The First 12 Hours of an Incident Matter More Than the Next 12 Days
5 Minute Read
by Bread Fyan
When organizations experience a cyberattack, executives often focus on recovery timelines, business impact, and regulatory obligations. Yet the outcome of those conversations is often determined long before recovery begins.
The first 12 hours of a cyber incident are when investigations gain momentum, critical evidence is preserved, and strategic decisions take shape. That early window is becoming increasingly important as threat actors continue to accelerate their operations. Recent incident response investigations show attackers moving from initial access to data exfiltration in days rather than weeks, dramatically reducing the time defenders have to detect, investigate, and contain malicious activity before business impact grows. Whether the event involves data theft, business email compromise, or a ransomware response, organizations that act deliberately in those early hours are far more likely to contain damage, accelerate recovery, and meet regulatory obligations.
The challenge is that those first hours rarely feel deliberate. They feel chaotic.
Technical teams are flooded with alerts. Leadership wants answers. Legal and communications teams need guidance. Cyber insurance providers and breach counsel may need to be engaged. Business leaders are trying to understand operational impact. In those moments, effective digital forensics and incident response is not just about investigating an attack, but also about bringing control, clarity, and calm to a rapidly evolving situation. As LevelBlue’s Global Services Leader of DFIR, Devon Ackerman, puts it, “Every case share[s] a common thread: someone [i]s experiencing the worst moment of their organization...and needed answers.”
Hours 0-2: Establish control before rushing to action
One of the most common mistakes during a cyber incident is treating speed as the only priority.
When suspicious activity is detected, there is often immediate pressure to disconnect systems, disable accounts, or power down affected assets. While these actions may be necessary, poorly sequenced containment efforts can inadvertently destroy evidence that investigators need to understand how an attacker gained access and whether they remain elsewhere in the environment.
The first two hours should focus on establishing control of the situation:
- Activate the incident response plan.
- Identify decision-makers and escalation paths.
- Notify legal counsel and key executives.
- Engage cyber insurance providers and understand notification requirements.
- Establish secure communication channels.
- Ensure investigators have visibility into affected systems before significant changes are made.
Prepare, investigate, and recover with LevelBlue Incident Readiness & Response.
Learn MoreEffective breach containment is rarely about taking the fastest action. It is about taking the right action at the right time to ultimately:
- Contain the threat without destroying critical evidence.
- Preserve forensic visibility into attacker activity.
- Coordinate business and executive decision-making.
- Establish a clear path toward recovery.
Organizations that achieve these objectives early are often able to reduce operational disruption, accelerate investigations, minimize long-term costs, and make more informed decisions. Those that do not may find themselves making critical decisions based on incomplete or inaccurate information.
Hours 2-6: Preserve evidence while the story is still intact
A cyber incident creates a rapidly changing crime scene. Memory data disappears. Log retention windows close. Systems reboot. Adversaries modify or delete artifacts to cover their tracks. The longer evidence collection is delayed, the harder it becomes to reconstruct what actually happened. This challenge is compounded by the pace of modern intrusions as recent incident response data shows a growing share of organizations identifying compromises within a 3-10 day window, reflecting how quickly many threat actors are now progressing once inside victim environments. When attackers are operating on a timeline measured in days, every hour of forensic visibility becomes valuable.
This is why digital forensics and incident response must begin immediately, not after containment is complete. During this phase, incident responders focus on answering critical questions:
- How did the attacker gain access?
- What systems were affected?
- Is the threat still active?
- Was sensitive data accessed or exfiltrated?
- What business functions are at risk?
The goal during the first 12 hours is to collect evidence and build an accurate timeline of attacker activity. Identifying and properly preserving key evidence sources have a direct impact on the overall understanding of the incident, from the amount of detail that can be learned to the level of confidence in the answers to the critical questions. For example, capturing the following data sources early, while evidence is still intact may be needed to fully understand what occurred during a breach:
- Impacted system images
- Network logs
- Cloud service (such as M365) logs
- Endpoint detection and alert data
Strong forensic practices also create confidence. Rather than making assumptions about the scope of an incident, organizations can base decisions on evidence. That distinction often determines whether recovery efforts are measured and effective or prolonged and reactive.
Hours 6-12: Prepare for business, legal, and regulatory impact
By this stage, leadership is often being asked questions that security teams cannot fully answer yet.
