What the first hours actually look like
Detection is rarely a clean alarm: a server behaves oddly, a share becomes unreadable, a supplier reports strange mail from your domain. Then the cascade: systems freeze one by one, phones fill, nobody is sure what still works, and every minute of indecision widens the encryption. The organisations that come out with survivable losses are not the ones with the best firewalls — they are the ones where the next five decisions had names attached before the day.
The five decisions, prepared in advance
| Decision | The question | Who must hold the pen |
|---|---|---|
| Isolate | Disconnect networks and sites — accepting operational stop — yes or no, when? | A named person reachable 24/7, with written authority |
| Declare | Trigger the continuity plan and crisis structure — on what threshold? | Duty leadership; the threshold defined, not debated |
| Operate degraded | Which activities continue manually, which stop safely? | Operations, from the pre-built manual-mode plans |
| Communicate | Staff, clients, regulator, insurer — who says what, when? | One voice; holding statements drafted in peacetime |
| Preserve evidence | Images, logs, timelines — before restoring anything | IT with the incident scribe; the insurer and any investigation depend on it |
The mistakes that multiply the loss
- Waiting for certainty before isolating. Encryption spreads while the meeting assembles. The isolation decision is bought in advance with written authority — or paid for in scope.
- Restoring before preserving. Wiping systems destroys the evidence your insurer, lawyers and any regulator will ask for — and can reinstall the attacker's access.
- Trusting backups untested by restore. The worst possible moment to discover a backup does not restore is the moment you need it. Restore-tested is the only «tested».
- Silence toward clients. Hours of silence cost more trust than the incident. A holding statement within the first hours keeps the relationship survivable.
- Improvised negotiation contact. Any contact with the attackers — if it happens at all — belongs to specialists and counsel, not to the night-shift admin. See our pay-or-recover analysis.
The one-page artefact that changes everything: the first-hours card — five decisions, named holders, deputies, thresholds, contact numbers. Laminated, offline, at three locations. Cost: a workshop. Value on the day: the difference between an incident and a catastrophe.
The UAE layer
For UAE organisations the event carries legal clocks alongside the operational ones: personal-data breach obligations, sector notification expectations (for financial institutions, prompt customer notification under the Central Bank framework), and evidence standards your insurer and — where relevant — authorities will apply. The notification decision path belongs in the plan with counsel's number on it, because the clock starts at detection, not at your first meeting.
Frequently asked questions
Should we call the authorities?
Prepare the answer before the event with counsel: which notifications are mandatory for you (data protection, sector regulators), which are advisable, and who makes the call. The wrong answer is discovering the obligations afterwards.
When do we involve the insurer?
Early — most cyber policies require prompt notification and some specify approved responders. Late notification is a classic ground for coverage disputes. The insurer's hotline belongs on the first-hours card.
Do we need external incident response on retainer?
At mid-size and above, a pre-agreed responder shortens the worst day materially — no procurement in a crisis, known rates, familiarity with your environment. At minimum: have the shortlist and contract template ready.