When your reputation is attacked, the first 72 hours matter more than the following six months. Not because the damage peaks early — it usually hasn’t yet — but because everything that determines how bad this gets is still in motion. Search engines haven’t finished deciding where the content ranks. Platforms haven’t locked in their view of the situation. The people who matter to you mostly haven’t seen it. And you haven’t yet made the unforced errors that turn a containable incident into a permanent fixture of your search results.
We work these situations professionally, and the pattern is blunt: people who run a disciplined first-72-hours triage usually end up with a manageable removal and response project. People who spend those hours refreshing the page, firing off angry replies, and calling everyone they know usually end up with a bigger, older, better-ranked problem by the time systematic work begins. This guide is the triage protocol — hour by hour, decision by decision: how to assess what you’re facing, map how far it has spread, and sort every piece of content into one of three buckets: remove, answer, or ignore.
A note on scope. This guide covers the immediate response window when an attack lands. If what you’re facing is a sustained, coordinated campaign by a specific adversary, read our companion guide on what to do when someone is trying to ruin your reputation — the long-game strategy differs. And as always: we are a content removal firm, not a law firm, and nothing here is legal advice.
Hour zero: stabilize before you act
The moment you discover the content is the moment you are least equipped to respond to it. Adrenaline is a poor strategist. Before any outward-facing action, three things — in this order.
Preserve the evidence. Full-page screenshots of every post, review, article, or comment, with URLs, usernames, and timestamps visible. Save the links in a document with dates. If the content is on a platform where edits or deletions are easy, consider a third-party archive for a timestamped independent copy. This takes twenty minutes and it is the one step you cannot redo later — content changes, and removal itself (including successful removal) destroys the record. Every downstream option, from platform escalation to legal content removal, is built on what you preserved in this window.
Say nothing publicly. Not a reply, not a “setting the record straight” post, not a cryptic status update. You will likely say something eventually — the triage below determines what and where — but a statement made in hour two is a statement made before you know what you’re dealing with, and public engagement is fuel: it signals to algorithms that the content is interesting and to the attacker that the hit landed.
Decide who is in the room. Pick the two or three people who will help you think — a business partner, counsel if the content is plausibly defamatory or threatening, a removal specialist if the exposure is significant. Resist the urge to tell everyone. Every person you alarm becomes a channel through which the story spreads, and most people who hear about attack content go and look at it, which is exactly what you don’t want.
The first 24 hours: assess what you’re actually facing
Not all attacks are the same problem, and misdiagnosing the type leads to the wrong response. When your reputation is attacked, the first analytical task is classification.
What kind of content is it?
- False factual claims — accusations of fraud, crime, misconduct that can be proven untrue. These open the strongest removal routes, from platform policies to defamation removal work and, where justified, legal escalation.
- Harassment, doxxing, or abuse — personal information published, threats, content designed to intimidate rather than persuade. Platforms treat this category most seriously, and cyber abuse removal routes are often the fastest available.
- Negative opinion or a genuine grievance — an angry customer, a critical post, a bad review rooted in a real interaction. Removal options are narrower here, and the answer bucket (below) matters more.
- Misleading truth — accurate facts framed for maximum damage, or old information resurfaced without context. Often the hardest category; strategy shifts toward de-indexing of private details, context, and suppression.
Most real attacks mix categories, which is fine — you will sort item by item, not incident by incident.
Who is behind it, and is it growing?
One angry person is a different problem from a coordinated group, and both differ from a story picked up by a site with actual readership. Look at the accounts posting: their age, history, and whether multiple “voices” write suspiciously alike. Then look at velocity — is this one post sitting still, or has it been reposted, quoted, or cross-linked in the hours since you found it? Velocity, more than venom, determines urgency.
Mapping the spread: know your full exposure
You cannot triage what you haven’t found, and the content you discovered is rarely all of it. Attack content propagates along predictable paths, and the map you build now becomes the working document for everything that follows.
Search your name — and your company, and your name plus words like “review,” “scam,” and “complaint” — in a private browser window, and record what appears in the first two pages of results. Do the same on image and video search. Check the major platforms directly, since much of what’s posted there won’t surface in web search for days. Look at where the original content links out and what links into it. Set up alerts on your name so anything new comes to you instead of waiting to be found; ongoing reputation monitoring does this systematically, which matters because the spread map is a living document — the situation at hour 60 will not match hour 6.
For each item found, log four things:
- URL and platform
- Visibility — does it rank for your name? How much traffic does the platform have? A brutal post nobody can find is a lower priority than a mild one in your top three results.
- Category — false fact, abuse, opinion, misleading truth.
- Audience risk — how likely are your clients, employer, investors, or family to encounter this specific item?
If the map is bigger than you can build alone, a free exposure scan covers it professionally — in attack situations we routinely surface content targets hadn’t found, on sites they didn’t know existed.
The triage decision: remove, answer, or ignore
This is the heart of the 72-hour protocol. Every mapped item gets exactly one label, and the discipline of choosing — rather than treating everything as equally urgent — is what separates strategy from flailing.
Remove: content with a viable takedown route
Content goes in the remove bucket when a realistic mechanism exists to take it down or de-index it: platform policy violations (harassment, impersonation, doxxing, fake accounts, review-platform rules), hosting and site-level complaint processes, search engines’ own removal policies for personal information, and legal process where the claims support it. False factual claims, coordinated fakery, and published private details usually land here.
