First decisions
The priority is not to "switch everything back on". It is to understand what is happening, limit the spread, preserve what will make analysis possible and maintain a common command across business, IT, cyber, legal and communications.
Powering off, reinstalling or massively modifying systems can destroy useful evidence. Containment actions must be decided with the incident response team according to the context.
1. Set up the crisis cell
Name a decision-maker, a technical lead and a crisis log. Separate the coordination channel from the potentially compromised environment. List the essential services, the dependencies and the decisions that require management approval.
2. Qualify and contain
- Identify the presumed entry point, the period and the affected accounts.
- Isolate the relevant segments or systems in a controlled way.
- Preserve logs, images, messages and useful timestamps.
- Revoke or renew secrets from a trusted environment.
- Watch for signs of persistence and lateral movement.
3. Steer the obligations in parallel
Legal counsel, the DPO, the insurer and the authorities must be mobilised depending on the nature of the incident and the applicable deadlines. Notifications must not wait for the end of the investigation: they rest on dated facts, updated as the analysis progresses.
4. Restore on a trusted base
Recovery follows a business order, not just a technical one. Each restoration verifies the integrity of the source, the exploited vulnerabilities, the identities, administrative access and the monitoring capability. A service that is not observed must not be considered durably restored.
5. Turn the incident into a resilience plan
The lessons-learned review connects technical causes, organisational factors and business impact. It produces actions with an owner, a deadline and expected evidence: segmentation, identity, patching, backups, detection, suppliers and exercises.