Incident Response Planning: What to Do in the First 60 Minutes of a Breach
- echoudhury77

- 4 minutes ago
- 5 min read

It's 2:47 AM and your monitoring tool just flagged unusual login activity on a finance workstation. Do you know what happens next? For most small and mid-size businesses, the honest answer is: nobody's quite sure — and that uncertainty is where a manageable incident turns into a six- or seven-figure disaster.
According to IBM's 2026 Cost of a Data Breach Report, the global average cost of a breach has climbed to $4.99 million, with the U.S. average now sitting at $11.5 million — more than double the worldwide figure. The bigger problem isn't just cost, it's speed: organizations took an average of 247 days to identify and contain a breach in 2026 (183 days to spot it, another 64 to shut it down).
Businesses that got that full lifecycle under 200 days saved an average of $1.33 million compared to those that didn't. In other words, the first hour of a breach — not the first week — is often what decides whether the story ends with "we caught it" or "we made the news."
Yet fewer than two-thirds of mid-size companies have a formal, documented incident response plan. If you're one of the many businesses operating without one, here's what a real plan covers and what your team should actually be doing when the alert fires.
Why "We'll Figure It Out" Isn't a Plan
It's tempting to assume that a capable IT team can improvise its way through a security incident. The data says otherwise. Organizations with a tested incident response plan and a dedicated response team have historically identified breaches 54 days faster than those without either — and IBM has previously found that formal plans and teams together can cut breach costs by more than half. Speed compounds: every day an attacker sits undetected in your network is another day they can move laterally, exfiltrate data, or deploy ransomware.
An incident response plan isn't a binder that sits in a drawer. It's a rehearsed set of roles, decisions, and actions your team can execute under pressure, without arguing about who's in charge while the clock is running.
The Four Phases Every Plan Needs
The NIST SP 800-61 framework — the standard most managed security providers build around — breaks incident response into four operational phases. (NIST's newest revision folds these into its broader Cybersecurity Framework 2.0 governance structure, but the underlying sequence of actions hasn't changed.)
1. Preparation. This is everything you do before an incident: defining roles, maintaining an up-to-date asset inventory, deploying detection tools, setting up secure backups, and running tabletop exercises so the plan isn't being read for the first time during a real event.
2. Detection and Analysis. Spotting the signal in the noise — an odd login, an unusual outbound data transfer, a flagged endpoint — and quickly determining what you're actually dealing with: false positive, isolated incident, or active breach.
3. Containment, Eradication, and Recovery. Isolating affected systems to stop the spread, removing the threat (malware, compromised credentials, the attacker's foothold), and restoring operations from clean, verified backups.
4. Post-Incident Activity. The step most businesses skip — a structured lessons-learned review that feeds back into Preparation, closing the gap that let the incident happen in the first place.
What Should Actually Happen in the First 60 Minutes
When an alert comes in, the first hour sets the trajectory for everything that follows. A solid first-hour checklist looks like this:
Confirm and classify. Is this a real incident or a false positive? If real, what type — malware, unauthorized access, data exfiltration, ransomware? Classification determines everything downstream.
Activate the response team. Everyone should already know their role: who leads, who communicates with leadership, who handles technical containment, who documents the timeline.
Contain — don't destroy evidence. Isolate affected devices or accounts from the network immediately, but resist the urge to wipe or reimage anything yet. You'll need that evidence for root-cause analysis and, potentially, for insurers or regulators.
Preserve logs and communications. Start a running incident log the moment you're aware something is happening — timestamps matter for both remediation and any compliance or cyber insurance requirements.
Loop in leadership and, if needed, legal counsel and your cyber insurance carrier early — not after the situation is contained. Many policies require prompt notification, and legal counsel can guide decisions around disclosure obligations.
Hold off on public or customer communication until you understand scope — premature statements you have to walk back cause their own damage.
None of this works if it's the first time anyone has thought through these steps. That's what tabletop exercises and a documented plan are for.
AI Is Changing Both Sides of This Equation
One 2026 trend worth building into your plan: IBM found that roughly 1 in 4 malicious breaches now involve AI-enabled attacks — a 56% jump from the prior year — with deepfake and impersonation attempts making up nearly half of those. AI-enabled breaches also cost more on average ($6.04 million vs. $5.03 million for non-AI incidents). On the defensive side, organizations that extensively use security AI and automation cut their average breach cost by nearly $2 million and identified incidents 65 days faster than those with no automation at all. The takeaway: your incident response plan should assume attackers have AI-assisted tools in their kit, and your detection capability should too.
Building — and Actually Testing — Your Plan
A plan that's never been rehearsed is a plan that will fail under real pressure. At minimum, your incident response plan should be reviewed and tabletop-tested at least once a year, updated whenever your infrastructure or vendor stack changes, and paired with 24/7 monitoring so incidents are caught in minutes, not months.
This is exactly where most small and mid-size businesses run into a wall — building a NIST-aligned plan, maintaining round-the-clock detection, and having a team ready to respond at 2:47 AM isn't realistic to staff in-house. It's the gap managed detection and response (MDR) and 24x7 live support are built to close: continuous monitoring that catches the anomaly before it becomes a headline, a team that's already on the line when it matters, and — if the worst happens — a disaster recovery plan that gets you back online in hours instead of weeks.
If your business doesn't have a documented, tested incident response plan yet, that's the single highest-leverage security project you can start this quarter. Firestorm Cyber can help you build one, stress-test it, and back it with the monitoring and response capability to make sure it actually works when you need it.
Sources: IBM Cost of a Data Breach Report 2026; NIST SP 800-61 Rev. 2/3 Computer Security Incident Handling Guide.




Comments