The first hour
- Contain — without destroying evidence. Disconnect affected machines from the network: pull the cable, kill the Wi-Fi, isolate the switch port. Do not power anything off — memory holds the forensic evidence that shutdown erases, and some ransomware corrupts irreversibly on reboot. If lateral spread is visible and you must choose, cutting the internet uplink beats powering down servers.
- Protect the backups — this minute. Attackers routinely linger before detonating, and the backup console is their first stop. Verify the offsite/immutable copy is intact and that its credentials aren't the same ones that just got compromised. Whatever you still have at minute ten, you keep. (With attacker breakout times now under an hour, minutes are the actual unit here.)
- Start the timeline. One person writes everything down: what was noticed when, what was disconnected, who was called. Insurers, forensics, and — if it comes to it — regulators will all ask. Memory under adrenaline is fiction; notes are evidence.
- Make the calls, in order. Your IT/security provider's emergency line first — containment at machine speed is their job. Then the cyber-insurance hotline: policies carry approval requirements and preferred forensics/legal panels, and acting without them can jeopardize coverage. Then counsel. Not yet: mass emails to staff or clients — communicate on a plan, not on panic, and assume email itself may be compromised; phones and text are safer channels for the first hours.
- Freeze the money paths. If there's any chance finance systems or email were touched, call the bank, hold pending wires, and warn whoever approves payments — BEC follow-on fraud loves the chaos right after an incident.
The communications hour (the one everyone gets wrong)
Somewhere between minute 60 and the end of day one, the pressure to say something becomes unbearable — staff are speculating, a client heard a rumor, someone drafts an all-hands email. Resist the improvisation. Internal first: a short, factual holding note — systems issue, being handled, don't touch affected machines, route questions to one named person. External: nothing beyond operational necessity until counsel weighs in, because early statements harden into legal facts, and "we have no evidence data was accessed" written at noon can be false by Friday and quoted forever. And deliver it by phone or text if email is in scope — announcing your response plan inside the attacker's mailbox is handing over the defense playbook. One voice, short sentences, no adjectives. Companies rarely get judged for having an incident; they get judged for the week of communication that follows it.
The first week, compressed
Forensics establishes what happened and what data was touched — resist the urge to wipe and reimage before scope is known, because rebuilding on an unknown foothold restarts the incident. Counsel drives notification: state laws (California's among the strictest), contractual duties to clients, sometimes regulators; timelines run in days. Recovery then works tier by tier from clean, verified backups onto verified-clean systems — with credentials rotated everywhere, MFA enforced, and monitoring watching for the attacker's return visit, which is common enough to plan for.