Upgrade your security strategy for the AI era.

After a Cyber Incident: What to Expect
When a cyber incident occurs, the first decisions an organization makes can affect everything that follows, from the forensic investigation to business recovery. Acting quickly matters, but so does preserving evidence, involving the right people, and understanding their roles in the response.
In this Q&A, Abbey Mirelli, an incident response manager at Pondurance, explains what organizations should expect during the first days and weeks following an incident and what they can do now to prepare for an effective response.
Q: What should an organization do immediately after discovering a cyber incident?
Abbey: The priority is to contain the incident without destroying evidence. If you can isolate an affected system, that might mean disconnecting it from the network. If multiple systems are affected, you may need to isolate a network segment. Before doing that, however, consider the potential impact on business operations.
Containment doesn’t mean immediately cleaning up the affected systems. Avoid deleting files, running cleanup tools, or reinstalling operating systems. Those actions can destroy evidence that a forensic team may need to determine what happened and whether data was accessed or affected.
Document what you observe and look for indications of a broader compromise. Check your endpoint detection and response (EDR) platform for alerts or unusual activity, or to help quickly isolate endpoints that were affected.
From there, escalate the incident according to your incident response plan. If you have cyber insurance, that generally includes notifying your carrier according to your policy’s requirements. Legal counsel is also recommended to become involved. Depending on your coverage, your insurer may help engage an approved forensic vendor or breach counsel.
A useful rule for the initial response is: isolate, preserve, document, and escalate.
Q: What happens once the response team is assembled?
Abbey: There is typically an initial scoping call involving the organization and outside parties engaged in the response. The purpose is to establish what happened, what has been discovered, and what actions have already been taken. It also allows everyone to establish their responsibilities.
Legal counsel can advise on communications and determine whether the incident creates legal, regulatory, contractual, or notification obligations. Once engaged, the forensic team begins collecting and analyzing evidence. The insurer handles questions about coverage, expenses, and approved vendors. Forensics and legal will not be able to answer questions about what your insurance policy covers.
Leadership should also be involved because the organization may need to make important decisions about recovery and business continuity while the investigation is ongoing. Sometimes, those hard decisions may have to be made with incomplete information as the forensic team continues its work.
Regular status calls help keep everyone coordinated as the response progresses. Depending on the incident, those calls may happen once or twice a day. The forensic team can provide preliminary findings, while legal counsel evaluates the potential implications of those findings.
Q: What should organizations expect during the first week?
Abbey: During the first week, the investigation and recovery are typically happening at the same time.
The forensic team will work to develop a timeline of the incident, identify which systems were affected, and investigate whether data may have been exfiltrated. Legal counsel can then use those findings to evaluate potential reporting and notification requirements.
This is also where understanding your data becomes important. Organizations need to know what types of data they have and where that information resides. Is sensitive information stored in email, on servers, or on employee workstations? Those details can become important when it comes to evaluating the potential impact of an incident.
Sometimes, the organization may need to begin restoring systems before the forensic investigation is finished. In some instances, you can’t necessarily wait until you have all the forensic answers before starting recovery. The two workstreams often need to proceed simultaneously, with recovery decisions being made as new forensic information becomes available.
Q: What happens in the weeks following an incident?
Abbey: Some forensic questions can take longer to answer, particularly when investigators are trying to determine exactly what data may have been accessed. That means the forensic investigation and work with legal counsel may continue even after the immediate operational response has passed.
While all of this work continues, the organization should document lessons learned, including whether responsibilities were clear, if decisions could have been made more efficiently, and if investigators had access to the logs and other information they needed. This is also the time to identify longer-term security improvements. For example, the organization might determine that it needs longer log retention or improvements to a particular technology or security control.
The goal isn’t simply to respond faster next time, as quicker isn’t always better. The goal is to make sound decisions and identify changes that can better prepare the organization for the next incident.
Q: What should organizations put in place before an incident occurs?
Abbey: Organizations often underestimate how long recovery can take. A good place to start is with recovery planning. This includes the maintenance and testing of offline and immutable backups, and understanding what recovery would look like if critical systems were unavailable for several days. Know your recovery time objective (RTO) and recovery point objective (RPO) for critical systems.
Make sure important logs are centralized, retained long enough to reconstruct an incident, and accessible to those who need them. Running a full incident response exercise is helpful for an organization so people understand their responsibilities rather than assuming the IT team or other employees will know what to do when an incident occurs. This includes having a clear call tree with primary contacts and backups.
Talk with your cyber insurer before an incident occurs so you understand when and how the insurer must be notified, which forensic firms and breach counsel are approved under your policy, and which actions or expenses require prior authorization. Be sure to keep your policy number and other critical insurance information somewhere you can access even if your normal systems are unavailable.
Finally, make sure your security incident response plan reflects how your organization will actually respond. The first hours of an incident are not the time to figure out who should be called, where evidence is stored, or who has authority to make critical business decisions.
An effective incident response depends on more than the actions taken after an attack. Organizations that know who to call, what systems and data they need to protect, how they will recover, and what information investigators will need are better positioned to make informed decisions when an incident occurs.
Join us on September 22 at 12 PM ET for The Business of Breach Readiness, a practical conversation about what effective preparation looks like across incident response, cyber insurance, and legal.


.png)


