The First 60 Minutes After a Breach: What You Should Do
The moment you realize something is wrong, whether it's a ransomware note, an alert from your monitoring, a customer reporting fraud, or an admin account behaving strangely, the instinct is to either panic or immediately start pulling plugs. Both reactions are understandable and both can make things worse. Here's what actually helps in that first hour.
First: don't destroy evidence by rebooting or reimaging affected systems, tempting as it is to "just fix it." Forensic evidence of how an attacker got in and what they touched often lives in memory and logs that a reboot can wipe out. If you're not sure whether a system is safe to leave running, isolate it from the network instead of shutting it down. Pull the network cable or disable the network interface, not the power.
Second: contain, don't panic-shutdown everything. Isolating the specific compromised systems from the network stops an attacker's access without destroying the evidence you'll need to understand what happened. Shutting down your entire environment at once is rarely necessary and often causes more operational damage than the incident itself.
Third: start a timeline immediately, even a rough one in a plain text file: what you observed, when, and what actions you've taken since. This sounds bureaucratic in the moment, but it becomes essential within hours, for your own incident response team, for legal counsel, and potentially for regulators or insurers who will ask exactly this.
Fourth: get the right people in the room before you get the wrong people involved. That means your incident response contact (internal or external), and likely legal counsel, early, before any public statement, before you email affected customers, and generally before you engage law enforcement, so those steps happen in the right order with the right advice. It does not mean broadcasting the incident company-wide before you understand its scope; loose, uninformed communication in the first hour tends to create confusion that responders spend the next day untangling.
Fifth: assume you don't yet know the full scope, because you don't. It's tempting to declare "only this one system was affected" within the first hour. Initial visibility is almost always incomplete. Treat early assessments as a working hypothesis to be confirmed by investigation, not a conclusion to communicate externally.
Sixth: preserve, don't investigate yourself, unless you actually have in-house forensic capability. Well-intentioned poking around by unfamiliar staff is one of the most common ways evidence gets contaminated or destroyed. If you have a retainer with an incident response provider, this is the moment to call them. The value of a retainer is precisely that this call happens in minute five, not after a day of your own team trying to figure it out alone.
The businesses that come through a breach in the best shape aren't the ones who never get breached. Everyone is a target eventually. They're the ones who had a plan for the first hour before they needed one, so that hour is spent executing a plan instead of arguing about what to do.
Need help with this? Read more about our Incident Response service.