Contain deliberately

Block active abuse where necessary, but preserve logs, memory, accounts, systems and alerts before reimaging or deleting data.

Record actions

Maintain a response log showing who did what, when and why.

Preserve scope evidence

Collect identity-provider logs, email audit logs, firewall, endpoint, cloud and application records.

Assess notifications

Obtain legal advice regarding contractual, regulatory, insurer and affected-party notification obligations.

Learn from the incident

Use verified findings to remediate root causes rather than relying only on indicators of compromise.

Important: This is general guidance. Legal authority, privacy, employment law, privilege and evidential requirements should be considered for the specific matter.