01
0–15 minutes: contain impact
Isolate affected devices and network segments according to incident scope.
- Disconnect network connectivity from affected systems
- Protect unaffected backups and administrative access
- Assign one incident coordinator
02
15–30 minutes: establish scope
Avoid destroying evidence through rushed changes.
- List affected accounts, endpoints, servers and services
- Preserve relevant logs and available evidence
- Record a timeline and actions taken
03
30–60 minutes: activate recovery
Recovery starts from a trusted baseline.
- Engage management and required legal, insurance or external contacts
- Verify backup availability and separation
- Plan prioritised recovery of clean systems and monitoring during return to service