Establish one operating picture
The first hours are rarely orderly. Alerts may be incomplete, business teams want immediate answers and technical staff may be working across several systems. Appoint an incident lead and create a written action log. Record what was observed, when it was observed, the systems involved and every material action taken. Use exact timestamps and include the timezone.
Confirm operational impact separately from technical indicators. A security alert does not always mean a service is unusable, while a business outage may involve dependencies that are not obvious from security tooling. Identify the services that must be protected first and the systems they rely on.
Contain deliberately
Disconnecting a host, disabling an account or blocking network paths may be necessary, but each action can affect operations and evidence. Preserve relevant logs and volatile information before making irreversible changes whenever the situation allows. Record the reason for each containment decision and the person who approved it.
Containment is not a race to change everything. It is a controlled reduction of risk based on what is known at that moment.
Protect communication and define the next decision
Move sensitive coordination to a channel known to be safe. Limit distribution to people with an operational, legal or decision-making role, and avoid speculation in broad email threads. State what is known, what remains uncertain, which actions are underway and when the team will reassess.
A disciplined first response creates the conditions for a more reliable investigation and a safer recovery. It also gives leadership a defensible account of why early decisions were made.