The first 60 minutes of an incident: what to do (and what not to do)

Containing the attack without destroying the evidence you will need later.

The first hour of an incident is when the most expensive mistakes are made. Not for lack of skill, but because under pressure instinct pushes you towards the wrong move: shut everything down, reinstall, delete the suspicious file and get back online. Every rushed action can fix the symptom of the moment and, in the same gesture, destroy what you will need to understand what happened, to notify correctly and — if it comes to it — to defend yourself in court.

The goal of the first sixty minutes is not to resolve the incident. It is to gain control without burning your future options. Two needs coexist and sometimes conflict: containing the damage and preserving the evidence. Knowing how to hold both together is what separates a professional response from a reaction.

Containing is not the same as shutting down

The most common reaction to a compromised machine is to pull the power. It is almost always the wrong move. Abruptly powering off a system wipes volatile memory: running processes, active network connections, encryption keys still in RAM, artefacts that exist only while the machine is on. These are often the most valuable evidence for reconstructing what the attacker was doing.

Containing means isolating, not destroying. Disconnect the system from the network — cable, Wi-Fi, segmentation at the switch or firewall — but leave it powered on until you have decided how to capture its state. Isolation cuts the attacker’s ability to move laterally or exfiltrate data without erasing the scene.

The order of volatility

If you have to collect evidence, gather first what disappears first. Forensic practice follows the order of volatility: memory and system state, connections and processes, then persistent storage such as disks and logs. A memory capture taken before shutdown can hold what no disk will ever preserve. If you lack the tools or the skills to do it, isolate and do not touch: a frozen scene beats a contaminated one.

Chain of custody from minute zero

Any evidence that might end up before a regulator, an insurer or a court needs a traceable history: who collected it, when, how, where it is stored and who has had access to it. This is the chain of custody, and it begins at minute zero, not when the lawyer arrives. Record timestamps with an explicit time zone, compute cryptographic hashes of your copies, keep an action log. Evidence without a documented custody is evidence the other side can challenge.

Communicate on a separate channel

If the attacker is inside your email or collaboration platform, they are reading your plan as you write it. Move coordination to an out-of-band channel — phones, a separate chat, an environment untouched by the incident. Set up a war room with a single source of truth and decide early who speaks to the outside. Operational silence does not mean hiding: it means not tipping off your adversary and not spreading panic before you have facts.

Document as you act, not afterwards

In the middle of the incident every action feels obvious; weeks later, in front of an insurer or a regulator, it no longer is. Keep a contemporaneous log: what you observed, what you decided, what you did and at what time. This is not bureaucracy, it is the backbone of everything that follows — the notification, the technical reconstruction, any litigation. The memory of the people who handled the crisis is the least reliable source you will have; the notes taken in the moment are the most reliable.

What not to do in the first hour

Do not reinstall or restore the affected systems: you erase the evidence and often fail to remove the attacker’s access. Do not delete suspicious files — isolate them. Do not reboot to see if the problem goes away. Do not use the same credentials that may be compromised. Do not issue statements or reply to the attacker without the people who will handle legal, technical and communications. And do not wait to bring in the right people: a lawyer engaged early can protect the confidentiality of the investigative work.

The takeaway

The first sixty minutes are won with discipline, not speed. Isolate instead of shutting down, collect the volatile before the persistent, document the chain of custody from the first move, and coordinate on a channel the attacker does not control. Anyone deciding these things during the incident is already late. Anyone who decided them beforehand simply executes.

From reading to deciding

Turn this into a decision you can defend.

A confidential 30-minute conversation to apply it to your situation — or start from a practical resource.