The short answerAssign an authorized incident lead, record what triggered concern, isolate affected systems when safe, protect critical accounts, preserve available evidence, identify affected users and business functions, and escalate to the appropriate security, legal, insurance, provider, or law-enforcement resources. Avoid uncoordinated cleanup that erases evidence or spreads the incident.

A security alert is not automatically a confirmed breach, but uncertainty is not a reason to ignore it. The first hour should reduce the chance of further harm while preserving enough information to determine what happened. The response must match the event: a suspicious sign-in, malware alert, lost device, fraudulent mailbox rule, exposed credential, ransomware note, and active financial fraud require different priorities.

Active danger comes first.If there is an immediate threat to personal safety, critical infrastructure, or an active financial transfer, use the appropriate emergency, banking, insurance, legal, or law-enforcement channel immediately. This guide is general operational information, not emergency response or legal advice.

1. Establish control of the response

  • Name the person authorized to direct containment and approve material changes.
  • Open a timestamped incident record separate from the potentially affected system.
  • Record the original alert, reporter, affected user or device, time discovered, and business impact.
  • Use a known-clean communication path if email or collaboration accounts may be compromised.
  • Limit sensitive incident details to people with a response role.

2. Contain what is known without guessing

  1. Isolate affected endpoints.Disconnect network access or use an approved endpoint-isolation function when active malicious behavior or spread is suspected. Avoid casually browsing, deleting files, or running unplanned cleanup tools.
  2. Protect affected identities.Block or reset compromised credentials through a known-clean administrator session, revoke active sessions, review authentication methods, and protect privileged accounts.
  3. Stop active business harm.Pause suspicious payments, mailbox forwarding, remote access, integrations, or automated processes using the organization's approved authority and provider channels.
  4. Preserve essential services.Do not take unrelated systems offline without understanding dependencies. Containment should reduce risk while keeping decisions deliberate.

3. Preserve evidence that can answer what happened

Capture information before it rolls over or disappears: alert details, timestamps, screenshots, sender and recipient information, message headers, endpoint identity, user reports, sign-in events, IP addresses, filenames, process details, administrative changes, and provider case numbers. Preserve original exports when possible and record who collected each item.

Do not assume a screenshot is sufficient for a forensic investigation. Material incidents may require a qualified incident-response or forensic provider to acquire endpoint, cloud, email, firewall, or application evidence correctly.

4. Build an initial scope

  • Which identities, endpoints, mailboxes, applications, locations, and providers are involved?
  • What is confirmed, what is suspected, and what remains unknown?
  • When did the earliest known activity occur?
  • Were administrator roles, MFA methods, forwarding rules, remote tools, or security controls changed?
  • Could regulated, contractual, customer, employee, financial, or authentication information be involved?
  • What operational processes are stopped, degraded, or at risk?

The initial scope will change as evidence improves. Label assumptions clearly so an early guess does not become accepted fact.

5. Escalate through the correct channels

Review the cyber-insurance policy and incident-response requirements before hiring providers or making representations that could affect coverage. Leadership and qualified counsel should determine notification obligations. Contact banks or payment providers immediately for suspected financial fraud. Engage a specialized incident-response team when the event exceeds available expertise, affects multiple systems, involves extortion, or may require forensic preservation.

What not to do

  • Do not email passwords, API keys, or evidence through an account suspected of compromise.
  • Do not announce a breach before the facts and communication authority are established.
  • Do not wipe or reimage affected systems before preservation decisions are made.
  • Do not restore normal access merely because the first alert disappeared.
  • Do not let multiple vendors make conflicting changes without one response lead.
  • Do not describe unverified assumptions as confirmed impact.

Frequently asked questions

Should a suspicious computer be shut down immediately?

Isolation is often important, but power-off decisions depend on the threat, active harm, encryption risk, evidence needs, and available response expertise. The authorized incident lead should direct the action.

When should insurance, counsel, or law enforcement be contacted?

Follow the incident plan, cyber-insurance conditions, legal obligations, and leadership direction. Material interruption, extortion, regulated information, financial fraud, or suspected criminal activity may require rapid specialized escalation.

Official security references

How CTS can help

CTS can assist with initial technical triage, endpoint and identity review, evidence organization, provider coordination, administrative remediation, and documentation within an authorized scope. Learn more about small business cybersecurity support. Events requiring formal forensics, breach counsel, regulatory determinations, or around-the-clock incident response are escalated to the appropriate specialists.