What should be done in the first 24 hours after a cyber incident?

FAQ

Disconnect the affected systems, but do not switch them off (because of the evidence), convene the pre-assigned roles, secure backups off the network and start writing a timeline. Then deal with reporting and communication with partners. This cannot be improvised while everything is happening, which is why we prepare the procedure, contacts and roles in advance and rehearse them. During an incident we also disconnect AI tools until you know what had access to them.

More questions and answers