First hour of a suspected cyber incident.
Written for the people who will actually be in the room. Print it, save it to your phone, keep it in the runbook. On the day you need it, the last thing you’ll want to be doing is reading prose.
First 15 minutes: contain
Don't power off compromised systems. You destroy volatile memory and the forensic trail. Disconnect from the network instead (cable out, Wi-Fi off).
Don't log in to compromised systems with admin or domain credentials. Treat the network as hostile until confirmed otherwise.
Isolate the affected network segment. Pull switches, disable Wi-Fi SSIDs, block at the firewall if you can do it without breaking everything else.
Note the time the incident was detected, the alerts that fired, and the last-known good state for the affected systems.
If you have an incident response partner, call them now. Not email. Phone.
Next 30 minutes: co-ordinate
Open a single incident channel (Teams, Slack, a dedicated email thread). One source of truth for who's doing what.
Designate an incident lead. Their only job is co-ordination, not technical work.
Brief leadership early and briefly. They need to know enough to make external comms decisions, not enough to micromanage.
Identify your cyber insurer's notification clock. Most policies require notification within hours. Miss the window and the cover thins.
If personal data is in scope, start the ICO 72-hour clock. Document the time you became aware.
Within the first hour: preserve and investigate
Take forensic images of affected systems before they're touched, rebuilt, or restored. If you don't have someone in-house who can do this, your partner should.
Preserve logs. Cloud telemetry, endpoint protection logs, mail flow rules, identity sign-ins. Logs roll off quickly; export now.
Identify the initial access vector if you can. Email? Exposed service? Compromised credential? Don't guess; if it's unclear, leave it unanswered for the forensic work.
Rotate credentials for affected accounts. MFA on everything you can, immediately.
Start the written narrative. Who detected it, when, what's been done. The written record will save you later.
What not to do
Don't pay anything before you've talked to your insurer and counsel. Ransomware negotiations can violate sanctions law; this is not a DIY conversation.
Don't restore from backup until you understand the initial access vector. Backups taken after the compromise may be compromised themselves.
Don't engage the attacker. Don't email, don't respond to ransom notes, don't negotiate. That's a specialist job.
Don't put external comms out before legal counsel has seen them. The wrong statement makes the regulatory situation worse.
Don't disband the incident channel once systems are back. The investigation continues; the channel is the evidence trail.