Blog

The First Hour After You Are Breached

Most guidance about security incidents concerns prevention, which is appropriate, because prevention is where the leverage is. This piece concerns the hour after prevention has failed, because that hour is where a serious incident becomes either a contained event or a much longer and more expensive one, and because the decisions in it are frequently made by whoever happens to be present rather than by anyone who has thought about them in advance.

The instincts most people have in that hour are reasonable, and several of them are actively harmful.

Do not power the machine off

The strongest instinct on discovering a compromised system is to shut it down, and it is the single most damaging action available.

A running system holds a substantial amount of information in memory that exists nowhere else, including active network connections, running processes, and in many cases credentials and encryption material. Powering off destroys all of it permanently. It can also, with certain ransomware families, cause the loss of material that would otherwise assist recovery.

The correct action is to isolate rather than to shut down, meaning disconnect the machine from the network while leaving it running. Remove the network cable, or disable the wireless adapter, or have your provider isolate it at the endpoint agent level, which is faster and can be done remotely. The attacker loses access, the machine stops being able to reach anything else, and the evidence remains intact.

Assume the environment is being watched

An attacker who has been present for days has usually read email. Discussing the incident over the compromised email system, or in a chat platform authenticated against the compromised directory, tells them precisely what you know and what you are about to do, and the observed consequence is that they accelerate.

Move incident communication to a channel outside the affected environment immediately. Personal mobile numbers and a phone call are entirely adequate and have the advantage of being available without configuration. Agree at the outset who is coordinating, because incidents deteriorate quickly when several people take independent action.

Preserve the logs before they roll over

Many logging systems retain data for a fixed period or a fixed volume, and the older entries are overwritten as new ones arrive. During an incident, when activity increases sharply, this can happen considerably faster than usual, and the entries most likely to be lost are the oldest ones, which describe the initial access and are the most valuable material you have.

Export and store the relevant logs early, covering the affected systems, the firewall, the mail platform and the identity system, and store the export somewhere outside the affected environment. This takes minutes at the start of an incident and is frequently impossible by the time somebody thinks of it.

Do not begin cleaning up

The instinct to restore normality quickly is understandable and it works against you in two ways.

Deleting the attacker’s tooling, removing the mail rules they created and resetting the accounts they used destroys the record of how the intrusion progressed, which makes it considerably harder to establish what was reached. That matters practically, because the scope of what was accessed determines who has to be told, and it matters commercially, because insurers and clients will ask.

It also frequently fails to remove the attacker. An intruder present for a week has usually established several ways back in, including accounts created for the purpose, additional credentials harvested, and persistence on machines nobody has looked at. Removing the visible access while leaving the rest results in the attacker returning within days, now aware that they have been noticed and working faster.

Establish whether recovery is actually available

This is the question that determines the shape of everything that follows, and it should be answered early rather than assumed.

Whether your backups are reachable and intact, which is not a given, since locating and destroying backups is a deliberate stage of a modern ransomware operation and typically occurs before encryption is triggered. Whether the copy you hold predates the initial compromise rather than merely predating the encryption, because restoring a backup taken during the intrusion restores the intrusion. And how long a restoration actually takes, which a business that has performed one knows and a business that has not is guessing at.

Make the notification decisions deliberately

Several parties may need to be informed and the timing is rarely optional. Your insurer will usually have notification requirements that affect cover and should be contacted early. Depending on your sector and what was accessed, regulatory and client notification obligations may apply and may carry defined timeframes. Legal advice is worth obtaining before external communication rather than after.

The observation worth making is that these decisions are far better made against a plan drafted calmly than improvised at eleven at night by people who have been awake for sixteen hours. If your business has no incident response plan, the useful moment to write one is now, and it does not need to be long.

The single thing worth doing this week

Establish who gets called first, and confirm they will answer.

Most businesses cannot name that person with certainty, and the ones who can frequently have not confirmed that the number works outside business hours. It is a five minute exercise and it determines how the first hour goes, which determines a great deal of what follows.

Siyaxhuma provides incident response alongside managed detection, which means the number is answered and the isolation is performed by people who already know your environment. Get in touch to discuss what that arrangement looks like.

Siyaxhuma Image

GET IN TOUCH

Solutions