One server had been compromised, and the provider was close to taking everything down.
The message arrived in the middle of other consulting work. I called the provider, took the affected machine offline, and started rebuilding it from a clean image.
Then I sent a short confirmation. The server was no longer reachable. It was being reprovisioned. If the provider saw another complaint or needed anything else, they could contact me directly.
That handled the immediate risk. It did not answer the bigger question.
If one box had been compromised, I could not assume every other machine was fine because it had not generated a complaint yet. I needed to run rootkit checks across the rest of the environment and look for anything else that did not belong.
The mail-server work moved down the list again.
That part was frustrating but normal. Small infrastructure jobs rarely stayed in the order written on the original project plan. The planned work might be mail, monitoring, or a firewall. A security call could replace all of it in one minute.
The public-facing response also had to be simple. The hosting provider did not need a long explanation. They needed to know the bad system was offline, the risk was contained, and somebody responsible was available.
Internally, the list was longer. Rebuild the server. Check every other box. Work out how it happened. Patch what needed patching. Then return to the mail server that had been delayed again.
Everything should be fine was not the same as everything had been checked. The checks came next.