Author
Trawvid Sec
Published
Last reviewed
Review status
Current
Before you begin
Set up the work
Expected effort: The universal first actions should take less than five minutes to read. Use only the scenario paths that fit the event. A preparation review normally takes about 30 minutes.
Bring these inputs
- A known-clean phone or communication channel that does not depend on the suspected system.
- Current leadership, technology-provider, bank, insurer, legal, and critical-vendor contacts.
- A safe place outside the suspected environment to record times, facts, actions, and case numbers.
Keep these outputs
- A named incident owner, trusted communication path, and next update time.
- A short incident timeline with the relevant scenario actions and outside contacts.
- A business-approved recovery order and open-action handoff.
If something is happening now, start here
Do not wait for a perfect diagnosis. The first job is to protect people, stop immediate loss, keep a useful record, and avoid making the event harder to investigate.
The universal first actions
- Protect people and physical operations. Life safety and operational safety come before a computer.
- Call the bank if money may have moved. Use a known number and ask for the fraud or wire department. Request a recall or reversal and record the case number.
- Limit active spread when it is safe. Disconnect a clearly affected device from wired and wireless networks when malware appears to be spreading. Do not connect backups or random cleanup tools.
- Move communication away from suspected systems. If email or chat may be compromised, use a known-clean phone or another trusted channel.
- Name one incident owner. That person coordinates actions, times, facts, outside calls, and the next update. They do not need to perform every technical task.
- Get qualified help when the business cannot confidently contain, preserve, scope, or recover. A serious event is not the time to learn digital forensics through search results.
Avoid these common mistakes:
- Do not wipe, reimage, or broadly reset systems before useful evidence needs are understood.
- Do not delete suspicious messages, logs, or files just because they look dangerous.
- Do not coordinate through an account that may be compromised.
- Do not make public or customer statements beyond the supported facts.
- Do not delay a bank, emergency, insurer, legal, or law-enforcement call while waiting for Trawvid Sec to reply.
Open one simple control record:
| Incident or concern | Discovered date and time | Incident owner | Leadership decision-maker | Trusted communication channel | Next update |
|---|---|---|---|---|---|
Then use every scenario below that may apply. A fraudulent payment may also involve a compromised mailbox. A provider incident may also expose sensitive information.
Choose the scenario actions that fit
Payment, wire, payroll, or invoice fraud
Act quickly. Recovery options get worse as time passes.
- Call the originating financial institution through a known number.
- Ask for the fraud or wire department and request a recall or reversal.
- Record the case number, time, instructions, and next follow-up.
- Verify the request with the intended vendor, employee, executive, or advisor through a known second channel.
- Preserve the original request, invoice, message, email headers when available, and transaction confirmation.
- Review related payments and recent changes during the suspected exposure window.
- File promptly with IC3 when the event involves internet-enabled fraud.
- Use the account-compromise path below if a mailbox or identity account may be involved.
Do not continue the suspicious thread to ask whether it is legitimate. Contact the known person another way.
Email, cloud, or identity account compromise
Use a known-clean device and administrative path when available.
- Move response communication outside the suspected account.
- Preserve available sign-in history, active sessions, forwarding rules, inbox rules, delegates, recovery changes, multifactor changes, and connected applications.
- Block or suspend sign-in when the evidence and business impact support it.
- Revoke active sessions and refresh tokens.
- Reset the credential to a unique value from a known-clean device.
- Remove unknown recovery methods, forwarding, delegates, and application permissions.
- Re-establish the legitimate user and verify known devices.
- Review which financial, payroll, cloud, customer, domain, social, and password-recovery workflows the account could influence.
Do not assume a password change ends the event. Sessions, forwarding rules, recovery methods, and connected applications may survive it.
Lost or stolen phone or computer
- Record the device owner, type, identifying information, last known time, and location.
- Determine whether the device was encrypted, locked, managed, and signed in to important accounts.
- Preserve management records showing encryption, last check-in, and actions taken.
- Use trusted locate, lock, or erase controls when the facts support that decision.
- Revoke high-risk sessions and protect accounts available from the device.
- For a phone, contact the carrier through a known number and check for a number transfer or SIM change.
- Record whether sensitive, regulated, confidential, or contract-protected information may have been available.
- Make a police report when theft is suspected and keep the report number.
Malware, ransomware, or spreading unusual activity
- Disconnect confirmed or strongly suspected devices from networks when safe.
- Coordinate broader isolation through network controls when many systems are involved.
- Protect backup administration and known-good recovery points. Do not connect offline backups to test them.
- Preserve ransom notes, screenshots, filenames, alerts, logs, and a representative affected-system list.
- Contact qualified response support when the business cannot confidently contain or preserve the event.
- Contact the cyber insurer according to the policy and confirm any vendor requirements before major expense when time permits.
- Record who can stop operations, approve workarounds, and decide recovery order.
