What to Do in the First Hour of a Security Incident
Last updated:
The instinct is usually wrong
The natural reaction to discovering a compromise is to clean it up immediately: change passwords, wipe the machine, restore from backup, get back to work.
Doing that first destroys the evidence needed to answer the questions that matter — how did they get in, what did they access, are they still there, and do we have a notification obligation.
Minutes 0–15: contain
- Disconnect affected machines from the network, but do not power them off
- Disable compromised accounts rather than deleting them
- Revoke active sessions and API tokens for affected accounts
- Stop any automated payment runs until you understand the situation
Powering off loses volatile evidence. Disconnecting stops the spread while preserving what is there.
Minutes 15–30: preserve
Screenshot everything before it changes. Export logs — email, server, authentication — before retention windows expire. Note times, in a document outside the affected systems.
Log retention is frequently shorter than the time it takes to investigate. Exporting logs early is the difference between knowing what happened and guessing at it later.
Minutes 30–60: assess and escalate
- What was accessed, and does it include personal data?
- Is the access still live, or is it definitely closed?
- Which other accounts share that password or that trust?
- Who needs to know inside the business, right now?
- Do we need external help, and who do we call?
Decide about external assistance early. Specialist help is far more effective in the first day than in the second week.
Notification obligations
If personal data may have been accessed, there are notification obligations with tight deadlines in the UK and EU, and the clock starts when you become aware. Take advice quickly rather than waiting for certainty.
Notifying customers is unpleasant and notifying late is worse. Businesses recover from breaches; they recover less well from having concealed one.
Prepare the one page in advance
Who to call, in what order, with numbers that do not depend on your systems. Which supplier holds which system. Where the logs are. Who can authorise spending on emergency help.
It takes an hour to write and it is the difference between a coordinated response and a chaotic one.
Frequently asked questions
Should we pay a ransom?
When should we bring in specialists?
Do we have to tell customers?
How do we prevent a recurrence?
No plan for the first hour?
The one-page version takes an hour to write. Happy to talk through what should be on yours.
Related services
What we build for problems like this one