PKTCCybersecurity& I.T. Services
Guides

Guide

First Steps After a Suspected Security Incident

A calm, evidence-conscious starting point for organizations that suspect an account, endpoint, or network has been compromised.

7 min readUpdated October 2026

The first decisions made during a suspected incident can affect both recovery and the evidence needed to understand what happened. Move quickly, but avoid uncoordinated actions that destroy information or alert an attacker before containment is ready.

Establish control and document

Create a single communication channel and begin a timeline. Record what was observed, when it occurred, who took action, and which systems may be involved.

  • Notify the designated incident lead and appropriate business leadership.
  • Preserve suspicious messages, alerts, log sources, and affected device details.
  • Use a trusted communication method if normal email or collaboration systems may be compromised.
  • Contact cyber insurance and legal counsel when required by your response plan.

Contain carefully

Containment should reduce harm without unnecessarily destroying evidence. The appropriate action depends on the incident and environment.

  • Isolate affected endpoints from the network when ongoing harm is likely.
  • Disable or restrict confirmed compromised accounts and revoke active sessions.
  • Do not wipe, reimage, or power off systems until response personnel evaluate evidence needs.
  • Avoid broad password resets from potentially compromised devices.

Bring in the right help

Seek experienced incident assistance when the scope is unclear, privileged accounts are involved, sensitive data may be exposed, or business operations are disrupted. This guide is general information—not a substitute for incident-specific forensic, legal, or regulatory advice.

This resource provides general educational information. Security, legal, compliance, and incident-response decisions should be based on your specific environment and professional advice where appropriate.