Incident Response Planning: What Happens During the First 24 Hours of a Cyberattack?

“Rusty, what actually happens if we get hacked?”

That’s one of the better cybersecurity questions a credit union executive can ask.

Not:

“Which firewall do we have?”

Not:

“How many security alerts did we get last month?”

But what actually happens when something goes wrong?

Imagine it’s 8:12 on a Monday morning.

An employee calls the help desk because she can’t open several files.

A few minutes later, another employee reports the same problem.

Someone notices a strange message on a computer screen.

Suddenly, this isn’t an IT ticket anymore.

You may be dealing with a cyberattack.

What happens during the next 24 hours can have an enormous impact on your credit union’s ability to contain the incident, protect information, continue operations, and begin recovery.

And here’s the most important part:

You shouldn’t be figuring out the first 24 hours during the first 24 hours.

Your incident response plan should already tell people what to do, who to call, and who is responsible for making decisions.

Let’s walk through what that can look like.

Hour 0–1: Identify the Problem and Start Containment

The first hour can be confusing.

You may not immediately know whether you’re dealing with ransomware, a compromised Microsoft 365 account, stolen credentials, malware, or another security event.

That’s okay.

Your first job isn’t to solve the entire mystery.

It’s to recognize that something serious may be happening and begin following your incident response process.

The appropriate technical team may need to isolate affected devices or accounts, preserve information needed for investigation, and determine whether suspicious activity is continuing.

At the same time, someone needs to activate the incident response team.

That could involve:

  • Executive leadership
  • Internal IT
  • Your managed technology or cybersecurity partner
  • Compliance personnel
  • Legal counsel
  • Cyber insurance resources
  • Other specialists appropriate to the situation

This is why contact information should already be documented somewhere accessible even if your normal network isn’t available.

During an emergency, you don’t want to hear:

“Does anybody have our cyber insurance carrier’s phone number?”

Hours 1–4: Determine What You’re Dealing With

Once immediate response steps are underway, the next question is scope.

What’s affected?

One computer?

Several accounts?

Microsoft 365?

Servers?

File systems?

A third-party application?

Your team needs to start building a picture of the incident.

This is also where good monitoring, documentation, and asset management become valuable.

It’s difficult to determine what’s abnormal if you don’t have a clear picture of what’s normal.

Leadership doesn’t need every technical detail.

Leadership does need answers to questions like:

Can we still serve members?

Is sensitive information potentially involved?

Is the incident contained?

Which critical systems are unavailable?

What professional resources do we need involved?

The answers may change as the investigation continues.

That’s normal.

Hours 4–8: Shift From Reaction to Coordination

This is where a cybersecurity incident becomes a leadership event.

Different groups may now be working simultaneously.

Technical teams may be investigating and containing the attack.

Leadership may be making operational decisions.

Legal and compliance professionals may be evaluating obligations.

Insurance resources may be involved.

Vendors may need to assist.

Communication may need to be prepared.

Without coordination, everyone can be busy while nobody is actually in charge.

Your incident response plan should establish roles and decision-making authority before the attack happens.

Someone needs to coordinate the overall response.

Someone needs to own technical recovery.

Someone needs to manage communications.

Someone needs to document decisions and actions.

And someone needs to keep leadership informed.

Hours 8–12: Understand the Business Impact

Eventually, the conversation has to move beyond:

“What happened?”

to:

“How do we keep operating?”

This is where incident response and business continuity come together.

Suppose your employees cannot access certain systems.

What processes can continue?

What services are most critical?

Which systems need to return first?

Are there manual workarounds?

How will employees communicate if email isn’t available?

How will leadership communicate with the board?

How will member inquiries be handled?

This is why your business continuity plan can’t live independently from your cybersecurity program.

A cyberattack can become a business interruption very quickly.

Your members don’t care which technology failed.

They care whether they can access the credit union.

Hours 12–18: Begin Recovery Carefully

One of the natural reactions after an attack is:

“Get everything back online.”

I understand the instinct.

But recovery needs to be deliberate.

Before restoring systems, the appropriate technical and incident-response professionals need to understand enough about the incident to avoid simply restoring the problem along with the data.

This is where tested backups become critical.

Notice I said tested backups.

I’ve said it before, and I’ll keep saying it:

A backup is not the same thing as recovery.

