In the middle of one right now?
Call +1 555 0100 and press 9. Do not switch machines off, do not start restoring backups, and do not pay anything yet. Unplug the network cable and leave the rest until we have spoken.
The first seventy-two hours
Every incident is different in its details and the same in its shape. This is the order we work in, and roughly how long each part takes for an office of twenty to fifty people.
-
Hour 0 to 2
Contain
Isolate affected machines, disable compromised accounts, block the attacker's route out. Nothing is wiped. Evidence is worth more than tidiness at this point.
-
Hour 2 to 24
Understand
How they got in, how long they were there, what they touched. This decides whether you have a notification duty, and it is the first thing your insurer will ask.
-
Day 1 to 3
Rebuild
Clean machines from known-good images, data restored from backups we have verified predate the intrusion, every credential rotated. Staff back at work in priority order.
-
Week 2
Report
A written account: timeline, root cause, what was and was not accessed, and the specific changes that would have prevented it.
What you get at the end
| Document | Who it is for | Length |
|---|---|---|
| Incident summary | Directors, staff, clients if needed | One page |
| Technical timeline | Insurer, legal counsel, regulators | Ten to twenty pages |
| Remediation plan | Whoever holds the budget | A prioritized list with costs |
The report was the first time anyone had explained our own network to us. We used it as the IT plan for the following year.
Operations director, regional logistics firm