Cybersecurity

Security Incident Response: What to Do in the First Hour

Updated November 14, 2023By the CalliArc team

Key takeaway

Contain without destroying evidence: isolate affected systems from the network rather than powering them off, rotate credentials, and start a written timeline immediately. Decide who declares an incident and who speaks publicly before you need to — improvising those two roles is what turns an incident into a crisis.

The first hour of a security incident is mostly decided beforehand. Teams with a one-page runbook act; teams without one hold a meeting.

Minutes 0–15: confirm and mobilise

  • Verify it's real — a misconfigured monitor and an intrusion look similar at first glance.
  • Declare the incident and name a single incident commander. One person decides; everyone else reports to them.
  • Open a dedicated channel and start a timestamped log of every observation and action. This becomes your evidence, your regulatory record, and your post-incident review.
  • Assume your normal channels may be compromised; have an out-of-band fallback agreed in advance.

Minutes 15–45: contain without destroying evidence

  • Isolate affected hosts at the network level rather than powering them off — memory contents are often the most valuable forensic artifact.
  • Snapshot disks and preserve logs before anything is rebuilt; logs frequently roll over during an incident.
  • Rotate credentials, API keys, and tokens for anything the affected systems could reach.
  • Revoke active sessions, and check for persistence: new accounts, changed keys, unfamiliar scheduled tasks.

Minutes 45–60: assess and notify

  • Establish what data could have been accessed — not what was definitely taken. Regulatory clocks run on possibility.
  • Notify legal and leadership; breach notification deadlines can be as short as 72 hours and start earlier than people expect.
  • Engage external incident response and your cyber insurer if you have them — many policies require early notification to pay out.
  • Prepare holding communications. Say what you know, what you're doing, and when you'll update. Do not speculate on cause.

What to prepare now, while nothing is on fire

  • A contact list with out-of-hours numbers, including legal, insurer, and IR firm.
  • Named incident commander and deputy, and a single spokesperson.
  • Logging that's centralised and retained long enough to investigate — 30 days is usually too short.
  • A tested ability to rotate every credential quickly.
  • One tabletop exercise a year. It reliably finds the gap you didn't know you had.
Share LinkedIn X

Ready to build it right?

Get a transparent, milestone-based estimate for your project in a free consultation.

Book a free strategy call