§ Cybersecurity proof & diagnostic assets·print-friendly · decision card

The first 60 minutes of an incident, decided in advance.

A one-page decision card for the opening hour of a suspected security incident: who declares, who isolates, who to call, what to preserve, and what not to do. Print it and keep it where your team will find it under pressure.

About this asset

Audience
IT and business leaders at organizations without a dedicated 24-hour security team who want the opening decisions pre-agreed.
Owner service
Incident Response & Ransomware Readiness
Classification
Classification: Public · Version 1.0 · July 2026
Methodology
The decision blocks reflect the incident-response and recovery outcomes in NIST Cybersecurity Framework 2.0 (NIST CSWP 29, the Respond and Recover Functions) and CISA's #StopRansomware guidance. It is a planning template for your own plan, not a substitute for one.
Limitations
Point-in-time, self-diagnostic planning aid you adapt yourself. It is not a DSE assessment, an audit, live incident response, digital forensics, or legal advice, and it produces no compliance result or certification.
Verification
The framework and guidance references were checked against the csrc.nist.gov and cisa.gov landing pages linked below. Roles and steps are generic planning defaults, not directives for any specific incident.
The decision card

Three time blocks, named owners.

Assign a real person to each role before an incident. The times are targets to force early decisions, not guarantees.

Detect & declare

0–10 minutes
  • Declare. The on-call IT lead decides whether this is an incident and declares it — erring toward declaring. Owner: IT lead / incident commander
  • Assemble. Notify the pre-named response group (IT, a business owner, and leadership) through an out-of-band channel in case email is affected. Owner: incident commander
  • Preserve. Start a written timeline and begin capturing what is known; do not alter affected systems yet. Owner: scribe

Contain & notify

10–30 minutes
  • Isolate. Disconnect affected hosts from the network — not power them off — to stop spread while preserving volatile evidence. Owner: IT / infrastructure
  • Call counsel. Engage legal counsel early — whether and how privilege applies, and what notification obligations exist, are counsel's determinations, and they are easier to make from the first hour. Owner: incident commander → counsel
  • Call the insurer. Notify your cyber-insurance carrier hotline — check your own policy's notice terms, which may condition coverage on timing. Owner: business owner → carrier hotline
  • Preserve evidence. Capture logs, keep ransom notes and suspicious emails, and photograph affected screens. Owner: IT + scribe

Stabilize & decide

30–60 minutes
  • Scope. Determine what is affected, whether data was accessed or exfiltrated, and whether backups are intact. Owner: IT lead
  • Route decisions. Send privilege, notification, and any ransom questions to counsel and leadership — never decide them ad hoc. Owner: incident commander
  • Select help. If you need live response or forensics, engage your pre-selected provider (or the carrier's) under contract. Owner: business owner

What NOT to do in the first hour

  • Do not wipe, reimage, or rebuild affected systems — you destroy the evidence needed to scope the incident and support a claim.
  • Do not power affected machines off if isolation is possible; you lose volatile evidence.
  • Do not pay, or promise to pay, a ransom ad hoc — whether payment is lawful or advisable is a determination for counsel, leadership, law enforcement, and your insurer, never an IT decision.
  • Do not improvise customer or regulator notifications. Obligations and deadlines vary by regime and can be short — route timing and content through counsel immediately rather than deciding ad hoc.

Turn this card into a plan your team has rehearsed.

A free 30-minute Cyber Risk Check scopes an incident-response readiness engagement — plan and role mapping, a tabletop, and a partner-handoff plan — so the first hour is practiced, not improvised.

What this is and is not. A point-in-time planning aid for your team's own plan. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice. DSE does not provide live incident response, digital forensics, or a 24/7 hotline; where you need those we help you scope and select a provider you contract directly. It does not guarantee any incident, recovery, or claim outcome.

Primary sources, verified.