🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
The first 24 hours: what to do in the moment everything is on fire
Incident Response

The first 24 hours: what to do in the moment everything is on fire

ERD Research TeamJul 11, 20267 min read

Key takeaways

  • Isolate, don't power off — pulling network access contains spread while preserving the forensic evidence a shutdown destroys.
  • Don't delete the ransom note or reboot affected machines; both erase options you may need for identification, recovery, and claims.
  • Engage IR, legal, and your insurer in parallel in the first hours — the order you notify them affects privilege and coverage.

First move: isolate, don't investigate

The instinct in the first minutes is to start clicking — reboot the affected machine, delete the note, open an encrypted file to see how bad it is. Resist all of it. The first correct action is almost always to isolate, not investigate: disconnect affected endpoints from the network by pulling the cable or disabling Wi-Fi, and cut off the pathways an active attacker is using. Isolation contains spread; investigation on the live host can tip the attacker off or trigger the very destruction you're trying to prevent.

Don't destroy what you'll need later

Do not power off affected machines — memory-resident forensic evidence is lost on shutdown, and modern IR teams can often work from a live, isolated system. Do not delete the ransom note; it identifies the variant, may enable a known decryptor, and is needed for insurance and law enforcement. Do not reboot in hopes it 'fixes' things. Each of these instinctive actions destroys evidence, recovery options, or both, and they can't be undone once done.

Mobilize the right people in parallel

The first hours are about parallel notification, not a serial checklist. Engage your incident response firm (or your insurer's panel), legal counsel, and your cyber insurer — the order matters, because notifying counsel early can preserve legal privilege over the investigation, and engaging the insurer promptly protects coverage that many policies condition on early notice. If you have a retainer, this is what you're paying for; if you don't, this is the call you make first.

Establish command and preserve the clock

Stand up a single incident bridge with a clear incident commander, and start a timeline — who did what, when — from the first minute. Decisions made in the fog of hour one look very different in the post-incident review and in any regulatory filing, and a contemporaneous log is worth more than anyone's memory. The goal of the first 24 hours isn't to fix the problem; it's to contain the damage and preserve every option — recovery, negotiation, legal, insurance — that a panicked reaction would have closed off.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy