A suspicious login, a website that starts behaving oddly, an employee who gets an antivirus alert nobody knows how to interpret. Most businesses don't have a plan for this moment, and the first hours are exactly what determines how the incident ends.
Here's what to do — and what to avoid — the moment you detect something is wrong.
First: don't panic, and don't shut anything down yet
The most common instinct is to disconnect the server or wipe the affected machine immediately. It's also the most expensive mistake: it destroys the evidence that would let you understand what happened, how attackers got in, and whether they're still inside the system.
Before touching anything, isolate the system from the network if possible (unplug the cable, don't power it off) and start documenting: what was seen, at what time, and who detected it.
The steps that actually make a difference
- Isolate without shutting down. Disconnecting from the network cuts off attacker access without destroying RAM or running processes, which usually hold the most valuable evidence.
- Rotate critical credentials. Admin passwords, API keys and privileged accounts, starting with any known or suspected to be compromised.
- Preserve logs before they rotate. Access, firewall and application logs are often overwritten within hours or days. Copying them as soon as possible is critical to reconstructing the timeline.
- Identify the real scope. Which systems are affected, what data may have been compromised, and whether access is still active.
- Check whether personal data was affected. If so, GDPR requires notifying the relevant data protection authority within 72 hours of becoming aware.
Why documentation matters as much as containment
A poorly documented incident is an incident that repeats: without knowing the exact entry vector, you can't truly close it. Every step — what was done, when, and by whom — should be logged from the first minute, with screenshots, logs and timestamps.
That same documentation is what later lets you build a prioritized remediation plan: what to close first, what to monitor, and what to reinforce so it doesn't happen again.
When to bring in outside help
If the incident affects production systems, there are signs of data theft, or there's simply no clarity on the scope, it's time to bring in someone experienced in forensic analysis. The sooner they're involved, the more evidence stays intact and the faster you can close the entry vector with confidence.
Where to start?
If you're in the middle of an incident right now, or want a plan ready before one happens, tell me your situation. In a 30-minute consultation I can tell you what to do and how to prioritize each step.
No obligation. No cost.
Free feasibility consultation
Tell me what's happening and I'll tell you what to do first. No obligation, no cost.
Write now →