The First Hour of a Cyber Incident: A Practical Checklist
Early decisions shape the rest of an investigation. Use this checklist to reduce confusion when every minute counts.
Harp Intelligence
01
Stabilize before you improvise
The first hour should focus on confirming what happened, limiting additional damage, preserving evidence, and establishing clear ownership.
02
Immediate actions
Follow the response plan and document decisions as they happen.
- Open an incident record and assign a coordinator
- Validate the alert using trusted telemetry
- Contain affected accounts or systems when appropriate
- Preserve logs and volatile evidence
- Notify legal, leadership, and external partners based on severity
03
Communicate with discipline
Use a defined channel, record facts separately from assumptions, and set a predictable update cadence. Clear communication protects the investigation from avoidable confusion.