FREEBeginner · 9 minute read

The first actions after a suspected incident

Respond calmly, preserve useful evidence and get the right people involved.

WHAT YOU WILL LEARN

Learning objectives

  • Report facts separately from guesses
  • Limit immediate exposure within your authority
  • Preserve a useful incident timeline
01

Start with safety and reporting

Describe what you observed, when it started, the affected device or account, and what you already did. Use your organisation’s incident contact. If normal email or chat may be compromised, use an approved separate channel. Prioritise human safety and critical services before routine troubleshooting.

02

Contain without destroying evidence

Follow the response plan. A trained responder may isolate a device from the network while keeping it powered to preserve volatile evidence. Do not run random cleanup tools or reset devices before getting guidance. Containment decisions differ for a personal laptop, a shared server and a safety-critical system.

03

Record a timeline

Write down the time of the first symptom, messages displayed and actions taken. Keep original logs and messages as directed. Avoid uploading private company data to public analysis services. A clear timeline helps responders understand scope and distinguish the attack from later recovery actions.

APPLIED EXAMPLE

Put it in context

A user sees a suspicious encryption notice on a work laptop. They contact IT using a known phone number, follow isolation instructions and record the message. They do not experiment with a “decryptor” found in a search result.

Illustrative scenario for learning, not a claim about a verified customer incident.

Common mistakes

  • Keeping an incident quiet out of embarrassment
  • Wiping the device before responders assess it
  • Uploading confidential files to public tools

Your practical checklist

Checklist ticks are temporary and are not recorded as account progress.

MINI RECAP

Report promptly, contain proportionately and preserve context. The best first action depends on the system and the approved response plan.

Put your understanding to the test.

Further authoritative reading ↗