What should I do during an active cyber incident?¶
Define the continuing harm, bring the appropriate response team together and use proportionate containment while preserving the live state whenever the delay is safe.
Establish what is happening now¶
Identify affected services, accounts, users and locations and whether data is leaving, systems are being encrypted, accounts abused or people placed at risk. Record visible alerts, sessions, processes, connections and times. The first affected device may be neither the entry point nor the full extent of compromise.
Notify incident-response, network, security, legal and operational owners appropriate to the environment. Uncoordinated exploration or malware deletion can overwrite evidence, disrupt services or alert an active operator.
Make containment traceable¶
Choose the narrowest measure that can control the harm - possibly one identity, device, interface or segment - while considering critical services, public safety, continuity and safeguarding. Record the authority, action, exact time and resulting changes, including systems intentionally left connected and why.
Preserve tickets, responder notes, internal messages, provider communications and configuration changes. These records explain decisions and separate attacker activity from the response. Where serious harm cannot wait, act first under appropriate authority and record what live evidence could not be captured.
Key takeaway
During an active incident, coordinate around the defined harm, preserve volatile state where safe and document every containment choice and system change needed to reconstruct the response.