Tools / IR

First-hour checklist

Defensive only. Adapt to your plan. This is not legal advice and not an ACSC playbook reprint.

IR / NIST 800-61 style loopPrepareDetect + analyseContain + eradicateRecover + lessonsFirst hour is contain and preserve. Fancy write-up comes later.
  1. 01Declare the incident. One lead. A shared timeline document, clock in UTC and AWST.
  2. 02Preserve: snapshot volatile systems only if you know how; otherwise do not trample logs. Export auth, VPN, EDR, mail, DNS.
  3. 03Contain obvious spread: isolate endpoints via EDR, disable compromised identities, block known-bad at the edge. Human gate on mass disables.
  4. 04Crown jewels: are identity, backups, and finance/OT reachable from the affected plane? Segment now.
  5. 05Facts only in the channel. What is confirmed, what is suspected. No root-cause fan fiction.
  6. 06Legal + privacy: is personal information involved? Start the NDB assessment clock. OAIC if it is eligible.
  7. 07Notify those with authority: exec, ACSC (1300 CYBER1) if you need them, insurer if the policy says so.
  8. 08External comms: one spokesperson. Customers later, when the facts hold.
  9. 09Keep a decision log: who approved isolation, who approved any shutdown.
  10. 10Do not rebuild yet. Recover is hour four or day two, after you know what you are recovering from.