A hack suspicion requires quick, controlled decision-making. Limit the spread, protect evidence and organise one coordination point. Do not pull the plug directly from anywhere: Uncontrolled shutdown can clear volatile tracks, make recovery difficult and lose sight of the attack.
For the first 30 minutes: alarm, isolate and capture
- Activate the incident team. Name an incident leader, a technical contact and one responsible for decisions and communication.
- Isolate aim. Get a hit device or segment from the network as needed, but leave systems on until a specialist determines what research is needed.
- Save evidence. Record time points, notifications and actions executed. Secure logs, snapshots, cloud audit data and other volatile information against overwriting.
- Protect backups and management accounts. Check if attackers have access to it and prevent recovery points from being encrypted or deleted.
For alignment, use a channel that is not dependent on potentially affected email or collaboration tools. Share only confirmed facts and avoid several teams simultaneously making uncoordinated changes.
The first hours: assess size, business impact and reporting obligations
Focus facts and critical processes
- which accounts, devices, cloud environments, locations and suppliers may have been affected;
- which data may have been accessed, modified or taken;
- which services are now being stopped and which safe relapse procedure is available;
- which accesses, sessions or keys must be checked;
- which decisions should be taken directly by the board, management and procedural owners.
Involve external parties with clear mandate
Inform your IT provider, cyberinsurer, legal advisor and forensic specialist according to the incident plan. Decide who is conducting research, who is allowed to perform changes and who coordinates contacts with police, regulators, customers and chain partners. Check the terms of cyber insurance before costly external orders are provided.
Review notifications and communication
Investigation in good time whether there is a data breach, a criminal offence, a sector-specific reporting obligation or an obligation under the Dutch Cybersecurity Act. Record the assessment and decision-making, even if you decide not to report it yet. Communicate in fact: what is known, what is investigated, what do you expect from the recipient and when will an update follow?
The first 24 hours: mastering, restoring safely and continuing to learn
- Create a validated recovery plan. Determine the order based on critical processes, dependencies and safe recovery points.
- Close known entrances. Retract suspicious sessions, reset relevant accounts, restore configurations and run necessary patches without prematurely destroying traces.
- Restore clean and checked. Use tested backups or clean installations and monitor intensively on return of attacker.
- Keep a decision and action log. Write down owner, time, justification and result of each relevant step.
- Plan follow-up communication. Tune messages to employees, customers, suppliers and other stakeholders.
What you shouldn't do in a cyber incident
- disable, reinstall or delete logs without coordination systems;
- approach attackers or pay ransom without any specialised legal and operational consideration;
- share wide sensitive incident details via potentially compromised channels;
- declare too early that the incident has been resolved while size and cause have not yet been established;
- to engage suppliers, cyberinsurer or relevant hotlines only afterwards.
After stabilisation: Improving it is evident
Run an incident review once the situation is stable. Research the technical cause and the way in which detection, decision-making, communication, supplier agreements, continuity and recovery have been carried out. Then, by improvement measure, identify who is responsible, when the measure is to be ready and how you control its operation.
An incident response plan, tabletop exercise, Cyber Security Audit or Information security risk analysis helps to ensure the lessons are structurally guaranteed. If you need support now, check it out Hacked: What now?.
Please note: This article provides practical information and is not legal or forensic advice. Reporting obligations and appropriate actions depend on your sector, organisation and the facts of the incident.


