Your Incident Response Plan: What to Do in the First Hour of a Breach

Almost every breach we have helped clean up got meaningfully worse in the first hour — not because of the attacker, but because of well-meaning decisions made under pressure. Someone powers off the server. Someone deletes the suspicious files. Someone calls a friend who "knows computers" and starts remediating before the insurance carrier has been told. Each of those feels like taking action. Each one costs you.

The fix is unglamorous: a one-page written plan that tells whoever discovers the problem exactly what to do, in order, before anyone has to think.

Isolate — but do not power off

The first move is to stop the spread. Unplug the network cable or disable the wireless adapter on affected machines, or have your security tooling isolate them remotely. If a whole segment is involved, pull the internet connection at the firewall rather than shutting individual systems down.

Do not power the machine off. A large amount of useful evidence — running processes, network connections, encryption keys still sitting in memory — disappears the moment the power does. In some ransomware cases, keys recovered from memory have made recovery dramatically cheaper. Once it is off, that option is gone permanently.

Preserve evidence and stop touching things

Everything the responders need to reconstruct the attack lives in logs, and logs roll over. Before anyone starts cleaning up:

  • Leave affected systems on and isolated. Do not reimage, do not run cleanup tools, do not delete suspicious files.
  • Preserve firewall, VPN, server, and Microsoft 365 or Google Workspace sign-in logs. Extend retention now if you can — default retention windows are often short.
  • Write down a plain timeline as you go: who noticed what, at what time, and what was done in response. Screenshots of ransom notes or odd messages help.
  • Stop using potentially compromised email accounts for coordination. Move to phone or a separate channel.

Call in the right order

Order matters more than speed here. A workable default:

  1. Your IT or security provider — to confirm scope and complete containment.
  2. Your cyber insurance carrier or broker — before remediation begins.
  3. Legal counsel — often engaged by the carrier, which can help protect the investigation under privilege.
  4. Leadership, then any regulator, customer, or partner notifications your counsel confirms are required.
  5. Law enforcement, typically the FBI through IC3, where appropriate.

Notify your insurer before you remediate

This is the step businesses most often get wrong. Most cyber policies require you to report an incident promptly and to use the carrier's approved panel of forensics and legal vendors. If you hire your own firm and start rebuilding first, you may be paying for work the policy would have covered — and in some cases you can jeopardize the claim entirely.

Find your policy number, the 24-hour claims hotline, and the notification requirements today, and put them on the same page as the rest of the plan. Nobody should be searching a filing cabinet at midnight.

Know your notification clock

Breach notification duties depend on what data was involved and where your customers live. Health data, financial data, and personal information carry different obligations, deadlines vary by state and by regulator, and contracts with larger clients frequently impose their own reporting windows. You do not need to memorize all of it — you need counsel involved early enough that the clock does not run out while you are still arguing about whether it started.

Decide your communications ahead of time

Name one person who speaks for the company, agree that nobody else does, and draft holding language now. Say what you know, what you are doing, and when you will update — nothing more. Guessing publicly about scope early is how a contained incident turns into a credibility problem.

Equal Tech Solutions builds incident response plans that fit on one page, keeps them current, and stands behind them when something actually happens — containment, evidence preservation, carrier coordination, and recovery.

The worst time to write a response plan is during the incident it was meant to cover. Equal Tech Solutions serves Chattanooga, Cleveland, and the Southeast US. Contact Equal Tech Solutions to build your first-hour runbook before you need it.