The first 24 hours after you think you were hit
In the first day, contain what is still spreading, preserve evidence, reset the accounts that matter, and call the people who can help. Do not reimage everything before anyone has looked. Do not pay from the first email. Tailored Tech clients should call the desk on the published after-hours path.
Updated 2026-09-01
What this page is
This is an owner checklist for the first day, not a technical playbook for attackers and not a substitute for counsel or your insurer. If you have an incident retainer or a cyber policy, those documents override a blog post.
If Tailored Tech already manages the environment, start with us. The desk has the inventory and the backups. You should not be guessing admin passwords while the clock runs.
First hour
Name one person who is in charge of the next twelve hours. Too many voices is how machines get wiped and logs get lost.
Call your managed provider or internal lead. If it is after hours, use the phone path in your agreement, not a chat thread nobody is watching.
Separate obviously affected machines from the rest of the network if you are told to. Do not start a scavenger hunt across every laptop.
Stop. Do not delete “suspicious” files to clean up. Do not power-wash the server because it feels decisive. Evidence and backups live on those disks.
The rest of day one
Identity first. Reset and review the admin accounts, the email admin, and VPN. MFA prompts that staff “just approved” are part of the story, not noise.
Email next if that is how it started. A flood of lookalike vendor mail is a containment problem, not a manners problem.
Backups. Confirm they are reachable and that the copies you need are not sitting only on the same host that is sick. Do not restore over the evidence until someone who owns the incident says so.
Write down times. When it was noticed, what was clicked, who was called. Insurers and counsel will ask. A shared note beats memory.
Who else to loop in
Leadership, so they hear facts instead of Slack rumor. Counsel if customer data or a contract requires it. The insurer if the policy says to notify early. Banking if wires are in play.
Do not negotiate with a ransom note on your own. That is a legal and insurance decision, not a help-desk decision.
What Tailored Tech does when we are already on the account
We work the ticket as an incident, not as “weird slowness.” Containment, identity, email, and backup status are the first pass. Projects and nice-to-have cleanups wait.
If we are not your provider and you are in the first day, start a conversation only after you have called whoever already has access. Switching MSPs mid-incident is not day-one work.
Keep going
Questions on this topic
Short answers for buyers comparing options.
Should we pull the internet connection?
Sometimes a segment needs to come off. A whole-office unplug without a plan can also block the people who need to fix identity and email. Ask the person running the incident before you yank the handoff.
Should we pay?
Do not decide that from a blog post. Call counsel and the insurer. Paying is not an IT setting.
When do we tell customers?
When you know what left and what the contract or law requires. Day one is usually for facts, not a public narrative.
Want this applied to your environment?
Tell us how the business runs. We will map the model without a long pitch.
