← All playbooks

Incident Playbook

Website Attacks

SIIRF-PB-09Infrastructure and connectivityTypical severity: Medium to highVersion 1.0 · October 2026

Summary

The organisation's website is unavailable, has been altered, or is being used to spread malware or scams.

Category
Infrastructure and connectivity
Typical severity
Medium to high
Response led by
Incident lead, with technical and communications leads

First 15 minutes

  1. Contact your host and your protection provider.
  2. Share key content through other channels while the site is down.
  3. If the site was defaced or hijacked, take it offline and restore a clean backup.

1. Overview

Attacks on your website can knock it offline with floods of traffic (DDoS), change what it says (defacement), or hijack it to spread malware or scams. They often come at the worst moment, such as a report launch or campaign.

2. How it happens

  • Floods of traffic timed to a publication, campaign or event.
  • Outdated website software, themes and plug-ins with known flaws.
  • Weak or reused passwords on hosting, domain or admin accounts.
  • Attackers taking over your domain to redirect visitors elsewhere.

3. Indicators

Signs that this incident may be happening:

  • The site becomes slow or unreachable.
  • Content changes that nobody on your team made.
  • Visitors report warnings, pop-ups or redirects.
  • Unknown admin accounts or files on the server.

4. Triage questions

Answer these first to understand scope and severity:

  1. Is the site down, slow, changed, or redirecting visitors?
  2. Is it down for everyone, or only in some places?
  3. When did it start, and does it coincide with a publication or campaign?
  4. Have admin, hosting or domain accounts been accessed?
  5. Is anything harmful being served to visitors?

5. Severity guide

Use your plan's severity levels. As a guide for this incident:

LevelTypical situation
LowBrief slowdown with no lasting effect.
MediumSite offline for hours due to traffic floods; no compromise.
HighDefacement, or site down during a critical launch.
CriticalSite serving malware or scams to visitors, or domain taken over.

6. Response steps

Work through these in order. Record every action, with the time and who did it, in your incident log.

  1. Contact your host and your protection provider.
  2. Share key content through other channels while the site is down.
  3. If the site was defaced or hijacked, take it offline and restore a clean backup.
  4. Change passwords for all admin, hosting and domain accounts.
  5. Record the timing and save evidence, such as logs and screenshots.

7. Communication

Who to inform, and when:

  • Hosting provider and any protection service, immediately.
  • Incident lead and communications lead.
  • Audiences, through other channels, about where to find content.
  • Visitors, if harmful content was served, with advice on what to do.
  • Partners, if a joint launch or campaign is affected.

8. Evidence to preserve

Keep these before making changes, wherever it's safe to do so:

  • Screenshots of defacement, error pages or redirects, with times.
  • Server, hosting and access logs.
  • Traffic data showing the attack.
  • Changes to files, admin accounts and domain settings.
  • Any messages or claims from attackers.

9. Recovery and review

  • Find out how attackers got in, and fix it.
  • Review the security of your hosting and domain accounts.
  • Update website software and remove unused plug-ins.
  • Record the incident and update your plan.

10. Prevention checklist

  • Use DDoS protection from your host or a protection service. Some offer free plans for non-profits.
  • Keep website software and plug-ins updated, or use a simpler static site.
  • Turn on 2-step verification and a registrar lock for hosting and domain accounts.
  • Keep regular backups of the whole site, stored separately.
  • Keep a list of everyone with admin access, and remove old accounts.
  • Plan alternative channels for important launches.