The instinct when you discover a breach is to fix it immediately — which is understandable, and often exactly the wrong first move. Acting in the wrong order can destroy evidence, tip off an attacker still inside the network, or leave a backdoor in place while you clean up the symptom you happened to notice first.
Hour 0–1: Contain, don’t panic-fix
Isolate affected systems from the network rather than shutting them down outright where possible — powering off can destroy volatile evidence that helps determine scope. Preserve logs immediately, since many systems rotate or overwrite them on a schedule that won’t wait for you.
Hour 1–6: Scope the incident
Before fixing anything, establish what was actually accessed, when access began, and whether the attacker still has a foothold. This is where the earlier "just delete the malicious file" instinct causes the most damage — acting before scoping means missing the backdoor or rogue account that lets the attacker straight back in.
Hour 6–12: Notify who needs to know
Depending on what was affected, this may include your cyber insurance provider, legal counsel, and — for personal data breaches — regulatory notification obligations under PIPEDA, provincial privacy law, or applicable US state law. Getting this timeline right matters for compliance, not just optics.
Hour 12–24: Eradicate and begin recovery
Only once scope is understood should eradication begin — removing every backdoor and unauthorized account identified during scoping, not just the one that was found first. Recovery starts from verified-clean backups, never from a system that hasn’t been confirmed clean.
The pattern that matters most
Contain, then scope, then eradicate, then recover — in that order. Every step skipped or done out of sequence is usually why an "incident" becomes a "second incident" two weeks later. If you’re in the middle of one right now, our incident response team is reachable 24/7.