// incident response · 6 min
Incident Response: What To Do in the First 24 Hours
The first day of an incident decides whether it becomes a controlled event or a career-defining disaster. This is the playbook, condensed.
Hour 0–2: Confirm and contain
- Verify the signal — is this a real compromise or a false positive?
- Contain without destroying evidence: isolate affected hosts from the network; do not wipe or reboot them.
- Start an incident log immediately: timestamps, actions, decisions, people. It will matter legally.
Hour 2–8: Assess scope
- What was accessed, from where, since when? Pull authentication logs, VPN records, and endpoint telemetry before retention windows eat them.
- Rotate credentials that could plausibly be exposed — service accounts first, they are the ones attackers keep.
- Identify whether personal data is involved: this starts regulatory clocks in most jurisdictions.
Hour 8–24: Communicate and stabilise
- One internal channel, one decision-maker, one external voice. Fragmented communication multiplies damage.
- Notify legal counsel and, where applicable, your insurer — before making public statements.
- Do not pay, promise, or publish anything under pressure without advice.
The mistakes that make it worse
Rebooting the evidence away. Announcing "we were hacked" before knowing scope. Letting the attacker watch your response inside the compromised email tenant. Skipping the post-incident review, so it happens again.
The best time to build this muscle is before the incident — through an IR readiness assessment and a tested response plan.
Concerned about any of this in your environment?
I help organisations test, find, and fix exactly these issues — with evidence, not scanner output. Start with a no-obligation conversation.
Written by Abdullah Bin Zarshaid, MSc, CEH — independent security consultant.
Discuss your security →