Incident response planning: what to do in the first hour
Most of what determines how badly a breach ends up hurting a business gets decided in the first sixty minutes — long before forensics, insurers, or the full damage assessment are even in the room.
Frameworks like NIST's incident handling guide break response into preparation, detection and analysis, containment and eradication, and recovery. In the first hour, only one of those matters: containment. Everything else can, and should, wait.
What matters in the first hour
Isolate first, investigate second. A compromised workstation or account gets disconnected from the network or has its credentials disabled immediately — before anyone has fully confirmed how the attacker got in. Waiting for certainty before containing anything is how a single compromised machine becomes a network-wide encryption event. Identify who has the authority to make that call without needing sign-off from three people first; a plan that only works when the right person happens to be reachable isn't a plan.
What can wait
Root cause analysis, full forensic imaging, communicating with every stakeholder, and deciding whether to engage law enforcement in detail are all real steps — but none of them need to happen inside the first hour, and rushing them tends to interfere with the containment that does. Preserving evidence matters, but preservation is a "don't destroy it" instruction, not a "stop and analyse it right now" one.
The POPIA clock is already running
If personal information is involved, the notification obligation to the Information Regulator and affected individuals starts from the moment of discovery, not from when the investigation concludes. A public sector breach earlier this year showed what a well-handled version of this looks like: contain, refuse to engage with the ransom demand, and notify the Regulator early rather than waiting for a complete picture. That sequencing, more than any single technical decision, shaped how the incident was received.
Building the muscle before you need it
The organisations that handle the first hour well are the ones that decided, calmly and in advance, who gets called, who has authority to disconnect a system, and what the very first message to staff says. None of that works if it's being improvised for the first time during the incident itself.
Keep reading
_____