- Report ransomware to a local FBI field office or IC3 and consider reporting to CISA.
Do not download a decryptor or cleanup utility from a random search result. Do not treat an extortion payment like an ordinary purchase. The FBI does not support paying ransom, and payment does not guarantee recovery or deletion.
Sensitive information may have been exposed
- Stop additional access by restricting the folder, disabling the public link, removing the page, or isolating the source.
- Preserve screenshots, settings, access history, logs, message headers, and timestamps before changing more than necessary.
- Record what information was involved, whose information it was, and the likely exposure period.
- Determine whether information was viewed, downloaded, altered, or only potentially available.
- Identify affected systems, providers, contracts, customers, and business relationships.
- Engage qualified counsel before making legal-notification conclusions or definitive external statements.
- Assign someone to check for copies in recipient systems, search results, caches, or other locations.
Do not say "no data was accessed" merely because access has not yet been proven.
A vendor or technology provider reported an incident
- Identify what the provider can access, administer, reset, export, delete, or interrupt.
- Preserve the provider notice and your own relevant logs before retention periods close.
- Ask for dates, affected services, customer impact, required actions, containment status, and the next update time.
- Narrow unnecessary access or rotate affected credentials when the facts support it.
- Verify remediation that matters to your environment rather than relying only on a general assurance.
- Assign the customer, contract, insurance, legal, and regulatory questions to the appropriate people.
- Record any decision to keep access active because immediate removal would create a larger safety or continuity problem.
Keep one running record
Do not create a different worksheet for every thought. Keep one timeline that separates facts, assumptions, actions, decisions, and open questions.
| Time | Fact, assumption, action, or decision | Source or person | Result or reason | Owner | Next action or update |
|---|---|---|---|---|---|
Preserve original records before forwarding, editing, wiping, or reimaging. Store the incident record outside the suspected environment and limit access to people who have a role in the response.
A new responder should be able to read the timeline and understand what is known, what remains uncertain, what has been done, and what decision comes next.
Decide who needs to be called
Not every event needs every outside party. Every material call should have an owner and a next follow-up.
| Party | Call when | Trusted contact | Owner | Case number or next follow-up |
|---|---|---|---|---|
| Bank or payment provider | Money moved or payment details may be fraudulent | |||
| Technology or incident-response provider | The business cannot confidently contain, preserve, scope, or recover | |||
| Insurer or broker | The policy may require notice or approved response vendors | |||
| Qualified counsel | Personal, regulated, contract-protected, extortion, employee, or material notice questions may exist | |||
| Law enforcement or government | Fraud, ransomware, theft, or another reportable crime may be involved | |||
| Critical customer or partner | Supported facts show a material operational or contractual impact requiring coordinated communication |
Give leadership the known business impact, uncertainty, decisions required, and next update time. Give technical responders the systems, accounts, indicators, evidence, actions, and dependencies. Give employees only the instructions they need to avoid more harm and continue approved work.
Technical staff should not guess legal duties. Legal reviewers should not guess technical facts. Keep the handoff explicit.
Recover in business order
Containment is not the finish line. Restore services according to business need, not whichever system is easiest to turn back on.
| Service or process | Business priority | Workaround | Technical owner | Business approver | Return criteria or remaining concern |
|---|---|---|---|---|---|
Before returning an affected service:
- Address the suspected access path enough to avoid immediate recurrence.
- Review affected credentials, sessions, keys, integrations, and administrator paths.
- Confirm the restore source is appropriate.
- Confirm required updates, logging, and monitoring are operating.
- Test that the service performs the business function expected.
- Record who approved the return, what remains uncertain, and how long heightened monitoring will continue.
Keep a service offline when the return criteria are not met and an approved workaround is safer.
Prepare before the first hour
Do this section when no incident is active.
- Name the incident owner, leadership decision-maker, and backups.
- Save known-clean contact methods for the technology provider, bank fraud team, insurer or broker, counsel, and critical vendors.
- Decide where the incident timeline can be kept when company email or cloud storage is unavailable.
- Record where asset, account, log, backup, insurance, and recovery information can be reached.
- Choose a communication method outside company email.
- List the business processes that must return first.
- Walk through one realistic scenario for 20 minutes.
- Fix the largest assumption the exercise exposes.
The preparation is usable when:
- The contact information works without company email.
- Decision authority is clear.
- The business knows where its basic records and recovery information live.
- One scenario has been discussed.
- Every discovered gap has an owner and date.
If the event is active and material, use the email and booking options on this page only as an additional advisory path. Do not delay emergency services, a financial institution, the phone carrier, an existing response provider, the insurer, qualified counsel, or law enforcement while waiting for a reply.
Keep working
Related resources
Practical next step
If the contact list, decision owners, evidence sources, or recovery order are unclear, build those answers before an incident forces the conversation.
Prepare for the first hourReference baseline