Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

First hour after a breach

Updated

In the first hour after a breach: finish isolate-and-preserve, then scope affected systems and accounts, decide contain-versus-observe, engage leadership, counsel, and the insurer, and begin a UTC timeline. Do not eradicate or reimage yet.

This is operational incident-response guidance, last verified 7 September 2026 against NIST SP 800-61r2, CISA incident-response guidance, the SANS Incident Handler's Handbook, and the FTC Data Breach Response guide. It is not legal advice, not a notification determination, and not a substitute for counsel, your insurer, or a retained DFIR firm.

What the first hour is for

Audience: the incident commander named in the first 15 minutes. The first 15 minutes were stop-the-bleeding and keep-the-evidence. The first hour is scoping, a contain-versus-observe decision, escalation, and a timeline you can defend later. Eradication, customer notice, and regulator filings are not this timebox.

NIST SP 800-61r2 groups containment, eradication, and recovery as one phase but sequences them: contain before you clean. The SANS PICERL model puts identification and containment before eradication. If the 15-minute checklist is unfinished — no commander, no out-of-band bridge, no isolation, no log — finish that first. This page assumes those moves have started.

  • Finish network isolation of likely-affected hosts. Leave them powered on. Do not reimage, restore, or 'just rebuild'.
  • Scope: which systems, accounts, identities, and data stores are in play, and which are only suspected.
  • Decide contain-versus-observe in writing, with a named owner and a flip-to-contain trigger.
  • Page leadership, counsel, and whoever your plan names for insurer notice. You can still be wrong; you cannot un-lose the hour.
  • Turn the contemporaneous log into a UTC timeline: detections, actions, decisions, and who made them.

Scope affected systems and accounts

Scope is a working list, not a verdict. NIST SP 800-61r2's detection-and-analysis phase is identifying the incident, its type, and its extent — then documenting what you know and what you do not. The SANS handbook treats notes as part of identification, not a write-up you do later. Do not log into possibly compromised admin paths 'to have a look' unless that is the only way to isolate.

  • Hosts: what was first seen, what it talks to, what shares its identity or image. Cloud: the account, project, subscription, and security groups — not only the instance.
  • Identities: human users, service accounts, API keys, SSO apps, CI tokens. A compromised identity is a system for scoping purposes.
  • Data stores in reach of those identities: file shares, mailboxes, databases, object buckets, backups, secrets managers. Reachable is not the same as stolen.
  • What you have not checked. Write that down. Unknown scope is a fact; pretending completeness is how later clocks get argued.
  • Do not expand scope by wiping, rotating every secret from the possibly compromised identity plane, or posting on a public status page. Those are later, coordinated moves. CISA warns that actors watch response activity.

Contain versus observe

NIST SP 800-61r2 says most incidents require containment, and that choosing a strategy weighs potential damage, evidence preservation, service availability, and whether the strategy will actually stop spread. It also records that some organizations delay containment to monitor an attacker and collect more evidence — and that this is a high-risk strategy. CISA's ransomware guidance does not treat watch-and-learn as the default: isolate in a coordinated way, and do not tip the actor.

Make the call in the first hour. Write who decided, why, and the condition that ends observation. Observation without a time box is how encryption finishes while you watch.

Contain-versus-observe (industry practice from NIST SP 800-61r2, SANS, and CISA — not a legal test)
DefaultWhenWhat you still must do
Contain now (isolate)Active encryption, data destruction, worm-like spread, or credentials still being used to move. Most ransomware. Anything you cannot watch without feeding the actor more access.Isolate from the network (cable, Wi-Fi, VLAN, cloud security group). Leave power on. Record the action in UTC. CISA: coordinated isolation; power-off only when you cannot disconnect, and know that step loses volatile evidence.
Observe brieflyYou need a short window to find persistence, C2, or the rest of the foothold, and immediate isolation would destroy that chance. Typically a quiet intrusion, not a smash-and-encrypt. Named commander owns the clock.Time-box it (minutes, not the rest of the day). Write the flip-to-contain trigger (new encryption, new identity use, data leaving). Keep the out-of-band bridge. Do not probe from a compromised admin path.
Do not 'observe'You have no watcher, no packet or EDR visibility, and no one who will flip to contain. Watching without instrumentation is hoping.Contain. Then get eyes. SANS short-term containment (isolate the segment or host) exists so the business can survive the hour; long-term containment is a later, more durable fix.

