After discovering a security breach caused by a misconfigured ACL, what is the FIRST remediation step an administrator should take?