Incident response for a compromised account
- Severity
- Critical
- Status
- Reviewed
- Affected area
- Incident Response
- Published
- Last reviewed

The instinct on discovering a compromised trading account is to do everything at once, quickly and in a panic. That instinct destroys evidence, misses the real foothold, and often makes the situation worse. The firms that survive a compromise well are the ones that decided, in advance and in calm, exactly what the first hour looks like. Incident response is not heroics under pressure; it is a rehearsed sequence executed while everyone else is losing their composure.
§01Contain before you investigate
The first priority is to stop the bleeding without destroying the crime scene. That means halting trading and withdrawals, the kill-switch earns its keep here, and revoking the credentials and sessions that could be the attacker’s access, all at once so they cannot simply re-enter through a second door. Containment is deliberately blunt: err toward locking things down, because a frozen account can be reopened, while a drained one cannot be refilled.
§02Preserve the record
Before anything is changed or cleaned up, preserve the evidence. Snapshot logs, capture the audit trail, and record timestamps, because the tamper-evident history is what will later tell you how they got in and what they touched. Responders who rebuild first and investigate later routinely destroy the only record of the initial foothold, and then reopen the same door for the attacker to walk through again. Preservation is not bureaucracy; it is what makes recovery real rather than hopeful.
§03Recover to known-good, not to before
Recovery means restoring to a state you can trust, which is not the same as the state you were in five minutes before the alarm. Rotate every credential the compromised account could reach, rebuild from known-clean artefacts rather than cleaning the running system in place, and reconcile positions and balances against an independent record to establish exactly what moved. Only once you understand the entry point do you reopen, otherwise you are recovering into the same weakness.
§04Rehearse the calm
The difference between a contained incident and a spiralling one is almost entirely preparation: a written playbook, known roles, and a drill run before it was ever needed. Decide who declares an incident, who can pull the halt, and how you communicate when normal channels may be compromised, long before the day you need the answers. This advisory is educational and illustrative and is not security, legal, or incident-response advice for any specific situation.