Incident response planning: what to do in the first hour | Liyatech Solutions

Incident Response

Incident response planning: what to do in the first hour

Cyber Security Team·August 2026

Most of what determines how badly a breach ends up hurting a business gets decided in the first sixty minutes — long before forensics, insurers, or the full damage assessment are even in the room.

Frameworks like NIST's incident handling guide break response into preparation, detection and analysis, containment and eradication, and recovery. In the first hour, only one of those matters: containment. Everything else can, and should, wait.

What matters in the first hour

Isolate first, investigate second. A compromised workstation or account gets disconnected from the network or has its credentials disabled immediately — before anyone has fully confirmed how the attacker got in. Waiting for certainty before containing anything is how a single compromised machine becomes a network-wide encryption event. Identify who has the authority to make that call without needing sign-off from three people first; a plan that only works when the right person happens to be reachable isn't a plan.

What can wait

Root cause analysis, full forensic imaging, communicating with every stakeholder, and deciding whether to engage law enforcement in detail are all real steps — but none of them need to happen inside the first hour, and rushing them tends to interfere with the containment that does. Preserving evidence matters, but preservation is a "don't destroy it" instruction, not a "stop and analyse it right now" one.

The POPIA clock is already running

If personal information is involved, the notification obligation to the Information Regulator and affected individuals starts from the moment of discovery, not from when the investigation concludes. A public sector breach earlier this year showed what a well-handled version of this looks like: contain, refuse to engage with the ransom demand, and notify the Regulator early rather than waiting for a complete picture. That sequencing, more than any single technical decision, shaped how the incident was received.

Building the muscle before you need it

The organisations that handle the first hour well are the ones that decided, calmly and in advance, who gets called, who has authority to disconnect a system, and what the very first message to staff says. None of that works if it's being improvised for the first time during the incident itself.

The first hour isn't for figuring out what happened. It's for making sure it stops happening while you still can.Liyatech Cyber Security Team

Keep reading

_____


Public Sector

Public sector cyber risk: lessons from recent South African breaches

Read more
Compliance

Compliance without the headache: how we approach POPIA and data protection

Read more
Security

What managed detection and response actually catches (that antivirus doesn't)

Read more