The first hours of a security incident create a hard tradeoff. The organization needs to contain damage, yet hurried containment can erase the evidence needed to understand entry, scope and persistence. Containment should proceed in coordination with evidence capture, so responders know what to record before a system is isolated, rebuilt or powered down.
Establish command and a shared clock
Name one incident lead and open a written decision log. Record who discovered the event, the first observed time, affected services, business impact and the people authorized to make containment decisions. Use an agreed time zone, preferably UTC for technical records, and note whether source systems have known clock differences.
Bring legal, security, IT operations, communications and the relevant business owner into the same operating picture. Their jobs differ, but they should work from one event timeline. A private response channel outside the potentially affected environment may be necessary.
Capture what disappears first
Volatile evidence can vanish when a host is shut down or a cloud session expires. Depending on the incident and authority available, priorities may include running processes, active network connections, logged-in users, memory, temporary files, authentication sessions and short-retention cloud logs. Collection should be performed by people who understand the operational risk and can document any change their tools make.
Do not assume the endpoint is the whole case. Identity-provider events, email audit records, VPN logs, DNS data, endpoint telemetry, cloud control-plane activity and security appliance records may tell different parts of the story. Confirm retention windows immediately. Exporting a critical log tomorrow may be too late.
Contain with an evidence note
Containment choices should state both the security objective and the evidentiary cost. Disabling an account may stop misuse but also end a live session. Blocking an address may reveal detection to an intruder. Reimaging may restore a workstation but destroy local artifacts. Sometimes the business and safety risk requires immediate action. The record should show who approved it and what was preserved first.
- Photograph or record the visible state when that context matters.
- Capture volatile data before shutdown when it is safe and proportionate.
- Preserve original security alerts and raw events, not only screenshots.
- Record isolation, credential reset, block and rebuild times.
- Keep forensic copies and investigative exports separate from restored systems.
Protect the timeline from well-meant cleanup
Routine administration can complicate later analysis. Log rotation, automated remediation, mailbox cleanup, account changes and application restarts may overwrite or detach useful records. Ask system owners to pause only the jobs that create a material evidence risk, and document every exception. Broad freezes can be harmful too, especially in safety-sensitive or revenue-critical systems.
Preserve communications about the incident as well as technical records. Tickets, chat messages and bridge notes can explain why actions occurred and identify facts that were known at each decision point. Keep speculation out of factual logs. Label hypotheses as hypotheses.
What the first handoff should contain
- A concise incident statement and named decision owner.
- A living timeline with source and time-zone notes.
- An inventory of affected and potentially affected systems.
- A list of preserved evidence, collection method and custodian.
- Containment actions, approvals and known evidentiary effects.
- Immediate log-retention gaps and collection priorities.
- Open questions, competing explanations and next decisions.
NIST’s 2025 revision of SP 800-61 Revision 3 places incident response across the Cybersecurity Framework functions instead of treating it as an isolated technical phase. That is a useful model for the first hours: governance, identification, protection, detection, response and recovery are happening together.
Use with judgment: This checklist cannot replace an incident plan or live judgment. Safety, legal duties and containment of ongoing harm can require action before ideal evidence collection is possible.