Customers may require updates, regulators may need notifications, boards may request briefings, media inquiries may emerge, and cyber insurance carriers and breach counsel may require investigative updates to support coverage decisions and response strategies.
Cyber incidents can be just as much business crises as they are technical events.
Organizations should begin assessing potential obligations under applicable frameworks and regulations, including:
- SEC cybersecurity disclosure requirements for public companies.
- NYDFS Part 500 requirements for covered financial entities.
- GDPR breach notification obligations.
- NIS2 reporting requirements across the European Union.
- DORA obligations for financial services organizations.
The objective is not to rush disclosure, but to ensure decisions are informed by facts, supported by evidence, and aligned with applicable requirements.
A mature incident response process translates investigative findings into actionable business intelligence. Leaders do not need every technical detail; they need clear assessments of risk, impact, and recommended actions.
In many cases, that ability to provide clarity is just as important as the technical investigation itself.
Recovery begins long before systems come back online
Many organizations think of cyber recovery as the final stage of an incident. In reality, recovery planning begins the moment an investigation starts.
Even when backups are available, restoring systems before understanding the root cause can allow attackers to regain access after restoration is complete. Organizations that recover most effectively begin evaluating backup integrity, restoration priorities, business continuity needs, root cause remediation activities, and long-term resilience improvements from day one.
What many organizations often underestimate is the length, and cost, of the recovery journey. The attack itself may last hours or days, but the business impact often unfolds over months or years, with evidence preservation quality greatly impacting that timeline. For example, poor evidence preservation or missing data sources can cause hardship during litigation and how well-informed the disclosure-related actions are.
For a high-level example, however, a typical incident timeline may include:
- 2-8 weeks: Investigation, digital forensics and incident response, and coordination with outside counsel.
- 1-2 months: Remediation activities, including security improvements, infrastructure hardening, and staff augmentation support.
- 1-2 months: Restoration efforts to safely return systems, applications, and business operations to normal.
- 1-3 years: Disclosure-related obligations, including breach notification, call center support, mailings, and credit monitoring services.
- 1-3 years: Litigation, regulatory inquiries, fines, arbitration, and potential class action proceedings.
While investigation and containment often receive the most attention during the early stages of a breach, they frequently represent only a fraction of the total financial and operational impact. Long after systems are restored, organizations may still be managing regulatory obligations, legal proceedings, customer communications, third-party assessments, and ongoing security improvements.
Recovery is therefore not simply a technology challenge. It is a business resilience challenge that requires expertise across digital forensics, incident response, legal coordination, regulatory compliance, communications, remediation, and long-term risk reduction. Organizations that recognize this reality early are better positioned to control costs, reduce disruption, and emerge from an incident with a stronger security posture than they had before.
Recovery is a parallel effort that begins on day one and, in some cases, continues for years after the initial attack.
How to take a proactive approach to incidents
The reality is that the quality of an organization's incident response is often determined before an incident ever occurs. The first 12 hours are not the time to decide who to call, negotiate contracts, or determine escalation procedures. These decisions should already be firmly in place.
This is also where organizations discover that not all incident response retainers are created equal. Beyond access to technical expertise, the most effective programs provide flexibility, insurance-aligned engagement models, rapid access to responders, litigation-ready investigative support, and ongoing resilience planning that helps organizations strengthen defenses once the immediate crisis has passed.
While important, the value of preparation is not simply faster response, but the ability to move confidently through uncertainty with a clear plan, proven expertise, and the resources needed to adapt as the situation evolves. A simplified checklist of what should be done ahead of time:
- Establish an incident response retainer with a trusted provider.
- Review cyber insurance policy requirements and notification procedures.
- Identify breach counsel and legal escalation paths.
- Conduct tabletop exercises with executives and technical teams.
- Define communication workflows for leadership, customers, and regulators.
- Validate backup and recovery capabilities.
The first 12 hours of a cyber incident are often more consequential than the next 12 days.
Those early decisions influence the effectiveness of breach containment, the quality of forensic evidence, the confidence of executive stakeholders, the success of a ransomware response, and the speed of cyber recovery.
Organizations cannot eliminate chaos when an incident occurs. But with the right people, processes, and preparation, they can bring control and calm to it.
About the Author
Bread Fyan is a Senior DFIR Consultant at LevelBlue who leads M365, litigation support, and remediation matters. He has written multiple declarations and frequently supports expert witness testimony for a variety of case types. Follow Bread on LinkedIn.
About LevelBlue
LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.