By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 21, 2026
Quick Answer
The first 24 hours of a cyber incident are the most consequential. The decisions and actions taken in this window determine how wide the breach scope becomes, how much data is exfiltrated or encrypted, how quickly the attacker is evicted, and how much the total incident costs. Most organizations have never walked through what actually happens hour by hour during an active breach, and the gap between expectation and reality is significant. The incident does not pause while the organization figures out who to call. The attacker, if still active in the environment, continues their work. The clock on regulatory notification begins running at detection. The window for reversing fraudulent financial transactions narrows with every hour. A structured response, backed by a pre-established retainer with onboarded context, compresses the time between detection and effective containment in ways that meaningfully reduce the total impact of the incident.
Key Takeaways
- Detection and escalation take longer than most organizations expect. Most cyber incidents are not detected by a real-time alert that clearly identifies a breach in progress. They are detected by an employee who notices something wrong, a managed service provider who flags an anomaly, a monitoring system that produces an alert requiring human interpretation, or a third party who notifies the organization that its data is being traded or its email domain is being spoofed. The time between the initial detection signal and confirmation that an incident has actually occurred can range from minutes to hours.
- The first instinct, to fix the problem immediately, can destroy evidence. The most common error in the first minutes of an incident is taking actions that make sense operationally, such as reimaging a compromised system, restoring from backup, or resetting a compromised account, before forensic evidence has been preserved. These actions may eliminate the indicators of compromise that the investigation requires to determine how the attacker entered, what they accessed, and whether the threat has been fully eradicated. The first step is to preserve, not to fix, and that prioritization runs counter to the instinct of every IT professional facing a problem they want to solve.
- Legal counsel should be engaged in the first hours, not the first days. The attorney-client privilege that protects the incident investigation from discovery in subsequent legal proceedings attaches to work conducted at the direction of counsel, not work conducted and then handed to counsel after the fact. Engaging breach counsel early ensures the forensic investigation and response documentation are produced under privilege from the outset rather than having privilege applied retroactively to work that does not qualify for it.
- The regulatory notification clock starts at discovery. Data breach notification laws in most jurisdictions require notification within a defined period from the point of discovery that personal information was accessed or acquired without authorization. The discovery point is not when forensic investigation confirms the full scope; it is when the organization knew or reasonably should have known that a covered event may have occurred. Understanding the notification timelines that apply based on data types, jurisdictions, and regulatory obligations, and tracking from the correct discovery point, is a legal function that breach counsel manages from the first hours.
- The attacker may still be present when the response team engages. Many organizations assume that detecting a ransomware deployment or a data exfiltration event means the attacker has finished and left. In many cases, particularly ransomware, the attacker is still active at the point of detection, monitoring the organization’s response, maintaining persistence through secondary access pathways, and prepared to re-engage if the primary compromise is evicted without closing all access points. The investigation must determine not only how the attacker entered but whether they are still present and through what mechanisms.
Hour by Hour: What the First 24 Hours Look Like
Hours 0 to 2: Detection and initial escalation
The incident begins with a detection signal. It may be a ransomware note on a screen, an alert from the endpoint protection platform, a call from a customer reporting suspicious communication from the organization’s email domain, a managed service provider flagging unusual outbound traffic, or an employee who cannot access their files. The initial signal is often ambiguous: it could be a genuine breach, a false positive, a hardware failure, or a software error. The first response is to triage the signal to determine whether an incident is actually occurring.
Internal IT or the managed service provider conducts the initial triage. This takes 30 minutes to two hours depending on the clarity of the signal and the complexity of the investigation needed to confirm it. Once confirmed as a genuine incident, escalation occurs: the IT or security team notifies the CISO or equivalent, who notifies executive leadership and the General Counsel. The question of what to do next arrives at the leadership level. If a retainer is in place, the answer is to make the activation call. If no retainer is in place, the next step is to search for an IR firm with immediate availability while the incident continues.
Hours 2 to 6: Response activation and initial containment
For organizations with a retainer in place, the activation call in the second hour reaches a team that already knows the environment. The call is a situation briefing, not an orientation session. The response lead confirms the incident type, reviews the asset inventory from the onboarding, identifies the most likely affected systems, and begins directing initial containment actions alongside the internal team. Initial containment actions in a ransomware scenario include isolating affected network segments to prevent lateral spread, taking affected systems offline to halt encryption, preserving forensic images of affected systems before any remediation, and identifying and blocking the command-and-control communication channels the malware is using.
For organizations without a retainer, hours two through six are split between the search for an available IR firm and the initial orientation work once a firm is engaged. The search itself takes one to two hours of calls and callbacks. The orientation takes another two to three hours as the newly engaged team asks the questions that the retainer’s onboarding workshop answered months ago. Initial containment actions begin in hour five or six rather than hour two. In a ransomware incident where the payload encrypts at a rate of dozens of systems per hour, that three to four hour difference in containment timing has a direct and measurable impact on the number of systems affected.
Breach counsel is engaged during this phase. The General Counsel either calls the organization’s existing breach counsel relationship or contacts the cyber insurance carrier to activate the breach coach coverage. Privilege is established over the investigation from this point forward. The regulatory notification assessment begins: which jurisdictions are implicated, what data types were potentially accessed, what are the notification deadlines, and what evidence is needed before notification obligations can be confirmed.
Hours 6 to 18: Investigation and extended containment
With initial containment actions in place, the investigation phase begins in earnest. The forensic team analyzes affected systems, logs, and network traffic to understand the attack vector: how did the attacker initially gain access, what lateral movement occurred, what data was accessed or exfiltrated, and what is the current state of the attacker’s presence in the environment? This investigation is the most technically demanding phase of the response and the one where the experience and tooling of the response team matters most.
