When Seconds Count: What to Do in the First 15 Minutes of a Suspected Cyber Breach

What happens in the first 15 minutes of a cyber incident determines whether you face an afternoon of containment or weeks of catastrophic downtime. Here is your emergency triage playbook.

Share
When Seconds Count: What to Do in the First 15 Minutes of a Suspected Cyber Breach
Photo by Philipp Katzenberger / Unsplash

A frantic employee pings you on Teams: "My screen just locked up, and there’s a weird text file demanding Bitcoin on my desktop."
Or maybe an accountant notices their Microsoft 365 password no longer works, while vendors begin emailing about urgent changes to wire instructions.
In that exact moment, your heart drops. It’s the scenario every business owner and IT manager dreads. But what happens in the first quarter-hour of a cyber incident often determines whether your company faces an afternoon of containment or weeks of catastrophic downtime, forensic investigations, regulatory fines, and reputational damage.
Panic is the enemy of containment. When a breach is suspected, follow this 15-minute emergency triage playbook to protect your organization.

The First 15 Minutes: An Emergency Triage Playbook

Minute 0–3: Disconnect, Don’t Power Down

The instinctive reaction when a machine acts possessed is to hold the power button down or yank the power cord. Do not shut the computer off.

  • Sever the connection: Unplug the physical Ethernet cable immediately and turn off Wi-Fi (or switch on Airplane mode).
  • Preserve volatile RAM: Modern malware, fileless ransomware, and active intrusions leave their digital footprints in the system’s volatile memory (RAM). Shutting down the machine can wipe critical cryptographic keys and forensic artifacts needed to determine the breach's root cause.
  • Isolate endpoints: If an infection is spreading across shared drives, disconnect other workstations on the same local subnet immediately.

Minute 3–7: Alert Your Incident Response Lead & MSP

Clear communication channels save organizations. Avoid emailing internal distribution lists from potentially compromised company accounts—the attacker may already be monitoring your inbox.

  • Use an out-of-band channel: Pick up a cell phone or use a secondary messaging app to call your Managed Service Provider (MSP) and internal leadership.
  • State the facts: What machine is affected? Who was logged in? What specific symptom triggered the alarm (e.g., popup, unusual MFA prompt, locked files)?
  • Initiate protocol: A managed security provider can remotely isolate affected endpoints at the hypervisor or firewall level, stopping lateral movement across your network before malware reaches core servers.

Minute 7–11: Revoke Credentials and Kill Active Sessions

Identity is the modern perimeter, and stolen credentials are the primary vehicle for modern breaches.

  • Force global sign-outs: Administrators should immediately revoke active session tokens in Microsoft 365 / Google Workspace and force a global logout across all devices for the compromised user.
  • Reset passwords and MFA: Reset passwords immediately and reset multi-factor authentication (MFA) methods to prevent an attacker from persisting via an authorized session or an attacker-registered authenticator app.
  • Check forwarding rules: Threat actors frequently set up hidden email forwarding rules to exfiltrate data silently. Audit the user’s mailbox rules right away.

Minute 11–15: Document the Timeline & Secure Backups

Before the fog of war sets in, capture details while they are fresh.

  • Write down what happened: Note the exact time the anomaly was spotted, who reported it, and any links clicked or files downloaded in the preceding hour. Take a photo of the monitor screen with a phone if a ransom note or error code is displayed.
  • Air-gap and verify backups: Confirm that your backup repositories are segregated and protected. Attackers spend days hunting down local backup servers, Shadow Copies, and NAS drives before deploying ransomware. Ensure your offsite, immutable cloud backups are untouched.

Moving Beyond Panic: The Three Layers That Stop Breaches Before They Start

While having an incident response plan is critical, building a resilient IT environment means you don’t have to execute that plan under duress.
Modern cyber hygiene relies on three foundational pillars designed to neutralize threats before they escalate into an emergency:

+--------------------------------------------------------------+
|                    THE MODERN DEFENSE TRIAD                  |
+--------------------------------------------------------------+
| 1. Robust MFA        --> Stops identity compromise at the door|
| 2. Next-Gen EDR/MDR  --> Hunts behavioral threats in real-time|
| 3. Security Awareness--> Turns employees into active firewalls |
+--------------------------------------------------------------+

1. Phishing-Resistant MFA (Everywhere, No Exceptions)

Basic passwords are long dead. Enforcing Multi-Factor Authentication across all business systems—email, VPNs, line-of-business software, and remote access tools—cuts account takeovers drastically. Upgrading to number matching or FIDO2 hardware keys eliminates "MFA fatigue" attacks where users are bombarded with prompts until they accidentally hit "Approve."

2. Next-Gen Endpoint Detection & Response (EDR / MDR)

Traditional antivirus scans for known signatures, meaning it is blind to novel zero-day attacks and fileless exploits. Modern EDR actively monitors system behaviors. If an unknown script begins encrypting directories or attempting lateral network traversal, EDR automatically freezes the process and isolates the device in seconds—long before human operators could intervene.

3. Continuous Employee Phishing Simulations & Training

Over 80% of security incidents involve human error. Annual 30-minute compliance videos don’t change behavior; continuous, realistic phishing simulations do. Training your team to identify subtle spoofed domains, urgent executive wire requests, and bogus invoice attachments turns your staff from your biggest vulnerability into an active human firewall.

Build Your Playbook Before You Need It

When an incident hits, panic costs money, uptime, and client trust. Having an incident response roadmap tailored to your specific infrastructure—paired with round-the-clock monitoring and immutable backups—ensures that a rogue click remains an isolated ticket rather than a headline.
If your team hasn’t tested your response procedures or audited your endpoint protections recently, partnering with a dedicated Managed Service Provider ensures someone is always watching the wire—so you don't have to navigate the first 15 minutes alone.