Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

First 15 minutes after a cybersecurity incident

Updated

In the first 15 minutes: declare an incident, name a commander, open a comms bridge the actor cannot see, start a contemporaneous log, and preserve volatile evidence. Do not power down or reimage yet.

This is a single-screen checklist. It is operational guidance, last verified 7 September 2026 against NIST SP 800-61r2, the SANS Incident Handler's Handbook, and CISA incident-response guidance. It is not legal advice and not a notification determination.

The 15-minute checklist

Audience: the incident commander (or the person who will be, in the next two minutes). Work top to bottom. Volatile evidence is first because it is gone the moment you power off, reimage, or let logs rotate. Containment here means isolate, not eradicate.

  • Declare an incident. You do not need legal certainty that this is a 'breach'. NIST SP 800-61r2 starts handling at detection and analysis.
  • Name one commander. Everyone else reports to that person for the next hour so actions are logged once.
  • Open an out-of-band comms bridge (phone, a clean conference, a channel the possibly compromised identity plane cannot see). CISA's ransomware guidance: isolate in a coordinated way and do not tip the actor.
  • Start a contemporaneous log in UTC: time, observer, system, what was seen, what was done. The SANS handbook treats notes as part of identification, not a later write-up.
  • List likely-affected systems and accounts. Do not log into them from a possibly compromised admin path to 'have a look' unless that is the only way to isolate.
  • Isolate from the network if spread is plausible: unplug, disable Wi-Fi, quarantine VLAN, or tighten a cloud security group. Leave the host powered on.
  • Preserve volatile evidence before any reboot: memory, live connections, running processes, log buffers. NIST SP 800-61r2: acquire, preserve, secure, and document evidence. If you do not have a memory-capture skill on hand, leave the box running and get someone who does.
  • Do not power down. Do not reimage. Do not delete logs, mail, or 'suspicious' files to tidy up. Eradication is a later timebox.
  • Page leadership and counsel (and whoever your plan names for insurer notice). You can still be wrong; you cannot un-lose the evidence.
  • Stop. The first hour is scoping, contain-versus-observe, and escalation — that work is the first-hour runbook, not this checklist. The breach hub explains how the later timeboxes fit together.

Do not power down or reimage yet

Two reflexes destroy the investigation. Powering off clears RAM: encryption keys, fileless malware, and live C2 sessions. CISA's ransomware guidance allows power-off only when you cannot disconnect the host from the network, and it states that the step prevents you from keeping ransomware artifacts stored in volatile memory. Reimaging is eradication; it overwrites the disk the DFIR team would image. The FTC Data Breach Response guide, which is regulator guidance for US businesses, says take affected equipment offline — and do not turn machines off until forensic experts arrive.

Isolate, then wait. If you cannot isolate and the infection is spreading, CISA's last-resort power-off is the exception, not the default, and you should record that you chose it because isolation was impossible.

What this checklist is not

It is not a notification decision. Customer, regulator, and insurer notice belong in later timeboxes and turn on facts and law you do not have at minute five. It is not a contain-versus-observe decision tree — that is first-hour work. It is not a ransomware-specific runbook; CISA's 'I've Been Hit By Ransomware' page is the primary source for that scenario and is linked below.

Legal requirement versus guidance versus practice: NIST SP 800-61r2 and the SANS handbook are industry practice. CISA's playbooks are regulator-authored operational procedures written for US federal civilian executive branch systems (CISA notes other organizations may use them to standardize practice). None of those documents files a notice for you. Statutes and regulations (US state breach-notification laws, sector rules, CRA Article 14 if it applies) are legal requirements only when they apply to your facts — confirm with counsel.

Where this shows up in ShipReady Metrics

The signed-in app does not run this 15-minute checklist. If you already have a session: Security findings is where open vulnerabilities, remediation, and KEV/EPSS ranking live; the cyber risk register is under Security; CRA Article 14 reporting is under Compliance readiness. Those pages require a login and do not preserve volatile evidence or isolate a host.

Frequently asked questions

What should we do in the first 15 minutes after a cyber incident?

Declare an incident, name one commander, open an out-of-band comms bridge, start a UTC log, isolate likely-affected systems from the network, and preserve volatile evidence. Do not power down, reimage, delete logs, or tip the actor. NIST SP 800-61r2, the SANS Incident Handler's Handbook, and CISA's incident-response guidance are the sources for that order.

Why not pull the power cord to stop the attack?

Pulling power clears volatile memory — often the only copy of fileless malware, encryption keys, and live connections. CISA says power-off is appropriate only when you cannot disconnect the host from the network, and that it costs you those artifacts. The FTC guide says take equipment offline but leave machines on until forensics arrive. Isolate first.

When do we reimage or restore from backup?

After volatile evidence is captured and a forensic image exists, during eradication and recovery — not in the first 15 minutes. NIST SP 800-61r2 and the SANS PICERL model put eradication after identification and containment. Reimaging now is how you arrive at the insurer and the investigators with nothing to show.

Is this legal advice?

No. It is a first-response checklist distilled from NIST SP 800-61r2, the SANS Incident Handler's Handbook, and CISA guidance. Notification duties, privilege, and whether the event is a notifiable breach are legal questions for counsel on your facts. This page does not start a reporting clock.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.