Think Build Implement Repeat
SaaS & Product

What to Do in the First Hour of a Security Incident

Last updated:

The instinct is usually wrong

The natural reaction to discovering a compromise is to clean it up immediately: change passwords, wipe the machine, restore from backup, get back to work.

Doing that first destroys the evidence needed to answer the questions that matter — how did they get in, what did they access, are they still there, and do we have a notification obligation.

Minutes 0–15: contain

  1. Disconnect affected machines from the network, but do not power them off
  2. Disable compromised accounts rather than deleting them
  3. Revoke active sessions and API tokens for affected accounts
  4. Stop any automated payment runs until you understand the situation

Powering off loses volatile evidence. Disconnecting stops the spread while preserving what is there.

Minutes 15–30: preserve

Screenshot everything before it changes. Export logs — email, server, authentication — before retention windows expire. Note times, in a document outside the affected systems.

Log retention is frequently shorter than the time it takes to investigate. Exporting logs early is the difference between knowing what happened and guessing at it later.

Minutes 30–60: assess and escalate

  • What was accessed, and does it include personal data?
  • Is the access still live, or is it definitely closed?
  • Which other accounts share that password or that trust?
  • Who needs to know inside the business, right now?
  • Do we need external help, and who do we call?

Decide about external assistance early. Specialist help is far more effective in the first day than in the second week.

Notification obligations

If personal data may have been accessed, there are notification obligations with tight deadlines in the UK and EU, and the clock starts when you become aware. Take advice quickly rather than waiting for certainty.

Notifying customers is unpleasant and notifying late is worse. Businesses recover from breaches; they recover less well from having concealed one.

Prepare the one page in advance

Who to call, in what order, with numbers that do not depend on your systems. Which supplier holds which system. Where the logs are. Who can authorise spending on emergency help.

It takes an hour to write and it is the difference between a coordinated response and a chaotic one.

Frequently asked questions

Should we pay a ransom?

Law enforcement advice is generally not to, there is no guarantee of recovery, and payment may carry its own legal complications. Working backups are what make this a decision you do not have to face.

When should we bring in specialists?

Early, for anything involving personal data, financial systems or evidence of ongoing access. Their value falls sharply once evidence has been destroyed by well-meaning clean-up.

Do we have to tell customers?

It depends on what was affected and the risk to them, and there are legal thresholds. Take advice quickly — the deadlines are short and are measured from awareness.

How do we prevent a recurrence?

Establish the root cause before rebuilding. Restoring the same configuration that was compromised leaves you exactly where you were.

Keep reading

No plan for the first hour?

The one-page version takes an hour to write. Happy to talk through what should be on yours.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

SaaS DevelopmentCustom Software Development