Incident Response · 4 min read
The First Hour of a Suspected Incident
Do not power off systems reflexively. Isolate them from the network instead, so volatile evidence is preserved while the threat is contained.
Preserve logs immediately. Cloud audit logs, endpoint telemetry, and firewall data often have short retention windows and are the backbone of any investigation.
Move coordination to an out-of-band channel if email or chat may be compromised, and notify leadership, counsel, and your cyber insurer early. Insurance policies frequently include notification requirements.
Write down what you observe and when, including actions taken. A simple timeline is one of the most valuable artifacts an investigation can have.
Want this reviewed in your environment?
A DarkBox assessment establishes what is actually in place before anyone recommends spending.
