Field guide
The first hour of a cyber attack.
Eight things to do before help arrives, in order. Written for the person who just got the call. Print it and put it in the drawer.
- 01 Declare it and name one commander. Say the word incident out loud. One person owns decisions from this minute. Everyone else reports to them, not to the group chat.
- 02 Do not power off affected machines. Shutting down destroys memory evidence and can make ransomware worse. Leave them on.
- 03 Isolate, do not wipe. Disconnect affected systems from the network. Pull the cable or disable Wi-Fi. Do not reinstall, delete, or “clean” anything yet.
- 04 Preserve your logs. Firewall, VPN, email, and domain controller logs age out fast. Export them now if you can do so safely.
- 05 Move your team off email and chat. The attacker may be reading them. Run the response over phone calls or a channel outside your network.
- 06 Check your backups, do not touch them. Confirm they exist and are disconnected. Do not start restoring. A restore over live evidence can destroy the investigation and reinfect you.
- 07 Start a timeline. One document. Every action, every observation, with a time next to it. It will be the most valuable page in the whole response.
- 08 Call for help before you are sure. You do not need certainty to call. The earlier help starts, the less an incident costs.
This page prints cleanly. Keep a copy where your team would look for it at 2 a.m.
01 Contact
Get ready before it happens.
Forty-five minutes with the person who would take your call. You leave knowing where you stand.
Keep the guide.
We email you the printable version.