Your team should already understand:

  • Which systems are most critical
  • Where protected backups are located
  • What order systems should be restored
  • Approximately how long recovery may take
  • Who has authority to begin restoration
  • How restored systems will be validated

Don’t invent that process at hour 14 of an attack.

Practice it beforehand.

Hours 18–24: Communicate, Document, and Prepare for What’s Next

By this point, leadership should have a clearer understanding of the situation, although the investigation may be far from finished.

Now documentation becomes even more important.

What happened?

When was it discovered?

What actions were taken?

Who was contacted?

Which systems were affected?

What decisions were made?

What remains unknown?

Depending on the circumstances, appropriate legal, compliance, insurance, regulatory, law-enforcement, forensic, and communications professionals may need to guide next steps.

Don’t guess about reporting obligations during a crisis.

Know ahead of time which professionals will help leadership determine what is required for the specific incident.

And don’t forget your employees.

People need clear instructions.

Tell them what they need to know, what they should do, and where questions should go.

Confusion creates risk.

Your Incident Response Plan Should Exist Before Day One

Here’s the mistake I want credit unions to avoid.

Don’t create a 75-page incident response document that nobody can find or understand when something actually happens.

The plan needs to be usable.

At minimum, leadership should know:

  1. Who declares an incident?
  2. Who leads the response?
  3. Who handles technical containment and recovery?
  4. Who contacts legal, insurance, compliance, and other outside resources?
  5. Who communicates with employees, the board, members, and other stakeholders when appropriate?
  6. Where is critical contact information stored?
  7. Which systems must be restored first?

Those seven answers can eliminate an incredible amount of confusion.

Run a Tabletop Exercise Before You Need the Plan

One of the most valuable things a credit union can do is surprisingly simple.

Get the appropriate people around a table for 60 to 90 minutes.

Then give them a scenario.

“It’s 8:12 Monday morning. Several employees can’t access files. Your technology team suspects ransomware. What happens next?”

Don’t make it a test where people are afraid of giving the wrong answer.

Make it a conversation.

Who makes the first call?

Can everyone access the incident response plan?

What if Microsoft 365 is unavailable?

Who contacts your insurance resources?

Who talks to the board?

What if your primary technology vendor can’t immediately respond?

What if the incident continues overnight?

Every uncomfortable question you uncover during a tabletop exercise is one less surprise during a real incident.

What Should the Board Know?

Your board doesn’t need to manage the cyberattack.

But it should understand the organization’s preparedness.

I would encourage board members to ask:

When did we last test our incident response plan?

What did we learn?

What are our biggest recovery risks?

Do we know who will lead the response?

Can we continue serving members if critical systems are unavailable?

Those are governance questions.

They don’t require a cybersecurity certification to ask.

Final Thoughts

The first 24 hours of a cyberattack will probably never go exactly according to plan.

That’s not the point.

The purpose of incident response planning is to prevent chaos from becoming your strategy.

Know who to call.

Know who’s in charge.

Know your critical systems.

Know how you’ll communicate.

Know where your backups are.

Know how you’ll recover.

And practice the plan.

After more than 26 years in technology, I’ve learned that organizations usually don’t rise to the complexity of an emergency.

They fall back on the preparation they did beforehand.

For a credit union, that preparation isn’t only about protecting computers.

It’s about protecting operations.

Protecting employees.

Protecting members.

And protecting the trust you’ve spent years building.

What Would Your Credit Union Do During the First 24 Hours?

If you’re not completely confident in the answer, that’s a conversation worth having before the incident.

At CTG, we help credit unions develop a practical approach to cybersecurity, incident response, ransomware recovery, business continuity, backup and disaster recovery, Microsoft 365 security, vendor coordination, and long-term technology planning.

For more than 26 years, CTG has helped organizations prepare for technology problems before they become emergencies. Our team brings more than 200 years of combined experience, and our vendor-agnostic approach keeps the focus on what is right for your organization.

We can help review your current incident response and recovery readiness, identify gaps, coordinate technology priorities, and help your leadership team prepare for the questions that matter.

Talk with CTG

Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net

Don’t wait until hour one of a cyberattack to decide what happens next.

Let’s build the plan—and practice it—before you need it.


Share:

Recent Blog Posts...