ChecklistResilience and incident response
14 Aug 20269 min read
What to Do in the First Hour of a Cyber Attack
Put one person in charge, contain the incident without making evidence loss automatic, start trusted calls and a time-stamped record, stop suspicious payments, and assess each reporting duty separately.
Read featured articlePractical takeaway
Appoint one incident lead, use trusted communications and record each containment decision from the start.
Written by Alec Pedersen