Initial Response
First Responder Checklist
Quick-reference checklist for the critical first minutes of any security incident, focusing on preservation and escalation.
Initial Response · beginner · 15-30 min
Universal first steps for any security incident, designed for IT staff who may be first on scene.
Steps
5
01
Stay Calm and Document
Your first priority is to document what you observe.
- Note the exact date and time you were notified
- Record who reported the incident and how
- Document your initial observations
- Take screenshots of any visible indicators
- Start a timeline of events and your actions
Use a shared document or incident management system Assume everything you document may be used in legal proceedings
02
Assess and Classify
Make an initial assessment of the incident severity.
- What type of incident is this? (malware, phishing, unauthorized access, etc.)
- What systems or data are potentially affected?
- Is the incident ongoing or historical?
- What is the potential business impact?
03
Preserve Evidence
Do not destroy potential evidence.
- Do NOT power off affected systems (unless actively destructive)
- Do NOT delete suspicious files or emails
- Do NOT login to potentially compromised accounts
- Do NOT alert potential threat actors
- Preserve logs before they rotate
When in doubt, isolate but don't modify Take photos of physical indicators if relevant
04
Contain (If Safe)
Take immediate containment actions if clearly safe to do so.
- Network isolate affected systems via EDR or VLAN change
- Disable compromised accounts
- Block known malicious IPs/domains at firewall
- If unsure, wait for security team guidance
05
Escalate
Notify the appropriate people.
- Contact the security team via established channels
- Notify your direct manager
- Do NOT discuss details on public channels
- Provide your documented observations and timeline
Checklist
- Time and date documented
- Initial observations recorded
- Screenshots/photos taken
- Systems NOT powered off
- Evidence NOT deleted
- Initial classification made
- Containment actions taken (if safe)
- Security team notified
- Manager notified
- Timeline started
Evidence
- Your written observations with timestamps
- Screenshots of indicators
- Photos of physical evidence (if any)
- List of potentially affected systems
- List of people you've notified