The First 24 Hours of a Breach: What Your Incident Response Plan Must Cover

Oct 6, 2026

0 Comments

The First 24 Hours of a Breach: What Your Incident Response Plan Must Cover

A security breach creates confusion quickly. Systems may be failing. Employees may be asking questions. Customers may be calling. Your team may not know whether the attacker is still inside.

The first 24 hours are not the time to improvise.

Your priority is to contain the incident, preserve evidence, understand the scope, and activate the right people. Recovery comes later. Incident response comes first.

This distinction matters. Disaster recovery focuses on restoring systems and operations. Incident response focuses on stopping the threat, investigating what happened, protecting evidence, and meeting legal and business obligations.

Here is a practical SMB-focused playbook.

BEFORE THE CLOCK STARTS: ASSIGN OWNERS

Your incident response plan should name people, not just departments.

At minimum, identify:

  • An internal incident owner with authority to make decisions.
  • Your IT team or managed IT services provider.
  • Your cybersecurity consulting or digital forensics contact.
  • Your cyber insurance carrier and 24/7 breach hotline.
  • Legal counsel with privacy and data security experience.
  • A communications lead.
  • A finance lead for suspected payment fraud.
  • Your preferred law enforcement contacts.

Store this list offline. Keep a printed copy. If your email or collaboration platform is compromised, you may not be able to access a digital plan.

Use phone calls or another pre-agreed out-of-band channel until your team confirms that internal communications are safe.

THE FIRST HOUR: CONFIRM, CONTAIN, AND CALL

The first hour is about limiting damage without destroying evidence.

1. CONFIRM WHAT YOU ARE SEEING

Common indicators include:

  • Ransom notes or widespread file encryption.
  • Unusual file extensions or locked applications.
  • Suspicious administrator activity.
  • Impossible-travel or unfamiliar logins.
  • New email forwarding rules.
  • Unauthorized payment instructions.
  • Employees reporting that messages were sent from their accounts.
  • Security tools showing lateral movement or data exfiltration.

Do not spend hours trying to prove every detail before acting. Establish what you know, what you suspect, and what remains unknown.

2. ISOLATE AFFECTED SYSTEMS

Work with your IT team or MSP to isolate affected devices and accounts.

Possible actions include:

  • Disconnecting infected endpoints from wired and wireless networks.
  • Taking an impacted network segment offline.
  • Disabling compromised accounts.
  • Revoking active cloud sessions.
  • Blocking suspicious remote access.
  • Pausing backup synchronization if backups may be receiving encrypted files.
  • Disconnecting accessible backup drives or storage devices.

Do not automatically shut down every device. Powering off a system can destroy volatile evidence in memory. If you cannot isolate a device any other way and the threat is actively spreading, containment may take priority. Document that decision.

3. CALL THE RIGHT PEOPLE

Do not wait until the investigation is complete to contact your insurer.

Call:

  1. Your internal incident owner. This person coordinates decisions and maintains accountability.
  2. Your IT team or MSP. They can isolate systems, secure accounts, and preserve technical information.
  3. Your cyber insurer. The carrier may require you to use approved legal counsel or forensic providers.
  4. Legal counsel. Counsel can guide privilege, notification decisions, contracts, and regulatory requirements.
  5. Digital forensics and incident response specialists. They determine how the attacker entered, what they accessed, and whether they remain present.
  6. Law enforcement, when appropriate. Ransomware, extortion, theft, fraud, and significant business disruption may justify early reporting.

Your insurance policy may specify how and when a claim must be reported. Waiting until after systems have been wiped or rebuilt can complicate coverage and eliminate valuable forensic evidence.

Forensic analyst preserving system images, memory, logs, and other digital evidence after a cybersecurity breach

HOURS 1–2: PRESERVE EVIDENCE

Your team will want to fix things immediately. Resist the urge to wipe, rebuild, or restore before forensics has captured what it needs.

Preserve:

  • System and disk images from representative affected devices.
  • Volatile memory captures, when feasible.
  • Endpoint detection and response alerts.
  • Firewall, VPN, identity, email, and cloud access logs.
  • Windows event logs and PowerShell logs.
  • Network traffic records.
  • File metadata and suspicious executables.
  • Ransom notes and encrypted file samples.
  • Phishing emails and full email headers.
  • Attacker email addresses, phone numbers, wallet addresses, and chat messages.
  • Screenshots or photographs of suspicious screens.
  • Affected laptops, servers, and mobile devices.
  • A written timeline of discoveries and actions.

Keep original evidence unchanged. Create working copies for analysis.

Your timeline should record:

  • When the incident was discovered.
  • Who discovered it.
  • Which systems showed symptoms.
  • Which accounts were disabled.
  • Which devices were isolated.
  • Who was contacted and when.
  • What decisions were made.
  • Why those decisions were made.

This record supports forensics, insurance, legal review, regulatory reporting, and future improvements.

The CISA StopRansomware Guide specifically recommends isolating impacted systems, preserving volatile evidence, collecting logs, and taking system images and memory captures where possible.

HOURS 2–6: DETERMINE THE SCOPE

By this stage, your response team should move from immediate containment to structured investigation.

Ask:

  • How did the attacker get in?
  • Which account, device, application, or vendor relationship was involved?
  • Is the attacker still active?
  • Were administrator credentials stolen?
  • Was data accessed or copied?
  • Are backups intact and separated from the affected environment?
  • Did the incident reach cloud systems?
  • Were customers, vendors, employees, or financial institutions affected?
  • Are there contractual reporting obligations?

Do not assume that the first affected device is the only affected device. An attacker may have entered through one employee account, moved laterally, created persistence, and then deployed ransomware days or weeks later.

