Practical cyber security guidance

The first hour of a cyber incident

The first hour should reduce damage without destroying evidence or creating confusion. A small business needs a named incident lead, a decision log and a way to communicate even if normal email cannot be trusted.

Frequently asked questions

6 practical answers.

### What should happen in the first 10 minutes?

Record what was observed, start the incident log, contact the incident lead and avoid deleting evidence. Determine whether an account, device, email system or wider environment may be affected.

### When should we contain accounts or devices?

Containment should begin quickly when compromise is credible, but it should follow an agreed process so important evidence and recovery access are not accidentally lost.

### Which accounts need protecting first?

Prioritise administrator accounts, email, identity, backup, domain/DNS, remote-access and other accounts that could let an attacker expand control or interfere with recovery.

### What if normal email may be compromised?

Move incident communications to a pre-agreed trusted channel. Avoid discussing containment steps through an account or platform the attacker may be monitoring.

### When do we need to consider the ICO?

If the incident involves a personal data breach, assess whether it meets the threshold for notification. A notifiable breach must be reported to the ICO without undue delay and no later than 72 hours after becoming aware of it.

### Should we rebuild systems immediately?

Not automatically. First understand the likely attack path and preserve necessary evidence. Recovery should use known-clean systems and should not reconnect compromised credentials or restore infected data.

Related guidance

Keep improving the control set.