Field guide

The first hour of a cyber attack.

Eight things to do before help arrives, in order. Written for the person who just got the call. Print it and put it in the drawer.


  1. 01 Declare it and name one commander. Say the word incident out loud. One person owns decisions from this minute. Everyone else reports to them, not to the group chat.
  2. 02 Do not power off affected machines. Shutting down destroys memory evidence and can make ransomware worse. Leave them on.
  3. 03 Isolate, do not wipe. Disconnect affected systems from the network. Pull the cable or disable Wi-Fi. Do not reinstall, delete, or “clean” anything yet.
  4. 04 Preserve your logs. Firewall, VPN, email, and domain controller logs age out fast. Export them now if you can do so safely.
  5. 05 Move your team off email and chat. The attacker may be reading them. Run the response over phone calls or a channel outside your network.
  6. 06 Check your backups, do not touch them. Confirm they exist and are disconnected. Do not start restoring. A restore over live evidence can destroy the investigation and reinfect you.
  7. 07 Start a timeline. One document. Every action, every observation, with a time next to it. It will be the most valuable page in the whole response.
  8. 08 Call for help before you are sure. You do not need certainty to call. The earlier help starts, the less an incident costs.

This page prints cleanly. Keep a copy where your team would look for it at 2 a.m.


01 Contact

Get ready before it happens.

Forty-five minutes with the person who would take your call. You leave knowing where you stand.

Keep the guide.

We email you the printable version.