top of page

The First 60 Minutes: A Step-by-Step Incident Response Guide

  • Writer: Jeremy
    Jeremy
  • 4 days ago
  • 4 min read

When a cyberattack hits your business, what you do in the first hour dictates everything that follows. It is the critical window that determines whether an incident is contained quickly or metastasizes into a multi-week operational shutdown.


The first 60 minutes are also when it's easiest to make costly, panicked mistakes—like turning off the wrong server, wiping forensic evidence, or sending status updates from an email account the attacker is actively monitoring.


Here is a clear, prioritized action plan so your team isn't guessing when seconds count.


Rule Zero: Don't Make It Worse


Before touching a keyboard, ensure your team avoids these four common mistakes:

  • Do NOT power off the computer: Disconnecting a machine from the network is almost always better than shutting it down. Powering down flushes RAM, destroying volatile evidence that incident response teams need to figure out how the breach happened.

  • Do NOT delete anything: Leave ransom notes, suspicious emails, log files, and system alerts exactly where they are.

  • Do NOT pay a ransom on impulse: Panicked, early payments rarely result in clean data recovery and mark your business as an easy target.

  • Do NOT use compromised channels to communicate: If an attacker has compromised your email tenant or VoIP system, they can read or listen to your internal communications. Switch immediately to out-of-band communication (personal mobile calls, trusted SMS, or alternate messaging apps).


The First Hour Action Plan


Work through these steps in exact order the moment a breach, ransomware pop-up, or suspicious account behavior is discovered.

[Isolate Devices] ──► [Call IT via Phone] ──► [Contact Bank (if financial)]
                                                      │
                                        ┌─────────────┴─────────────┐
                                        ▼                           ▼
                             [Preserve Evidence]         [Reset Credentials]

Step 1: Sever Network Connections (Isolate, Don't Power Down)


Immediately unplug the Ethernet cable and disable Wi-Fi on every affected machine. If a device is virtualized or remote, disconnect its network interface controller (NIC) via your hypervisor or management portal. Isolating the endpoint stops ransomware or lateral movement tools from spreading across local VLANs, reaching shared drives, or encrypting backup repositories.


Note: Only fully power down an endpoint if you are physically unable to disconnect it from the network by any other means.

Step 2: Call Your IT Partner and Cyber Insurer by Phone


Pick up the phone and call your Managed Service Provider (MSP) or internal security team. Do not send an email or submit a portal ticket from an affected machine. If you carry cyber insurance, call your insurer's emergency breach hotline immediately; many policies mandate early involvement of their approved panel of incident response specialists to maintain coverage.


Step 3: Preserve the Evidence


Leave the affected systems untouched. Do not attempt to run cleanups, run antivirus scans, or reinstall operating systems yet. Take clear smartphone photos of ransom demands, error codes, or altered desktop backgrounds, but keep the original files intact on the drive.


Step 4: Initiate Bank Recalls (For Wire/Financial Scams)


If the incident involves an unauthorized wire transfer, altered banking detail, or fraudulent payroll redirection, call your financial institution immediately. Request an emergency wire recall and ask to freeze the destination account. When wire fraud is reported within the first 24 to 72 hours, financial institutions have a significantly higher rate of freezing and recovering stolen funds.


Step 5: Execute Out-of-Band Password Resets


From a verified clean device (such as a personal smartphone not connected to the corporate Wi-Fi), force a global password reset and revoke active session tokens for all affected user accounts, prioritizing Microsoft 365/Google Workspace global admins and core infrastructure access. Ensure Multi-Factor Authentication (MFA) is re-verified for every identity.


Canadian Reporting & Regulatory Requirements


Once containment is underway, reporting the incident is vital for recovery and legal compliance. Where and when you report depends on your jurisdiction:

  • Canada: Report cybercrime and fraud directly to the Canadian Anti-Fraud Centre (CAFC) and the RCMP's National Cybercrime Coordination Centre (NC3).

  • United States: File a report with the FBI’s Internet Crime Complaint Center (IC3) and notify CISA.

  • United Kingdom: Report through the NCSC and Action Fraud.

  • Australia: Report via ReportCyber or call the 24/7 hotline at 1300 CYBER1.


Privacy & Data Breach Notification Laws


If client, employee, or financial data was accessed or exfiltrated, you may have statutory obligations to notify privacy regulators and affected individuals.


In Canada, under PIPEDA (and equivalent provincial legislation like Alberta's Personal Information Protection Act), organizations must report real risks of significant harm (RROSH) to the Office of the Privacy Commissioner (OPC) as soon as feasible. In the UK/EU, GDPR mandates reporting within 72 hours. Engage legal counsel early to determine your precise notification timeline.


Should You Pay a Ransom?


Ransomware demands present a difficult dilemma, but paying is strongly discouraged by law enforcement and top security researchers.


Paying a ransom does not guarantee you will get your data back, often results in corrupted decryption tools, and marks your company as a lucrative target for repeat attacks. Furthermore, decrypted systems must still be fully remediated from scratch, as attackers frequently leave secondary backdoors behind.


Before even considering a ransom discussion, your incident response team should verify:

  1. Whether immutable, off-site, or air-gapped backups can be used to restore operations.

  2. Whether a public, open-source decryption key already exists for that specific ransomware variant.


Preparation Beats Panic


The easiest way to navigate a crisis is deciding how to handle it before it occurs. A simple, one-page Incident Response Plan should be kept printed in physical binder form and stored securely off-network.


Your plan should clearly state:

  • Emergency phone numbers for your MSP, cyber insurance provider, legal counsel, and primary bank.

  • The location, retention schedules, and restoration testing logs for your immutable backups.

  • A clear hierarchy of critical business applications so IT knows which systems to restore first.


Want to make sure your business is prepared for a worst-case scenario? We help local teams design practical incident response plans, implement immutable backup policies, and lock down cloud boundaries before an incident occurs. Reach out to our team today to schedule an emergency readiness assessment.

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page