A breach is usually found through a small sign: an antivirus alert, a user whose files won't open, strange traffic at three in the morning. What you do in the hour after that decides whether the incident is over in a day or drags on for months.

This checklist doesn't replace a full incident response plan. But if you don't have one, it keeps you away from the worst mistakes.

What not to do

  • Don't switch the server off. Its memory holds evidence that disappears at power-off: running processes, open connections, sometimes the ransomware's encryption key. Disconnect it from the network instead.
  • Don't delete or reinstall anything. Reinstalling the operating system wipes the attacker's way in along with everything else, and until you know that route, they come back through it.
  • Don't announce it over company email or chat. If the attacker has the mailbox, they read your coordination too. Use the phone or a separate channel.
  • Don't change passwords on an infected machine. A new password typed on it leaks the moment it's typed. Use a clean device.
  • Don't contact the attacker or pay anything, at least until the scope of the incident and the state of your backups are clear.

The first hour, step by step

  1. Isolate, don't power off. Unplug suspect machines from the network or shut their switch ports. If ransomware is spreading, cut the links between network segments.
  2. Start writing things down now. Every action, with the exact time and who did it. You'll need this later for analysis, insurance and any formal report.
  3. Preserve the logs. Copy firewall, server and authentication logs before rotation deletes them.
  4. Put one person in charge. One coordinator decides and everyone reports to them. Ten people working at once without coordination destroy evidence.
  5. Check the state of the backups, without connecting the backup system to the infected network.
  6. Estimate the scope. Which machines and accounts are involved? Treat every account used on an infected machine as compromised.
  7. Tell the people who need to know. Management, and if needed a specialist incident response team. In Iran, security incidents can also be reported to the Maher Center, the national computer emergency response team.

If it's ransomware

  • Keep the ransom note and a sample of the encrypted files. Free decryptors have been published for some ransomware families, and identifying exactly which one you have is the first step.
  • Don't delete the encrypted files; if a key ever turns up, those are the files it will unlock.
  • Before restoring from backup, make sure the attacker's way in is closed; otherwise the restored copy gets encrypted again.

Before the day of the incident

The best time to prepare is today: an emergency contact list on paper, a communication channel separate from company email, backups ransomware can't reach, and centralised logs an attacker can't erase. An organisation with those four starts its first hour with a plan, not a guess.