Incident management

Cyber incident: the first 60 minutes without making it worse

The first hour is not for fixing everything. Isolate what is affected, preserve the traces, assign the roles and prepare a controlled decision.

An unplugged network cable, a stopwatch and three blank cards make up an incident management desk.
In this article

A screen displays an unusual message. Files will not open. An administrator account signs in from an unfamiliar location. In the first few minutes, the temptation is strong to reboot, delete files, or ask the whole team to "check whether it still works".

Those reactions are understandable, but they can erase traces, spread the incident or make recovery harder. The goal of the first hour is not to repair everything. It is to limit the damage, preserve the useful information and organise a response.

First, describe what is actually being observed

Note the first signal with a precise time:

  • which device or service is affected;
  • who observed the problem;
  • what was displayed, or stopped working;
  • the last normal actions carried out;
  • the people already informed.

Avoid concluding straight away that this is ransomware, a leak or a targeted attack. An outage and a cyberattack can produce similar symptoms. Describing the facts lets the provider or the technical team decide faster.

Isolate without destroying the traces

If a computer appears to be actively compromised, disconnect it from the wired network and from Wi-Fi. Do not automatically power the device off. Memory, active connections and other traces may be useful to the analysis.

There are exceptions to that rule. Equipment that presents a physical danger, heats up abnormally or controls a sensitive process must be handled according to the site's safety procedures. The safety of people comes before the preservation of evidence.

Do not plug in a USB stick to "quickly rescue" documents. Do not connect a backup drive to a potentially compromised system. You risk extending the incident to copies that are still clean.

Appoint someone to coordinate

A small organisation does not need a complex committee. It needs one person keeping the timeline and another retaining the authority to decide.

Assign the roles:

  • overall coordination;
  • contact with the provider or the IT team;
  • decisions on which services to suspend;
  • communication with staff and partners;
  • preservation of evidence and references.

The same people can hold several roles. What matters is that two contradictory calls are not placed to the same supplier, and that nobody restores a service while someone else is trying to contain it.

The first ten minutes

Concentrate on four actions:

1. note the time and the symptoms;
2. isolate the clearly affected equipment;
3. contact the person responsible and the provider on record;
4. forbid improvised handling of the devices concerned.

If the usual mailbox appears compromised, use another channel to coordinate the response. Avoid, however, transferring sensitive data to personal accounts without a framework.

Between ten and thirty minutes

Establish the scope of the problem without multiplying connections:

  • one workstation or several;
  • one account or several;
  • a local service or a cloud provider;
  • backups that are accessible or potentially exposed;
  • activity still under way, or an event already over.

Ask the provider to preserve the logs, sessions, IP addresses and authentication events. Photograph the screens if a normal capture is not possible. Keep the original emails rather than plain copies of the text.

If a payment, a banking fraud or a change of account details is involved, contact the bank immediately through its official channel. The ability to stop a transaction diminishes with time.

Between thirty and sixty minutes

The organisation must now decide what stays open and what must be suspended. Base that decision on the real impact:

  • service essential to citizens or clients;
  • risk of spreading;
  • exposure of personal data;
  • dependence on a supplier;
  • availability of a continuity solution.

Prepare a first, factual internal message. State what is being observed, what users should do, which channels to avoid, and the time of the next update.

Do not name a culprit and do not announce a leak before it is confirmed. Cautious communication can be transparent without presenting a hypothesis as a fact.

Report and ask for help

Organisations can report a cyber incident to the Centre for Cybersecurity Belgium. Entities subject to NIS2 have specific obligations and deadlines. They must use the channel provided by the CCB and not wait for the internal investigation to finish.

A police complaint may also be necessary, particularly in cases of fraud, extortion, data theft or interference with a system.

Notification is not proof of failure. It provides guidance, allows similar incidents to be connected, and documents the facts properly.

Do not restore too early

The pressure to bring the service back online is strong. Yet restoring a backup into an environment that is still compromised can let the attacker back in, or contaminate the copy.

Before resuming:

  • identify the entry point where possible;
  • change exposed secrets and passwords from a clean device;
  • fix the vulnerability or the misconfiguration;
  • verify the integrity of the backups;
  • reconnect gradually;
  • watch for new signals.

A backup is not a recovery plan if nobody has tested restoring it.

The crisis page to prepare today

Print a single page containing:

  • the name of the coordinator and their deputy;
  • the numbers of the provider, the host, the bank and the insurer;
  • the CCB reporting channel;
  • the services to restore first;
  • where the backups are held;
  • the first instructions on isolation and preservation.

That page must stay reachable when the mailbox, the shared storage or the password manager no longer are.

Official sources

Practical timeline of the first sixty minutes after a cyber incident
Editorial information
Written by
Jeremy Kraft
Last reviewed
Method
Public sources, editorial review and proportionate guidance.
← Publications