The first 60 minutes of an incident, decided in advance.
A one-page decision card for the opening hour of a suspected security incident: who declares, who isolates, who to call, what to preserve, and what not to do. Print it and keep it where your team will find it under pressure.
Three time blocks, named owners.
Assign a real person to each role before an incident. The times are targets to force early decisions, not guarantees.
Detect & declare
0–10 minutes- Declare. The on-call IT lead decides whether this is an incident and declares it — erring toward declaring. Owner: IT lead / incident commander
- Assemble. Notify the pre-named response group (IT, a business owner, and leadership) through an out-of-band channel in case email is affected. Owner: incident commander
- Preserve. Start a written timeline and begin capturing what is known; do not alter affected systems yet. Owner: scribe
Contain & notify
10–30 minutes- Isolate. Disconnect affected hosts from the network — not power them off — to stop spread while preserving volatile evidence. Owner: IT / infrastructure
- Call counsel. Engage legal counsel early — whether and how privilege applies, and what notification obligations exist, are counsel's determinations, and they are easier to make from the first hour. Owner: incident commander → counsel
- Call the insurer. Notify your cyber-insurance carrier hotline — check your own policy's notice terms, which may condition coverage on timing. Owner: business owner → carrier hotline
- Preserve evidence. Capture logs, keep ransom notes and suspicious emails, and photograph affected screens. Owner: IT + scribe
Stabilize & decide
30–60 minutes- Scope. Determine what is affected, whether data was accessed or exfiltrated, and whether backups are intact. Owner: IT lead
- Route decisions. Send privilege, notification, and any ransom questions to counsel and leadership — never decide them ad hoc. Owner: incident commander
- Select help. If you need live response or forensics, engage your pre-selected provider (or the carrier's) under contract. Owner: business owner
What NOT to do in the first hour
- Do not wipe, reimage, or rebuild affected systems — you destroy the evidence needed to scope the incident and support a claim.
- Do not power affected machines off if isolation is possible; you lose volatile evidence.
- Do not pay, or promise to pay, a ransom ad hoc — whether payment is lawful or advisable is a determination for counsel, leadership, law enforcement, and your insurer, never an IT decision.
- Do not improvise customer or regulator notifications. Obligations and deadlines vary by regime and can be short — route timing and content through counsel immediately rather than deciding ad hoc.
Turn this card into a plan your team has rehearsed.
A free 30-minute Cyber Risk Check scopes an incident-response readiness engagement — plan and role mapping, a tabletop, and a partner-handoff plan — so the first hour is practiced, not improvised.
What this is and is not. A point-in-time planning aid for your team's own plan. It is not a DSE assessment, an audit, an attestation, a certification, or legal advice. DSE does not provide live incident response, digital forensics, or a 24/7 hotline; where you need those we help you scope and select a provider you contract directly. It does not guarantee any incident, recovery, or claim outcome.
Primary sources, verified.