Contain deliberately
Block active abuse where necessary, but preserve logs, memory, accounts, systems and alerts before reimaging or deleting data.
Record actions
Maintain a response log showing who did what, when and why.
Preserve scope evidence
Collect identity-provider logs, email audit logs, firewall, endpoint, cloud and application records.
Assess notifications
Obtain legal advice regarding contractual, regulatory, insurer and affected-party notification obligations.
Learn from the incident
Use verified findings to remediate root causes rather than relying only on indicators of compromise.
Important: This is general guidance. Legal authority, privacy, employment law, privilege and evidential requirements should be considered for the specific matter.
