The first 24 hours of a suspected compromise, in order
Somebody has found something. A file that should not be encrypted, a login from a country nobody works in, an invoice paid to the wrong account, an alert nobody can explain. The instinct is to fix it. The first decisions of an incident are not about fixing anything — they are about preserving the options you will need later, most of which are destroyed by the obvious first move.
The short version
- Confirm something is actually happening before you escalate the whole organization.
- Start writing down what you know and what you do, with times.
- Call counsel early, and your insurer early.
- Preserve evidence before containment destroys it.
- Contain at the network, not at the power switch.
- Decide nothing about notification on day one; establish facts so that decision can be made well.
Hour zero: confirm, then start the log
Most suspected incidents are not incidents. A failed backup job, a misconfigured integration and a staff member on holiday in another country all look alarming at first glance. Confirm the observation with a second source before you declare, because a false declaration burns credibility you will need when a real one arrives.
Start a timeline in the first ten minutes and keep it in one place: what was observed, when, by whom, and every action taken with its timestamp. It is the single highest-value thing anybody does on day one. Use a document, a shared note or a paper pad — anything outside the systems that might be affected. Record observations separately from conclusions, and record who was told what and when. Nobody has ever regretted this, and every incident review finds that the first hour is the part nobody can reconstruct.
One practical warning: if you suspect the compromise reaches your email or chat, move coordination to an out-of-band channel immediately. Discussing your response in a system an intruder is reading is a well-established way to make things worse.
Who to call first
The order that works: the person who can authorize disruptive action; your legal counsel; your insurer, if you carry cyber cover; and then the technical people you need.
Counsel is on that list early for two reasons. The first is that notification determinations are legal determinations, and starting the fact-gathering under counsel’s direction keeps the eventual decision clean. The second is practical: counsel will tell you what to preserve and how to structure the engagement of any third party, which is much harder to retrofit.
If you do not know who your counsel is at eleven at night, that is a finding to fix this week, and it is the first thing incident response readiness addresses.
Preserve evidence before containment destroys it
Containment and evidence pull in opposite directions during the same hour, and the sequencing matters more than either one individually.
- Memory first, where it can be captured. It holds running processes, network connections and, sometimes, keys — and it is gone the moment the machine is powered off.
- Extend log retention now. Cloud platforms and appliances frequently roll logs within days. Pin them, export them, or raise the retention before the window closes on the evidence you have not yet realized you need.
- Snapshot rather than rebuild. A rebuilt server is a server whose evidence has been deleted by somebody trying to help.
- Capture the account and configuration state — who had access, which tokens existed, what rules were in place — because it will be changed during response.
Where the matter may end up in court, before a regulator or in an insurance claim, the handling of that evidence has to stand up. That is specialist work, and it is delivered with appropriately licensed partners where the law requires it.
Containment decisions and the trade they make
Not reflexively. Pulling power destroys memory-resident evidence and can trigger encryption routines, so the usual first move is to isolate at the network rather than to shut anything down. Network isolation keeps the machine alive and its evidence intact while removing the attacker’s access, and it is reversible in a way that a wipe is not.
The other containment moves worth having ready: disable the compromised accounts rather than deleting them, because a deleted account takes its history with it; revoke sessions and tokens, since a password change alone frequently leaves an active session in place; block the identified command-and-control destinations; and isolate rather than restore from backup until you know when the compromise began, because restoring an infected backup is a common and demoralizing way to lose the second day as well.
What not to do on day one
Do not wipe or rebuild — it destroys evidence and tells you nothing about how they got in, so it will happen again. Do not pay anything without counsel and your insurer involved; payment carries sanctions and disclosure questions of its own. Do not announce before you know enough to be accurate, because a correction later is worse than a delay now. Do not log in to affected systems with privileged credentials you have not confirmed are safe.
