What should I do during an active cyber incident?¶
During an active cyber incident, the immediate task is to control harm while preserving enough evidence to understand and investigate what is happening.
Avoid this assumption: Evidence preservation should delay containment, or that containment should be carried out without recording the original state. Both extremes can damage the investigation and the organisation.
Identify the active harm. Is data being stolen, systems encrypted, accounts abused, services disrupted or people placed at risk?
Record affected systems, accounts, users, locations, alerts, times and visible activity.
Preserve current screens, sessions, processes, network connections, security alerts and decision logs before action where this can be done without unacceptable delay.
Notify the appropriate incident-response, network, security, legal and operational contacts.
Use the narrowest effective containment measure. Isolating one device, account or network segment may be preferable to shutting down everything.
Record every action, authorisation, time and resulting change.
Do not start exploring systems or deleting malware without a coordinated plan.
Preserve incident tickets, internal messages, provider communications, configuration changes and responder notes.
Consider public safety, business continuity, safeguarding and regulatory obligations alongside evidence.
Do not assume the first affected device is the point of entry or the only compromised system.
Where the attacker may still be active, specialist coordination is essential to avoid alerting them prematurely or losing visibility.
Record any systems intentionally left connected and the reason for doing so.
Operational takeaway¶
During an active incident, define the harm, preserve the live state where practicable, use coordinated proportionate containment and document every decision and system change.