The investigation findings feed directly into the extended containment and eradication planning. If the attacker gained initial access through a phishing email that delivered a malicious attachment, the investigation determines whether the phishing campaign was targeted at this organization specifically or part of a broader campaign, whether other employees received and clicked similar messages, and whether the malicious payload has been fully identified and removed or whether secondary payloads or persistence mechanisms remain. Extended containment addresses the access points that remain open after initial containment closes the most visible avenues.
Communications run in parallel. Internal stakeholder updates, calibrated to the audience and the sensitivity of the information, keep leadership, department heads, and relevant staff informed about the response status without speculating about scope or impact before the investigation has produced reliable findings. External communications, whether to customers, partners, regulators, or the public, are held until breach counsel has advised on the appropriate timing, content, and channel for each audience based on the regulatory obligations and litigation risk landscape.
Hours 18 to 24: Stabilization and transition
By hour 18 to 24 of an effectively managed response, the attacker should be evicted from the environment, all known access points closed, and affected systems either isolated for remediation or in the early stages of recovery. The investigation findings to this point support a preliminary understanding of the scope: which systems were affected, what data types were on those systems, what the likely regulatory notification obligations are, and what the business impact is. This understanding is preliminary, not final; the forensic investigation continues after the initial 24 hours, often for days or weeks, as deeper analysis of logs and evidence refines the picture.
The transition from acute response to sustained recovery begins. Systems are restored from clean backups with integrity verification to confirm that the restored systems do not contain remnants of the compromise. Business operations are progressively restored in priority order based on the business-critical system classification established during the retainer onboarding. The communications program moves from internal stakeholder updates to the regulated notification process under breach counsel’s direction. And the post-incident documentation begins to take shape: the timeline, the actions, the decisions, and the preliminary findings that will form the basis of the post-incident report.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the single clearest divider between a first 24 hours that contains an incident and one that compounds it is not the size of the security team or the sophistication of the tooling. It is whether the first two hours were spent activating a team that already knew the environment or spent searching for one that did not.
Armour Cybersecurity’s zero dollar IR retainer provides the guaranteed 24-hour remote response activation, the onboarded context that compresses the initial containment timeline, and the full response lifecycle coverage from identification through lessons learned. The retainer is structured with no upfront block-hour fee, so the relationship is in place before the incident, not discovered as a budget priority after one.
Frequently Asked Questions
What is the single most important action to take in the first 15 minutes of a detected incident?
Do not take any remediation actions before preserving evidence. The most common error in the first 15 minutes is the instinct to fix the problem immediately, reimaging a system, restoring from backup, deleting suspicious files, resetting compromised accounts. These actions can destroy the forensic evidence that the investigation requires to determine how the attacker entered, what they did, and whether the threat has been fully addressed. The correct first action is to escalate to the designated incident response contact, whether internal or the retainer activation line, and to hold the affected systems in their current state until the response team advises on the appropriate preservation steps. Isolated does not mean turned off; many forensic preservation steps require the system to be running to capture volatile memory.
Should we pay a ransom demand?
The decision to pay a ransom is a business and legal decision that should be made by executive leadership in consultation with legal counsel, the cyber insurance carrier, and the incident response team, not by IT or security personnel acting unilaterally. The considerations are numerous: whether paying the ransom is legally permissible given the identity of the threat actor (paying sanctioned entities creates legal liability under OFAC regulations), whether payment is likely to result in a working decryptor (many ransomware groups provide decryptors, but not all), whether the attacker has actually exfiltrated data as claimed, and what the carrier’s position on ransom payment is under the terms of the policy. The incident response team’s role in this decision is to provide the technical assessment of the situation that informs the business decision; the team does not make the payment decision and should not be asked to.
How do we communicate with employees during an active incident?
The communications approach during an active incident must balance the need to keep employees informed enough to be cooperative with the response against the risk of creating panic, speculation, or inadvertent disclosure. The key principles are: communicate through channels that are confirmed to be outside the scope of the compromise (if corporate email is potentially compromised, do not use it to communicate about the breach), provide factual information about what employees should and should not do without speculating about scope or cause, and direct all external inquiries, from customers, media, or other third parties, to the designated communications contact rather than allowing individual employees to respond. The breach coach and IR team advise on the specific communications approach based on the incident type and scope.
What happens after the first 24 hours?
The first 24 hours establish containment and begin the investigation. The subsequent days and weeks complete the investigation, execute the recovery, fulfill the regulatory notification obligations, and produce the post-incident documentation. The depth of the forensic investigation required depends on the incident type and the regulatory and legal context: a ransomware incident at an organization with no personal data obligations may require a shorter investigation than a data exfiltration incident at a healthcare organization with HIPAA breach notification requirements. The post-incident report, produced at the conclusion of the engagement, covers the complete timeline, the actions taken, the lessons learned, and the recommendations for improvements to controls and processes that reduce the risk of a recurrence. This report is the deliverable that supports the insurance claim, the regulatory notification, and the internal improvement program that makes the organization more resilient against the next incident.
The Bottom Line
The first 24 hours of a cyber incident are decided long before the incident starts. Whether the first two hours go to containing the breach or to finding someone who can, whether evidence is preserved or destroyed by a well-meaning fix, whether counsel is engaged early enough to protect the investigation under privilege, all of it comes down to whether the plan and the relationships were in place beforehand. The incident does not wait, and the most expensive hours are the ones spent getting organized while the attacker keeps working. Armour Cybersecurity’s zero dollar IR retainer puts the team, the context, and the guaranteed activation in place before the clock starts, so the first 24 hours are spent responding, not scrambling, with no upfront cost to stand in the way of being ready.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