Your cybersecurity consulting team or forensic provider should review identity activity, endpoint alerts, network traffic, cloud logs, email traces, and privileged account changes.

Prioritize systems that support mission critical operations, but do not restore them until the attack path is understood. Restoring too early can reintroduce the attacker.

RANSOMWARE AND BEC REQUIRE DIFFERENT FIRST MOVES

The response framework is similar, but the immediate priorities differ.

RANSOMWARE

Ransomware response focuses on containment and preventing further encryption.

Your team should:

  • Isolate infected systems and affected network segments.
  • Protect offline and immutable backups.
  • Identify whether data was exfiltrated before encryption.
  • Determine whether administrative credentials were compromised.
  • Preserve ransom notes and attacker communications.
  • Avoid paying or negotiating without legal, insurance, and forensic guidance.
  • Check for sanctions and other legal risks before any payment discussion.
  • Report to law enforcement and relevant authorities as advised.

Do not assume payment solves the incident. Payment does not guarantee decryption, deletion of stolen data, or removal of attacker access. CISA and its federal partners do not recommend rushing to pay a ransom.

Isolated network nodes and protected backup storage representing ransomware containment and segmentation

BUSINESS EMAIL COMPROMISE

Business email compromise is usually an account, communication, and payment crisis rather than a system-encryption crisis.

Your team should:

  • Disable or secure the compromised account.
  • Revoke active sessions and reset credentials.
  • Enforce multifactor authentication.
  • Remove malicious forwarding rules and OAuth permissions.
  • Review sent, deleted, and mailbox access activity.
  • Notify finance and purchasing immediately.
  • Contact the bank or payment provider about suspicious transfers.
  • Alert vendors or customers who may have received fraudulent instructions.
  • Preserve the original emails and full headers.

Speed matters with BEC. A fraudulent wire transfer may be reversible for only a short period. Do not wait for the forensic report before notifying your bank about a suspicious transaction.

Business email compromise response showing a suspicious payment intercepted by identity verification and multifactor authentication

HOURS 6–24: PLAN NOTIFICATIONS AND SAFE RECOVERY

You are not automatically required to notify everyone the moment an incident is discovered. You are required to assess the facts quickly and follow the laws, regulations, contracts, and insurance requirements that apply to your business.

Work with legal counsel to determine:

  • Whether personal, financial, health, or regulated information was accessed.
  • Which states or countries are involved.
  • Whether customers, employees, vendors, or business partners must be notified.
  • Whether sector-specific rules apply.
  • Whether regulators, law enforcement, or consumer protection agencies must be contacted.
  • Whether contractual notification deadlines apply.
  • What the notice must contain and when it must be sent.

All U.S. states and several territories have breach notification laws, but requirements vary. Some laws apply only when certain types of personal information are involved. Others impose specific timelines. Your counsel should make the final determination.

The FTC’s Data Breach Response Guide for Business recommends mobilizing a response team, using forensics and legal counsel, securing operations, preserving evidence, and notifying appropriate parties.

During this period, prepare a recovery plan without rushing restoration:

  • Identify clean systems and known-good backups.
  • Prioritize identity services and mission-critical applications.
  • Rebuild in an isolated environment when possible.
  • Scan backups before using them.
  • Rotate credentials after containment and eradication.
  • Close the original access path.
  • Validate that persistence mechanisms are removed.
  • Restore systems in a controlled sequence.
  • Monitor closely after reconnection.

This is where incident response transitions into disaster recovery. Do not skip the first phase.

THE MISTAKES SMBs MAKE IN THE FIRST HOUR

Avoid these common errors:

  1. Rebooting every affected device. This may destroy volatile evidence.
  2. Wiping or rebuilding systems immediately. It can erase information needed to identify the attacker.
  3. Continuing to use compromised email. The attacker may be monitoring your response.
  4. Waiting to call the insurer. You may miss policy requirements or approved forensic resources.
  5. Paying quietly. Payment can create legal, financial, and operational risks.
  6. Restoring from the first available backup. The backup may be encrypted, corrupted, or infected.
  7. Letting everyone communicate externally. Conflicting statements create confusion and legal exposure.
  8. Assuming ransomware did not involve data theft. Modern attacks often combine encryption with exfiltration.
  9. Ignoring BEC because no malware was found. A stolen mailbox can still cause major financial loss.
  10. Failing to document decisions. A missing timeline weakens the investigation and post-incident review.

BUILD A PLAN YOU CAN ACTUALLY USE

A gold-standard incident response plan does not need to be 100 pages. It needs to be current, accessible, assigned, and tested.

At minimum, your plan should include:

  • A contact tree with after-hours numbers.
  • Decision authority for isolating systems.
  • Cyber insurance reporting instructions.
  • Evidence preservation procedures.
  • Ransomware and BEC checklists.
  • Legal and regulatory escalation criteria.
  • Internal and external communications templates.
  • Critical systems and recovery priorities.
  • Backup isolation and restoration procedures.
  • A process for documenting every action.

We help small and mid-size organizations build practical security programs through IT consulting services, cybersecurity capabilities, and advisory services. We can also coordinate with your existing IT team, MSP, insurer, legal counsel, or forensic provider. The goal is not to create dependency. The goal is to give you a clear plan and the confidence to use it.

HAVE AN HONEST CONVERSATION BEFORE YOU NEED ONE

If you are responding to an active incident, contact your insurer, legal counsel, and incident response provider first.

If you are preparing before an incident happens, start with an honest conversation. We can review your current contacts, escalation process, backups, logs, and recovery priorities without turning the discussion into a high-pressure sales pitch.

Tell us where your plan is strong, where it is incomplete, and what needs to change first. Visit Five 9 LLC’s contact page to begin.

Five 9 Assistant

Automated · not a live person