Guide
First Steps After a Suspected Security Incident
A calm, evidence-conscious starting point for organizations that suspect an account, endpoint, or network has been compromised.
The first decisions made during a suspected incident can affect both recovery and the evidence needed to understand what happened. Move quickly, but avoid uncoordinated actions that destroy information or alert an attacker before containment is ready.
Establish control and document
Create a single communication channel and begin a timeline. Record what was observed, when it occurred, who took action, and which systems may be involved.
- Notify the designated incident lead and appropriate business leadership.
- Preserve suspicious messages, alerts, log sources, and affected device details.
- Use a trusted communication method if normal email or collaboration systems may be compromised.
- Contact cyber insurance and legal counsel when required by your response plan.
Contain carefully
Containment should reduce harm without unnecessarily destroying evidence. The appropriate action depends on the incident and environment.
- Isolate affected endpoints from the network when ongoing harm is likely.
- Disable or restrict confirmed compromised accounts and revoke active sessions.
- Do not wipe, reimage, or power off systems until response personnel evaluate evidence needs.
- Avoid broad password resets from potentially compromised devices.
Bring in the right help
Seek experienced incident assistance when the scope is unclear, privileged accounts are involved, sensitive data may be exposed, or business operations are disrupted. This guide is general information—not a substitute for incident-specific forensic, legal, or regulatory advice.