Emergency Guidance

Think you're compromised?

These steps can help preserve evidence and reduce further damage while you seek expert assistance.

01

Don't panic-reset everything

Mass password resets, reinstalls and cleanup activities can destroy valuable information needed to understand how the incident occurred.

02

Preserve logs

Where possible preserve authentication logs, application logs, firewall logs, endpoint alerts, cloud audit logs, suspicious emails, timestamps, screenshots and suspicious files.

03

Record what you observed

Capture when the issue was discovered, who discovered it, affected accounts, affected machines, unusual behaviour and recent system changes.

04

Contain carefully

If immediate containment is required, document every action. Network isolation and account disablement can contain threats while preserving evidence.

05

Avoid confronting suspected insiders prematurely

Premature confrontation may affect evidence, behaviour or investigation integrity. Preserve technical evidence before personnel decisions.

06

Seek appropriate expertise

Security incidents often require specialized investigation skills. Early expert guidance can prevent evidence destruction and scope misassessment.

This information is general incident-response guidance and does not replace advice tailored to the specific incident.