WHAT YOU WILL LEARN
Learning objectives
- Report facts separately from guesses
- Limit immediate exposure within your authority
- Preserve a useful incident timeline
Start with safety and reporting
Describe what you observed, when it started, the affected device or account, and what you already did. Use your organisation’s incident contact. If normal email or chat may be compromised, use an approved separate channel. Prioritise human safety and critical services before routine troubleshooting.
Contain without destroying evidence
Follow the response plan. A trained responder may isolate a device from the network while keeping it powered to preserve volatile evidence. Do not run random cleanup tools or reset devices before getting guidance. Containment decisions differ for a personal laptop, a shared server and a safety-critical system.
Record a timeline
Write down the time of the first symptom, messages displayed and actions taken. Keep original logs and messages as directed. Avoid uploading private company data to public analysis services. A clear timeline helps responders understand scope and distinguish the attack from later recovery actions.
APPLIED EXAMPLE
Put it in context
A user sees a suspicious encryption notice on a work laptop. They contact IT using a known phone number, follow isolation instructions and record the message. They do not experiment with a “decryptor” found in a search result.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Keeping an incident quiet out of embarrassment
- Wiping the device before responders assess it
- Uploading confidential files to public tools
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
Report promptly, contain proportionately and preserve context. The best first action depends on the system and the approved response plan.