFA) means signing in with your password plus a second proof, such as a code or approval on your phone. Yes, you need it. MFA blocks most attacks that rely on stolen passwords, and many cyber insurance applications now ask whether you use it.
Where to turn MFA on first:
- Email accounts, including Microsoft 365 and Google Workspace.
- Remote access such as VPN and remote desktop.
- Banking and payroll systems.
- Administrator accounts and IT management tools.
- Any cloud app that holds customer or financial data.
App-based approvals or physical security keys are stronger than text-message codes. BC Networks sets up and manages MFA for Bay Area businesses as part of its managed IT service.
How should a small business back up its data?
A good business backup keeps multiple copies of your data, at least one of them separate from your main network, and is tested regularly by actually restoring files. A common rule is 3-2-1: three copies, on two types of storage, with one copy offsite. Untested backups are the most common failure.
What a solid backup plan includes:
- Automatic daily backups of servers, shared files, and key computers.
- A copy that ransomware cannot reach, such as offline or immutable cloud backup.
- Backups of Microsoft 365 or Google Workspace, since those platforms do not fully protect you from deletion or ransomware.
- Regular test restores so you know how long recovery takes.
- A written recovery plan that says what gets restored first.
BC Networks provides data backup and disaster recovery for San Jose businesses, including third-party backup for OneDrive, SharePoint, Teams, and Exchange. Ask about it in a free 15-minute assessment.
What does cyber insurance require from my IT?
Most cyber insurance applications ask about specific security controls, and missing them can raise premiums, limit coverage, or lead to a denied claim. Common requirements include multi-factor authentication, endpoint detection and response (EDR), tested backups, patching, email security, employee training, and an incident response plan. Requirements vary by insurer.
Controls insurers commonly ask about:
- MFA on email, remote access, and admin accounts.
- EDR or managed security monitoring on all computers and servers.
- Backups stored separately from your network, with tested restores.
- Timely security updates on software and devices.
- Security awareness and phishing training for employees.
- A written incident response plan.
Answer insurance applications carefully. Claiming a control you do not actually have can cause problems at claim time. BC Networks helps Bay Area businesses meet cyber insurance requirements and document the controls insurers ask about. Call (408) 243-1100.
Why would hackers target a small business like mine?
Attackers target small and mid-sized businesses because they often have valuable data and money but fewer security defenses than large companies. Most attacks are automated and opportunistic. Criminals are not picking you by name. They are looking for any business with a weak password, a missed update, or an employee who will click.
What makes a business an easier target:
- No multi-factor authentication on email.
- Outdated software and devices that no longer get security updates.
- No one watching for suspicious activity after hours.
- Backups stored on the same network as everything else.
- Staff who have never had phishing training.
BC Networks has protected Silicon Valley businesses since 1989. A free 15-minute risk assessment shows where your business may be exposed.
What should an incident response plan include?
An incident response plan is a written playbook for what your business does when a cyberattack or data breach happens. It should name who is in charge, who to call, how to contain the problem, how to communicate, and how to recover. A plan you have practiced is far more useful than one on a shelf.
Key parts of a plan:
- Roles and contacts, including your IT provider, cyber insurance carrier, attorney, and bank.
- First steps for common incidents like ransomware, phishing, and lost devices.
- Communication rules for employees, customers, and the public.
- Legal and notification steps, including California breach notification.
- Recovery priorities, such as which systems get restored first.
- A review after every incident to fix what went wrong.
BC Networks builds and supports incident response plans for Bay Area businesses and offers a complimentary incident response readiness review. Call (408) 243-1100.
Choosing IT Support
Should we hire in-house IT or outsource?
For most businesses with 50 to 250 employees, outsourcing to a managed IT provider, or combining a small internal team with one, gives broader coverage than hiring one or two people. One employee cannot cover every skill, work 24/7, or take vacation without gaps. In-house staff do bring on-site presence and deep company knowledge.
How to decide:
- Count the skills you need: help desk, networking, security, cloud, compliance, and planning.
- Consider coverage. Who handles problems at night, on weekends, and during vacations?
- Compare total cost, including salary, benefits, training, tools, and turnover.
- Consider co-managed IT if you already have IT staff who are stretched thin.
BC Networks offers both fully managed and co-managed IT for Bay Area businesses. A free 15-minute assessment can help you compare options.
What should I look for in an IT support company?
Look for an IT company that includes cybersecurity as part of its core service, offers 24/7 support and monitoring, has local engineers who can come on-site, explains things in plain English, and provides regular planning meetings with leadership. Clear pricing and documented processes matter as much as technical skill.
A checklist for comparing providers:
- Security built in, not sold as an add-on.
- 24/7 help desk and security monitoring.
- Local engineers for on-site visits.
- Experience with businesses your size and in your industry.
- Predictable pricing with clear scope.
- Regular business reviews and a technology roadmap.
- Help with compliance and cyber insurance requirements.
BC Networks is a San Jose managed IT and cybersecurity provider serving Bay Area businesses since 1989. Call (408) 243-1100 to talk through your needs.