Engage leadership, counsel, and the insurer

The first 15 minutes named a commander. The first hour is when the rest of the people your plan names hear that an incident is on. Do not wait for a complete picture; completeness is a later timebox. NIST SP 800-61r2 expects the team to notify appropriate internal parties as the incident is handled. The FTC Data Breach Response guide, which is US regulator guidance for businesses rather than a statute, tells firms to assemble a team that can include legal, forensics, and communications — and to notify law enforcement when the facts warrant it.

Who to loop in during hour one (operational; confirm against your plan and policy)
WhoWhen in the first hourWhy, and the limit
Leadership (founder, CEO, or whoever your plan names)As soon as the incident is declared, not after scoping is finished.Decisions about service impact, public statements, and spend need a single executive owner. Split command is how evidence and containment drift.
Counsel (inside or outside breach counsel)When facts suggest legal exposure, privilege, or a notification question — often immediately.Whether the event is a notifiable breach is a legal determination. This page does not make it. Counsel also tells you how to keep the working papers so they are usable. A dedicated 'when to call breach counsel' guide is not on this site yet.
Cyber insurerWhen your policy's notice condition says to. Many policies require prompt notice of an incident, sometimes before you retain a firm from their panel.Read the notice clause on YOUR policy. Late notice is a coverage argument you do not want. This page does not interpret your contract. A dedicated 'when to contact cyber insurance' guide is not on this site yet.
DFIR / forensicsIf you do not have in-house memory and disk capture and evidence is at risk.Page the retained firm or the insurer's panel. Do not wait for a perfect scope. They cannot image a host you already rebuilt.

Begin the timeline

The 15-minute checklist started a contemporaneous log. The first hour turns that log into a timeline other people can use: counsel, the insurer, DFIR, and you in a week when memory has flattened the order of events. SANS treats contemporaneous notes as part of identification. NIST SP 800-61r2's evidence-handling guidance is acquire, preserve, secure, and document — documentation is not optional cleanup.

  • UTC only. Local time plus 'I think' is how two logs disagree.
  • Each line: time, observer, system or account, what was seen, what was done, who authorised it.
  • Record the contain-versus-observe decision as an event: who, when, why, and the flip trigger.
  • Record who was paged and when they joined the out-of-band bridge. Gaps in notification are facts.
  • Do not tidy the log. Corrections are new lines, not edits. A reconstructed 'clean' timeline written tomorrow is a different artifact from the notes you took while it happened.

Where this shows up in ShipReady Metrics

The signed-in app does not run this first-hour runbook, isolate a host, or file a notice. If you already have a session: the cyber risk register lives under Security; the obligation map (which frameworks you have marked in-scope) is under Compliance; CRA Article 14 reporting is under Compliance → CRA reporting. Those pages require a login. They do not start a reporting clock, and they are not a determination that any law applies.

Primary sources (last verified 7 September 2026)

Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

NIST SP 800-61 Revision 2 remains the current final Computer Security Incident Handling Guide (August 2012). Treat it as guidance, not a statute. CISA's playbooks are operational procedures written for US federal civilian executive branch information systems; CISA notes other organizations may use them to standardize practice. The SANS Incident Handler's Handbook is a practitioner checklist, not a regulator document. The FTC guide is business guidance from a US regulator; the legal notification duties are in the statutes it points at, not in the guide itself.

Frequently asked questions

What should we do in the first hour after a breach?

Finish isolation and evidence preservation from the first 15 minutes, then scope affected systems and accounts, decide contain-versus-observe in writing, page leadership, counsel, and the insurer if your plan or policy requires it, and turn the contemporaneous log into a UTC timeline. Do not reimage, eradicate, or notify customers yet. NIST SP 800-61r2, CISA, and the SANS handbook are the sources for that order.

Should we contain immediately or watch the attacker?

Default to contain (isolate, leave power on) when encryption, destruction, spread, or live credential use is happening. CISA's ransomware guidance is isolate, and do not tip the actor. NIST SP 800-61r2 allows delayed containment to collect evidence only as a high-risk choice. If you observe, name an owner, time-box it, and write the flip-to-contain trigger. Observation without instrumentation is hoping.

When do we call counsel and the cyber insurer?

In the first hour, not after you 'know everything'. Counsel owns privilege and whether the event is a notifiable breach. The insurer is whoever your policy's notice condition names — many policies want prompt notice, sometimes before you pick a DFIR firm. Read YOUR policy; this page does not interpret it. A dedicated insurance or breach-counsel guide is not on this site yet.

Is this legal advice?

No. It is a first-hour runbook distilled from NIST SP 800-61r2, CISA incident-response guidance, the SANS Incident Handler's Handbook, and the FTC Data Breach Response guide. Notification duties, privilege, coverage, and whether the event is a notifiable breach are legal questions for counsel on your facts. This page does not start a reporting clock.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.