Cybersecurity
Security Incident Response: What to Do in the First Hour
Updated November 14, 2023By the CalliArc team
Key takeaway
Contain without destroying evidence: isolate affected systems from the network rather than powering them off, rotate credentials, and start a written timeline immediately. Decide who declares an incident and who speaks publicly before you need to — improvising those two roles is what turns an incident into a crisis.
The first hour of a security incident is mostly decided beforehand. Teams with a one-page runbook act; teams without one hold a meeting.
Minutes 0–15: confirm and mobilise
- Verify it's real — a misconfigured monitor and an intrusion look similar at first glance.
- Declare the incident and name a single incident commander. One person decides; everyone else reports to them.
- Open a dedicated channel and start a timestamped log of every observation and action. This becomes your evidence, your regulatory record, and your post-incident review.
- Assume your normal channels may be compromised; have an out-of-band fallback agreed in advance.
Minutes 15–45: contain without destroying evidence
- Isolate affected hosts at the network level rather than powering them off — memory contents are often the most valuable forensic artifact.
- Snapshot disks and preserve logs before anything is rebuilt; logs frequently roll over during an incident.
- Rotate credentials, API keys, and tokens for anything the affected systems could reach.
- Revoke active sessions, and check for persistence: new accounts, changed keys, unfamiliar scheduled tasks.
Minutes 45–60: assess and notify
- Establish what data could have been accessed — not what was definitely taken. Regulatory clocks run on possibility.
- Notify legal and leadership; breach notification deadlines can be as short as 72 hours and start earlier than people expect.
- Engage external incident response and your cyber insurer if you have them — many policies require early notification to pay out.
- Prepare holding communications. Say what you know, what you're doing, and when you'll update. Do not speculate on cause.
What to prepare now, while nothing is on fire
- A contact list with out-of-hours numbers, including legal, insurer, and IR firm.
- Named incident commander and deputy, and a single spokesperson.
- Logging that's centralised and retained long enough to investigate — 30 days is usually too short.
- A tested ability to rotate every credential quickly.
- One tabletop exercise a year. It reliably finds the gap you didn't know you had.