What questions should I ask before hiring an MSP?
Ask how they handle security, what happens after hours, how they bill, how onboarding works, and what reports you will receive. Good providers answer clearly, specifically, and in writing, without jargon. Vague answers about security or scope usually mean surprises later.
Questions to ask:
- What security tools and monitoring are included, and what costs extra?
- Who answers the phone at 2 a.m., and what happens next?
- Is pricing flat, or do you bill hourly for some work?
- How do you onboard a new client, and how long does it take?
- How do you test backups, and how often?
- What will you report to us each quarter?
- How do you help with cyber insurance and compliance?
- What happens to our data and passwords if we leave?
BC Networks welcomes these questions. Ask them during a free 15-minute assessment by calling (408) 243-1100.
How do we switch IT providers without disruption?
Switching IT providers goes smoothly when the new provider collects passwords, documentation, and system access before the old contract ends, and runs a planned handover. Check your current contract's notice period first. Most disruption comes from missing passwords or undocumented systems.
Steps for a clean switch:
- Review your current contract for notice periods and data return terms.
- Confirm you own your accounts, including domain name, Microsoft 365, and software licenses.
- Get a full list of passwords and admin access, kept in a secure vault.
- Ask the new provider for an onboarding plan with dates and responsibilities.
- Overlap briefly if possible so nothing falls through the cracks.
- Remove the old provider's access once the handover is complete.
BC Networks onboards Bay Area businesses with a structured handover plan. Onboarding a fully managed client typically takes 15 to 30 days, depending on complexity and the number of employees and workstations. Call (408) 243-1100, or reach sales directly at (408) 243-1101.
What happens in a free IT or cybersecurity risk assessment?
A cybersecurity risk assessment is a review of where your business is exposed and what to fix first. BC Networks' free 15-minute assessment is a conversation, not a technical audit. No system access is needed. It covers security, backups, remote work, compliance, and how well your business could keep running during an outage.
What the assessment looks at:
- Whether threats can be found and stopped quickly.
- Whether your business could keep operating during an outage or attack.
- Gaps that could cause audit, insurance, or customer problems.
- Whether important data can be restored after an incident.
- How safely employees work remotely and use AI tools.
The assessment is free and carries no obligation. San Jose and Bay Area businesses can schedule one at bcnetworks.com or by calling (408) 243-1100.
Everyday IT Problems
Do we need to back up Microsoft 365?
Yes. Microsoft keeps its service running, but protecting your data from accidental deletion, ransomware, or a malicious insider is largely your responsibility. Built-in retention has limits. A separate third-party backup of Exchange email, OneDrive, SharePoint, and Teams gives you a copy you control.
Why a separate backup matters:
- Deleted items are only kept for a limited time.
- Ransomware can encrypt synced OneDrive and SharePoint files.
- When an employee leaves and their account is removed, their data can go with it.
- Legal, compliance, or insurance needs may require longer retention.
BC Networks includes third-party Microsoft 365 backup in its managed IT service for San Jose businesses. Ask about it in a free 15-minute assessment.
What should we do when an employee leaves?
Remove the departing employee's access on their last day, ideally at the moment they leave. Disable their accounts, collect their devices, change any shared passwords they knew, and preserve their email and files. A written offboarding checklist prevents former employees from keeping access to company data.
An offboarding checklist:
- Disable email, Microsoft 365 or Google Workspace, VPN, and business app accounts.
- Sign them out of all devices and remove their phone from company email.
- Collect laptops, phones, keys, and badges.
- Change shared passwords and remove them from any password vault.
- Forward or preserve their email and files for their manager.
- Reassign software licenses so you stop paying for them.
BC Networks handles employee onboarding and offboarding for Bay Area businesses as part of managed IT support.
AI for Business
Is it safe for employees to use ChatGPT at work?
It can be, with guardrails. The main risk is employees pasting confidential information, such as customer data, contracts, source code, or financials, into AI tools that may store or use it. A clear policy, approved business versions of AI tools, and basic training make AI use much safer.
Guardrails to put in place:
- Decide which AI tools are approved, and prefer business plans with data protection terms.
- Spell out what data must never be entered into AI tools.
- Require people to check AI output before using it with customers.
- Find out which AI tools employees already use.
BC Networks helps Bay Area businesses set practical guardrails so employee AI tools do not put company data at risk.
Not sure where your business stands?
BC Networks offers a free 15-minute cybersecurity risk assessment for San Jose and Bay Area businesses. It is a conversation with a senior advisor, not a technical audit, and it needs no access to your systems. You leave knowing what to fix first. No cost and no obligation.
Schedule your free 15-minute assessment, call (408) 243-1100, or reach sales directly at (408) 243-1101.
BC Networks, Inc.1735 Technology Drive, Suite 820
San Jose, CA 95110
Main line, support, and emergencies: (408) 243-1100
Sales direct: (408) 243-1101
info@bcnetworks.com
Help desk and SOC monitoring: 24/7. After-hours emergency service through the main line. Office hours: Monday to Friday, 8am to 5pm Pacific.