What Would Your IT Team Do in the First 60 Minutes of a Cyberattack?

Imagine it is 9:17 on a Tuesday morning.

An employee calls the help desk because they suddenly cannot open several files. A few minutes later, another person reports the same problem. Someone notices an unusual login notification. Then an IT administrator sees something that confirms the concern: this may not be an isolated technical issue.

Something is happening.

What happens next?

Most organizations spend a great deal of time thinking about how to prevent a cyberattack. Firewalls, endpoint protection, email security, MFA, employee training and other safeguards are all important.

But there is another question that deserves just as much attention:

If those defenses are tested and an attack actually begins, does everyone know what to do?

The first hour of a cybersecurity incident can become confusing very quickly. Decisions need to be made, people need to communicate and IT teams need to determine what is happening without unintentionally making the situation worse.

Here is what those first 60 minutes could look like.

Minute 0–10: Is This Actually a Cybersecurity Incident?

Not every strange computer problem means an organization is under attack. But unusual activity should not be dismissed simply because the cause is unclear.

Early warning signs might include:

  • Multiple users suddenly losing access to files
  • Unexpected MFA requests
  • Unusual administrator activity
  • Security alerts from endpoint or network monitoring tools
  • Accounts behaving unexpectedly
  • Files being renamed, encrypted or deleted
  • Employees receiving suspicious emails from legitimate internal accounts
  • Systems suddenly becoming unavailable

At this stage, the goal is not to immediately understand every detail. It is to recognize that something abnormal may be occurring and begin following the organization's incident response process. That raises an important question:

Would your employees know who to contact if they suspected something was wrong?

If the answer depends on who happens to be in the office that day, there may already be a gap in the plan.

Minute 10–20: Contain What You Can

Once suspicious activity has been identified, preventing it from spreading becomes a priority. Depending on the incident, an IT or security team may need to isolate affected endpoints, disable compromised accounts, restrict certain network connections or take other containment measures. This is also where preparation matters.

In the middle of an incident is not the ideal time to determine who has the authority to disable an executive's account, disconnect a critical server or take a business system offline. Those decisions can affect operations, which means the response plan needs to account for more than technology.

Who has the authority to make those calls in your organization?

Minute 20–30: Figure Out What You're Dealing With

Now the questions start coming quickly.

  • Which systems are affected?

  • Which users are involved?

  • Where did the suspicious activity begin?

  • Are other locations affected?

  • Is data being accessed or removed?

  • Are backups potentially at risk?

  • Is the attacker still active?

Security logs, endpoint detection tools, network monitoring and other systems can help IT teams begin building a picture of what happened. But having security tools and being able to quickly use the information they provide are two different things. If alerts are spread across several platforms, nobody is actively monitoring them or only one employee understands how everything fits together, valuable time can be lost.

Minute 30–40: Start the Communication Chain

A cybersecurity incident quickly becomes more than an IT problem.

Depending on the situation, leadership, legal counsel, cybersecurity insurance providers, outside technology partners and other stakeholders may need to become involved.

  • Employees may also need instructions.

  • Should they disconnect from the network?

  • Should they stop using email?

  • Can they continue working?

  • What should they do if they receive suspicious messages?

One overlooked part of incident response is how the organization will communicate if its normal communication tools are unavailable or compromised. If email suddenly cannot be trusted, does your organization have another way to reach employees and decision-makers? That is a question worth answering before an emergency.

Minute 40–50: Protect the Rest of the Environment

By this point, the response team should be thinking beyond the first compromised device or account. A cyberattack may move between users, endpoints, servers and cloud services. Credentials may have been compromised before anyone noticed unusual activity. The team may need to investigate additional accounts, endpoints, network activity, remote access systems and administrative credentials. This is also where visibility becomes critical.

You cannot quickly investigate systems you did not know existed.Accurate documentation, asset inventories, network diagrams and clearly defined administrative access can make a significant difference when an IT team is trying to understand the scope of an incident.

Minute 50–60: Prepare for What Comes Next

At the end of the first hour, the incident probably isn't over. In many cases, the organization may still be determining exactly what happened. But ideally, several important things are now underway: the incident has been recognized, affected systems are being investigated or contained, the right people have been notified, evidence is being preserved, and the organization has begun making informed decisions about its next steps. Recovery may take hours, days or considerably longer depending on the incident. The goal of the first 60 minutes isn't to solve everything. It's to prevent confusion from becoming part of the emergency.

The Best Time to Answer These Questions Is Before an Attack

Cybersecurity preparedness is not just about buying another security product.

  • It is knowing who receives an alert at 3:00 a.m.

  • It is knowing who has permission to shut down a system.

  • It is knowing how to reach employees if email is unavailable.

  • It is knowing where your backups are and whether they can actually be restored.

  • It is knowing which vendors to call.

  • And it is making sure this information isn't stored only in the head of one IT employee.

One of the simplest exercises an organization can conduct during Cybersecurity Awareness Month is to put a hypothetical incident on the table and ask:

“It's happening right now. What do we do first?”

If the room goes quiet, you have identified something worth working on.

Cyber Smarter Starts With Being Prepared

At Total Communications, we help organizations look beyond individual cybersecurity products and consider how their technology, security, people and processes work together. From managed IT and cybersecurity services to endpoint protection, vulnerability management, employee security awareness, backup and disaster recovery, and strategic technology planning, our goal is to help organizations identify gaps before those gaps become emergencies. This Cybersecurity Awareness Month, don't just ask whether your organization has cybersecurity tools.

Ask whether your team knows what to do when those tools tell you something is wrong.

If you're unsure, Total Communications can help you take a closer look at your current cybersecurity environment and preparedness.