Passwords (Security Admin)
Have accounting turned on so you can track the commands this person ran
Contact your vendor for patches for any security holes that might have been exploited
Search the web and news groups for security info (Remember this is where the hackers get their info also)