Think you're compromised?
These steps can help preserve evidence and reduce further damage while you seek expert assistance.
Don't panic-reset everything
Mass password resets, reinstalls and cleanup activities can destroy valuable information needed to understand how the incident occurred.
Preserve logs
Where possible preserve authentication logs, application logs, firewall logs, endpoint alerts, cloud audit logs, suspicious emails, timestamps, screenshots and suspicious files.
Record what you observed
Capture when the issue was discovered, who discovered it, affected accounts, affected machines, unusual behaviour and recent system changes.
Contain carefully
If immediate containment is required, document every action. Network isolation and account disablement can contain threats while preserving evidence.
Avoid confronting suspected insiders prematurely
Premature confrontation may affect evidence, behaviour or investigation integrity. Preserve technical evidence before personnel decisions.
Seek appropriate expertise
Security incidents often require specialized investigation skills. Early expert guidance can prevent evidence destruction and scope misassessment.
This information is general incident-response guidance and does not replace advice tailored to the specific incident.