Insurers, and who gets to investigate
If you carry cyber cover, read the policy before the incident, because many policies specify a panel of responders and require notification within a short window. Engaging your own supplier first can prejudice a claim, and the insurer’s panel may be a better-resourced option than anything you could arrange at midnight.
The corollary is that your incident plan should name the insurer’s process, not just your preferred supplier. Plans written without reading the policy tend to be unusable at the moment they are needed. The ransomware-specific version of all of this is in ransomware readiness and resilience.
Communications
Three audiences, three owners, and no improvisation.
| Audience | Owned by | Day-one position |
|---|---|---|
| Internal staff | The incident lead | What is happening, what to do, who to ask — and not to speculate externally |
| Customers and partners | The executive owner, with counsel | Usually nothing on day one unless service is affected |
| Regulators and commissioners | Counsel | Prepared for, not sent, until the facts support it |
Your counsel decides whether a notification duty is engaged, working from the statutory test and the facts as they are established. That determination is a legal one and it does not belong to a security supplier. The statutory test differs between instruments — the federal Act, the provincial private-sector Acts and the public-sector Act do not say the same thing, and what a BC private-sector organization is actually required to do is widely misreported. We set the position out in reporting a breach in BC, and the instruments themselves begin with PIPEDA.
Bringing in an investigator
We help you prepare for an incident and we work alongside you during one, and investigation and forensic work is delivered with appropriately licensed partners where the law requires it. We claim no licence of our own and we do not take reactive forensic engagements on our own account. Where forensic work is needed, it is usually engaged through counsel, and there are good reasons for that arrangement beyond privilege: it keeps the scope, the reporting line and the handling of findings coherent with the decisions counsel will have to make.
What an investigator will need from you, and what you can prepare while they are being engaged: the timeline you started in hour zero; network and authentication logs with their retention confirmed; an inventory of affected systems and the state each is currently in; the account and access state you captured; and a named person who can authorize access and disruptive action.
The end of day one
By the close of the first day, five things should exist in writing: a timeline of observations and actions; a current statement of what is known, what is suspected and what is unknown, with those three kept apart; a list of systems and data potentially involved; a record of decisions with who made each and when; and the preservation record — what was captured, by whom, and where it is held.
Notice what is not on that list. You do not need to know how they got in, whether data left, or whether anyone must be notified. Those are the outputs of the investigation, and an organization that tries to answer them on day one usually answers them wrongly and then has to walk it back.
Why a plan written in advance changes all of this
Every decision above is easier when it was made in advance by somebody who was not frightened. A plan does not need to be long: contacts including counsel and insurer, the authority to disconnect, the out-of-band channel, the preservation checklist, and the communications owners. One page, printed, and rehearsed once a year against a scenario somebody made up.
The rehearsal is what makes it real. Organizations that have walked through a scenario once make different decisions in the first hour, and the difference shows in the timeline. That work is incident response readiness; where the systems involved include a model, the additional questions are in AI incident readiness; and the privacy-programme side of it is Canadian privacy readiness.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
Investigation and forensic work is delivered with appropriately licensed partners where the law requires it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Should we shut everything down?
Not reflexively. Pulling power destroys memory-resident evidence and can trigger encryption routines, so the usual first move is to isolate at the network rather than to shut anything down.
Who decides whether we have to notify?
Your counsel decides whether a notification duty is engaged, working from the statutory test and the facts as they are established. That determination is a legal one and it does not belong to a security supplier.
Can you investigate for us?
We help you prepare for an incident and we work alongside you during one, and investigation and forensic work is delivered with appropriately licensed partners where the law requires it. We claim no licence of our own and we do not take reactive forensic engagements on our own account.
What should we be writing down?
Start a timeline in the first ten minutes and keep it in one place: what was observed, when, by whom, and every action taken with its timestamp. It is the single highest-value thing anybody does on day one.
Before the next one
If you are in an incident now, call your counsel and your insurer first. If you are not, that is the moment to write the one-page plan — send us what you have and the reply says what is missing from it. More of our writing is indexed at writing.