What to Do in the First 24 Hours After a Cybersecurity Incident
A security incident rarely announces itself politely.
It’s a ransomware note on a locked screen. A vendor calling to ask why your emails suddenly look strange. An employee who can’t log in, or worse, one who can log in but shouldn’t be able to.
However it starts, the first 24 hours after you realize something is wrong are the most important – and the easiest to get wrong.
What you do (and don’t do) in that window can determine how much the incident actually costs your business.
Step One: Don’t Panic, and Don’t Improvise
The instinct in the first few minutes is often to start clicking around – disconnecting things, restarting servers, deleting suspicious files, or trying to “fix” the problem before anyone else finds out.
Resist that instinct.
Well-intentioned troubleshooting can destroy the evidence needed to understand what happened, and can sometimes make the underlying problem worse.
The first move isn’t a technical one. It’s a phone call.
Step Two: Contain, Don’t Investigate
Before anyone tries to figure out exactly what happened, the priority is stopping it from getting worse.
That typically means:
-
Isolating affected devices from the network (unplugging or disabling Wi-Fi, not powering them off)
-
Disabling compromised user accounts
-
Resetting passwords for accounts that may be affected
-
Preserving logs and evidence rather than deleting or overwriting them
This is where having a partner who has done this before matters. Containing an incident correctly, without destroying evidence or triggering a bigger disruption, isn’t something most internal teams do more than once or twice in their careers.
Step Three: Figure Out What’s Actually Affected
Once the situation is contained, the next question is scope.
What systems were touched? What data was accessed? Which accounts were involved? Is the threat still active, or has it been stopped?
This step matters for more than curiosity. It determines who needs to be notified, whether there are regulatory or contractual reporting obligations, and how the recovery plan should be structured.
Step Four: Loop in the Right People – Internally and Externally
A cybersecurity incident isn’t purely an IT problem. Depending on what’s involved, it may need input from leadership, legal counsel, insurance carriers, and in some cases, law enforcement.
Knowing who needs to be told, and in what order, shouldn’t be figured out for the first time in the middle of a crisis.
Step Five: Start Recovery – Deliberately, Not Frantically
Once the threat is contained and the scope is understood, recovery can begin.
That might mean restoring from backups, rebuilding affected systems, or working through a broader business continuity plan.
Speed matters, but so does making sure the same door doesn’t get left open on the way back in.
The Best Time to Plan for This Is Before It Happens
Every one of these steps is easier – and faster – when there’s already a plan in place.
Businesses that have a designated incident response contact, a documented process, and current backups tend to recover in hours or days. Businesses that are improvising for the first time during the incident itself often take weeks, and pay for it.
Is Your Business Prepared for the First 24 Hours of an Incident?
If you’re currently in the middle of a security incident, don’t wait: contact our incident response team or call 877-678-0155, option 7, available 24/7.
If you’re not in the middle of one, now is the time to build the plan. Schedule a complimentary consultation to talk through how prepared your business actually is.


