Skip to Content

What Organisations Should Do in the First Hour of a Cyber Incident.

The first hour is not about solving everything. It is about making the next six hours easier: preserve evidence, limit attacker freedom, establish control of the response and avoid irreversible decisions made under pressure.

The first objective is control, not certainty

When a serious incident begins, teams often wait for certainty before acting. That is understandable and dangerous.

You rarely know the full scope in the first hour. You may only have an endpoint alert, unusual identity activity, a suspicious mailbox rule, a ransom note, an administrator account behaving strangely or traffic that does not fit the normal pattern.

The first-hour objective is therefore not to produce a complete root-cause analysis. It is to establish enough control that the incident does not become harder to investigate or contain.

Preserve evidence before you destroy it

Well-intentioned response can erase exactly the evidence needed to understand what happened.

Reimaging a compromised endpoint, deleting suspicious accounts, rebooting servers, clearing logs or removing files may stop visible symptoms while also destroying volatile data, timestamps, process information, session artefacts and attacker tooling.

Preservation does not mean leaving a dangerous system untouched. It means coordinating containment with evidence collection. If a host must be isolated, isolate it. If an account must be disabled, disable it. But record what was done, when it was done and what evidence was collected first.

Every containment action changes the scene.

Treat the environment as both an active security problem and an evidence source.

Contain the attacker without announcing every move

Containment should reduce attacker capability, but aggressive action can reveal that the organisation has detected the intrusion.

If the attacker still has multiple access paths, disabling one account may simply push them to another. Blocking one IP address may have little value if they are using cloud infrastructure, compromised endpoints or legitimate remote-access services.

Effective containment is based on observed access paths. That may mean isolating selected endpoints, revoking tokens, resetting specific credentials, disabling persistence mechanisms, restricting remote access or segmenting affected systems.

The response team should avoid broad changes that create unnecessary disruption unless the business impact of continued attacker access clearly outweighs the operational cost.

Build a timeline immediately

The incident timeline starts before you understand the incident.

Record the first alert, the first human observation, the systems involved, the identities involved and every response action taken. Capture exact timestamps and time zones. Preserve screenshots where useful, but do not rely on screenshots as the primary evidence source.

A disciplined timeline helps the team correlate endpoint, identity, firewall, cloud, email and application logs later. It also prevents repeated work when multiple teams are investigating the same event from different angles.

Decide who is actually in charge

Technical incidents become organisational problems quickly.

Someone needs authority to coordinate the response, decide priorities, control communications and resolve conflicts between operational teams. That person does not need to perform the forensic analysis themselves.

The organisation should also identify who owns legal, regulatory, privacy, executive and external communications decisions. Those functions may not need to act immediately, but they should not be discovered for the first time when the incident is already escalating.

A clear incident lead prevents parallel teams from making contradictory changes to the environment.

Secure the accounts responders are using

Response teams often focus so heavily on the compromised environment that they forget their own access can become part of the attack path.

Use trusted administrative accounts, strong authentication and known-clean devices where possible. Avoid sending sensitive investigation details through channels that may be compromised. If business email compromise is suspected, assume that ordinary email communication may be visible to the attacker until proven otherwise.

The response process itself needs a trusted communication path.

What should exist before the incident happens

The best first-hour response is prepared before the first hour begins.

Organisations should know who can isolate endpoints, revoke cloud sessions, disable accounts, preserve logs, contact key vendors, approve emergency changes and engage external incident-response support. Critical log sources should have sufficient retention, and responders should know how to access them quickly.

Incident response becomes dramatically slower when every action requires discovering a process, owner or credential during the crisis.

The first hour will always contain uncertainty. Preparation determines whether that uncertainty becomes controlled investigation or operational chaos.

Keep Reading.

RELEVANT XDEFENSE SERVICE

Incident Response & Digital Forensics

Turn the ideas in this blog into a practical security decision for your environment.

Explore Service