Contained suspicious activity with little or no operational impact. Record, verify and monitor.
Cyber incident response
A calm, practical framework for decisions under pressure.
Cyber incidents affect more than devices. They can disrupt operations, expose sensitive information and undermine trust. This guide explains how a structured response moves from detection and containment through to safe recovery and improvement.
Public response guide
Prepare the people, decisions and communication before an incident.
A useful response plan establishes who can make decisions, how support is contacted, what evidence should be retained and which services matter most. This educational guide does not disclose any client environment and is not a substitute for a tailored incident plan, legal advice, privacy or breach-notification advice, insurer direction or emergency services.
- 01
Detect & triage
Confirm what changed, when it began, which users or systems are affected and whether harmful activity may still be continuing.
- 02
Contain
Limit access and spread while preserving the information needed for investigation and any professional advice.
- 03
Investigate & eradicate
Build a reliable timeline, determine the likely cause and remove malicious access, persistence or unsafe configurations.
- 04
Recover
Restore clean systems and priority services in stages, based on business need and an understood recovery path.
- 05
Validate & communicate
Confirm essential workflows are safe and usable, then provide clear updates to the people who need them.
- 06
Review & improve
Record decisions and outcomes, close control gaps and test the improvements made after the incident.
First actions
Protect people. Slow the spread. Preserve the facts.
- Use the agreed support and management escalation path immediately.
- Record the time, affected users, devices, accounts and visible symptoms.
- Do not delete suspicious messages, logs or systems before receiving guidance.
- Avoid sharing passwords, patient information or detailed attack data through a general web form.
- If safe to do so, stop using an affected device and wait for containment instructions.
Severity and escalation
Classify the business impact—not just the technical alert.
Severity should reflect scope, urgency, data sensitivity, operational disruption and whether the activity is still happening. It can change as new evidence appears.
A limited account, device or service impact that requires prompt containment and investigation.
Business-critical disruption, wider compromise or possible exposure of sensitive information. Escalate immediately.
Severe or continuing impact across important services, safety, sensitive data or multiple locations. Activate executive and specialist response.
Evidence, communication and ownership
A response works when technical action and business decisions stay connected.
Good incident handling keeps a decision record, limits unnecessary disclosure and gives each participant a clear responsibility.
Communication
Provide factual, severity-appropriate updates. Avoid speculation and share sensitive details only with authorised people.
Evidence
Preserve relevant alerts, logs, timestamps, messages and decisions so the investigation has a dependable timeline.
Roles
Define the IT lead, business decision maker and the point at which vendors, insurer, legal, forensic or regulatory specialists may be engaged.
Decision record
Record containment, recovery and communication decisions, who authorised them and what changed as new facts emerged.
Safe recovery
Restore only after the threat is understood and contained, using clean systems or recovery points and a staged return to service.
Business validation
Confirm identity, applications, email, files, printing, integrations and priority workflows with the people who use them.
After the incident
Turn the response into a measurable improvement plan.
The review should explain what happened, the likely root cause, the recovery outcome and the practical changes that reduce recurrence or impact.
Prioritise identity, remote access, endpoint, email, network or backup changes according to the evidence—not a generic shopping list.
Update support contacts, escalation paths, staff guidance and security awareness where the incident exposed uncertainty.
Confirm protected copies, clean recovery options and the tests needed to prove critical workflows can return.
Assign an owner and review date to each action so recommendations become completed improvements.
Need help now?
Start with a confidential incident discussion.
If there is an immediate safety emergency, contact emergency services. For IT and cyber support, contact Podium IT and share only the information needed to begin triage.