Work this bucket first and quietly. Removal requests filed early — before content is widely engaged with, before the thread fills with your replies — succeed more often, and every day content stays up, it accumulates the links and engagement that make search results sticky. Be honest with yourself about what “viable” means: removal decisions belong to platforms, hosts, and courts, and no one can guarantee a specific outcome. What a professional can do is match each item to the right mechanism and escalate through channels that reach human reviewers — which is exactly the discipline behind how our process works.
Answer: content that deserves a measured response
Some content shouldn’t be fought — it should be answered, once, well. A negative review from a real customer on a platform with a response feature. A journalist’s inquiry. A claim circulating among a specific audience you can address directly.
The rules for the answer bucket are strict. Respond once, not repeatedly. Respond with facts and composure, never with anger — your reply will be read by strangers deciding who sounds credible. Respond in the narrowest effective channel: a private note to a concerned client beats a public statement; a review-platform owner response beats a social media thread. And never answer content in the remove bucket — responding to something you’re trying to take down entrenches it and can complicate the takedown itself.
Ignore: content that response would only amplify
The hardest bucket emotionally, and often the largest. Content gets ignored when it is low-visibility, on low-traffic sites, not ranking for your name, and not spreading. Obscure forum posts, rant accounts with no followers, content already buried past page two. Responding to any of it — even filing aggressive takedowns that trigger a poster’s spite — can lift it from irrelevance into visibility. Ignored is not forgotten: every item in this bucket goes on the monitoring list, and if one starts moving, it gets re-triaged. But the discipline of leaving weak attacks alone is one of the most valuable and least intuitive skills in this entire field.
Hours 24–72: execute in sequence
With the map built and buckets assigned, the remaining work of the window is execution.
- File the removal requests for the remove bucket, strongest cases first, each framed in the specific terms of the policy it invokes. Blast-radius reporting — flagging everything under every category — reads as noise and gets template rejections.
- Deliver the answers in the answer bucket, after someone with distance from the situation has read them. Every sentence you publish this week should pass one test: does this still look smart in six months?
- Brief the people who matter, privately. If clients, an employer, a board, or partners may encounter the content, a short calm note from you beats their discovering it cold: what happened in one line, that it’s being handled through proper channels, and that you’re available for questions. No detailed rebuttals — briefing is about trust, not litigation.
- Stand up monitoring on your name, so days four through ninety are managed by alerts rather than anxious searching.
- Schedule the reassessment. At the end of 72 hours, re-run the search map. What moved? What got removed? What new content appeared? The answers tell you whether this transitions to a routine cleanup, a sustained removal campaign, or — rarely — a genuine crisis requiring coordinated professional and legal response.
What the first 72 hours cannot do
Some honesty about limits. Three days of good triage does not finish the job — platform escalations take days to weeks, de-indexing takes longer, and rebuilding search results around accurate content is a months-scale reputation management effort. Nor can any amount of early discipline guarantee removal of a specific item; those decisions rest with third parties, and anyone promising otherwise is selling comfort, not results. What the window actually buys you is position: evidence preserved before it changed, removals filed before content entrenched, no self-inflicted amplification, and a complete map instead of a panicked guess. Every subsequent week of work is cheaper and more effective from that position — and the position cannot be bought back later at any price.
Frequently asked questions
Should I respond publicly when my reputation is attacked?
Almost never in the first 72 hours, and less often than you’d think after that. Public responses feed engagement algorithms, bind your name to the accusation in the index, and signal the attacker that the hit landed. The exceptions live in the answer bucket — a single owner response to a legitimate review, a statement to a genuinely significant audience — and they work best written once, calmly, after triage rather than before.
The attack is spreading fast. Does the 72-hour framework still apply?
Yes — velocity compresses the timeline but doesn’t change the sequence. Preservation still comes first (fast-moving content changes fastest), mapping still beats guessing, and the remove/answer/ignore triage still governs. What changes is resourcing: genuine velocity is the strongest signal that you should bring in professional help immediately rather than triaging alone, because platform escalation channels that move in hours rather than days matter most in exactly this scenario.
What if I don’t know who is attacking me?
Proceed anyway — the triage protocol doesn’t require knowing. Removal routes run through platforms and policies, not through the attacker, and anonymous content is often more removable because anonymity correlates with the fake accounts and policy violations platforms act on. Identifying an anonymous attacker is sometimes possible later through legal process, but it’s a separate, attorney-driven question that shouldn’t delay the first 72 hours of containment.
When should I involve a lawyer versus a removal firm?
They solve different layers, and serious situations often need both. Counsel belongs in the room when content involves clear false statements of fact causing real damage, threats, extortion, or when unmasking an anonymous poster may be warranted. Removal specialists handle the operational layer — platform policy work, escalation channels, de-indexing, monitoring — that exists whether or not litigation ever makes sense. A good removal firm will tell you plainly when a matter needs an attorney; ours does.
If your reputation is attacked and you’re inside that first window now, don’t spend it guessing at your exposure. Start with a free exposure scan — we’ll map every piece of content attached to your name, triage it honestly into remove, answer, and ignore, and tell you exactly what we’d do in the next 72 hours and why.
By