![]()

Key Takeaways
- The first 60 minutes decide how much worse things get; isolating systems beats shutting them down and destroying evidence.
- Evidence doesn’t get touched, cleaned up, or “just fixed” before it’s documented, it may be needed for insurers, law enforcement, and legal defense weeks later.
- Legal counsel and the cyber insurer usually get called before customers do, and the order isn’t arbitrary.
- Employees hear about it first, in plain language, before a headline or a customer breaks the news.
- Recovery starts once containment is confirmed, not before; restoring systems too early is how the same incident happens twice in one week.
After discovering a breach, the instinct is to fix everything at once. That instinct is worth resisting. The only job in the first hour is to stop the bleeding without destroying evidence that matters later, per DYOPATH’s incident response framework, which lays out exactly what that looks like hour by hour.
Minute 0-60: contain it
Isolating a compromised system, pulling the network cable, disabling Wi-Fi, is almost always better than shutting it off completely. Powering a machine down erases the data in its memory, and that memory is often exactly what a forensic investigator needs to figure out how the attacker got in and where else they went. If a machine is actively encrypting files and isolating it fast enough isn’t possible any other way, powering it off still beats watching it spread. But isolation comes first when it’s an option.
Passwords change on any account known to be involved, starting with admin rights. Multi-factor authentication doesn’t get disabled to “make troubleshooting easier,”; that’s exactly what an attacker wants. Remote access tools, RDP, VPN, any remote desktop software, get locked down unless they’re confirmed clean. And nothing gets announced company-wide yet. A vague “we’re having IT issues” message that leaks before the scope is understood tends to cause more confusion than it prevents.
Hour 1-4: preserve the evidence
Before anyone touches a keyboard to clean up, document what’s in front of them. Ransom notes, error messages, anything on-screen, get photographed with a phone camera, screenshots can be altered later, questioned, or simply lost if the machine reboots. Exact timestamps get noted: when something wrong was first spotted, and when each action after that happened.
Firewall logs, endpoint detection, server logs, none of it gets cleared or overwritten. This is also where system images and forensic copies matter more than a quick restore. NIST’s Computer Security Incident Handling Guide, SP 800-61, lays out the standard for this kind of evidence handling, chain-of-custody included, worth a read for any organization building out its own governance and risk assessment process before the next incident, not during it.
This is also usually when most organizations realize they need outside help. Without a forensics team on retainer, this is the moment to call one, trying to run a full forensic investigation with an internal team that’s never done one before usually costs more time than it saves.
Hour 4-12: make the calls
Three calls matter most in this window, and the order matters. Legal counsel first, because attorney-client privilege can affect what gets written down and how, and because notification laws vary significantly by state and by what kind of data was involved, health records, financial data, and general personal information often carry different clocks and different regulators. The cyber insurance carrier, second, because most policies require notification within a specific window, often 24 to 72 hours, and may require approved vendors for forensics or negotiation; calling after a provider’s already engaged can mean the costs aren’t covered.
Federal reporting sometimes applies too. CISA’s incident response resources outline what’s reportable and to whom, the FBI’s Internet Crime Complaint Center and CISA itself both take reports, and law enforcement involvement is sometimes protective rather than complicating, particularly with ransomware.
None of this gets skipped because of how it looks. Regulators and insurers generally respond far worse to a late or hidden notification than to a prompt, honest one.
Hour 12-24: communicate, carefully
Internally first, then externally if warranted, with legal input on anything that leaves the building. For employees, a short, factual message beats silence or speculation: what’s known, what’s being done, and what they should and shouldn’t do meanwhile, no clicking unfamiliar links, no discussing it on social media, reporting anything unusual immediately. “No data was affected” and “this won’t happen again” shouldn’t be promised before that’s confirmed. Those sentences tend to age badly, and they’re the kind that get quoted back later.
If customers or partners need notifying, that message usually goes through legal review first, and it’s fine for it to be short. A factual holding statement, an incident was detected, it’s being investigated, here’s how to reach us with questions, buys time to get the details right without leaving people in the dark. Leadership gets a real update too, not a summary that makes things sound more settled than they are.
Beyond 24 hours: recover, don’t rush
Once containment is confirmed, not assumed, recovery can start. Restore from clean backups where possible, watch closely for reinfection, and patch whatever vulnerability let the attacker in before considering the incident closed. A system restored and reconnected before the entry point is fixed is often compromised again within days, which is exactly the gap a structured vulnerability management program is built to close ahead of time.
The real remediation work happens next: rotating every credential the attacker may have touched, reviewing what data actually left the network, not just what’s assumed, and closing the gaps a forensic review turns up. This phase runs days to weeks, not hours, anyone who says a serious incident wraps up by end of day is either dealing with something small or skipping steps.
Once things stabilize, there’s a step most organizations skip: a lessons-learned review. What let the attacker in. How long it took to notice. Where the response plan held up and where it didn’t. Skip that step, and the same gap tends to get exploited again, sometimes within the same year.
Why this goes faster for some organizations
Organizations with a written incident response plan in place move through these hours noticeably faster and calmer than those improvising for the first time, not because the situation is any less serious, but because nobody’s arguing about who calls the insurer while the clock runs. That’s the exact gap a managed security service provider relationship closes ahead of time, roles and call order are settled before anything happens, turning a chaotic first day into a sequence someone can actually follow.
DYOPATH
1801 South Meyers Road
Oakbrook Terrace
Illinois
60181
United States
