If a compromise is suspected, the immediate objective should be to contain the potential incident while preserving useful information.
A suspicious event does not always mean that a system has been hacked. The safest response is to slow down, establish what actually happened, protect important accounts, and preserve evidence before making significant changes.
Incident response checklist
10 things to do if you suspect a compromise
The right response depends on the circumstances, but these steps provide a practical starting point for protecting systems and preserving useful information.
-
Initial assessment
Do not assume the first explanation is correct
A slow computer, unexpected popup, failed login, or unusual network connection does not automatically mean that a system has been compromised.
Potential explanations include:
- Software failures
- Misconfigured services
- Automated Internet scanning
- Legitimate administrative activity
- Malware
- Credential compromise
- Unauthorized access
Recommended actionRecord the original symptoms and establish what actually occurred before making major changes to the system.
-
Containment
Disconnect an affected computer from the network
If there is strong evidence that a particular computer is compromised, disconnecting it from the network can prevent further communication with other systems.
Depending on the circumstances, this can mean:
- Disconnecting Ethernet
- Disabling Wi-Fi
- Moving the system to an isolated network
Preserve information firstAvoid immediately deleting suspicious files or reinstalling the operating system if an investigation may be necessary.
-
Account protection
Do not continue using a potentially compromised account
If the suspected incident involves an account, use a known-clean device to change the password.
Prioritize:
- Administrator accounts
- VPN accounts
- Cloud services
- Financial accounts
- Domain administration
- Password managers
If the same password was reused elsewhere, change those credentials as well. Enable multi-factor authentication wherever possible.
Use a known-clean deviceChanging credentials from a potentially compromised computer may expose the new credentials.
-
Evidence preservation
Preserve logs
Logs may contain information about what happened. Do not assume that logs will remain available indefinitely because some systems rotate logs quickly.
Potentially useful sources include:
- Firewall logs
- VPN logs
- Windows Event Logs
- Linux authentication logs
- DNS logs
- Web server logs
- Cloud authentication logs
- Endpoint security logs
- Email security logs
Recommended actionPreserve relevant logs before they are overwritten and record where each log source came from.
-
Investigation
Identify the earliest known suspicious activity
Establishing a timeline is often more useful than immediately trying to determine exactly who was responsible.
Determine:
- When the unusual activity was first observed
- Which account or device was involved
- Which IP addresses were involved
- Which services were accessed
- Whether authentication succeeded
- Whether additional accounts were created
- Whether files were modified
- Whether other systems show related activity
Recommended actionRecord times in a consistent time zone and preserve the original timestamps from the relevant systems.
-
Scope assessment
Check other systems
A compromised workstation does not necessarily mean that the entire network has been compromised. However, related systems should be reviewed for indicators of additional activity.
Review for:
- Authentication failures
- Successful logins
- New administrator accounts
- Unexpected processes
- New scheduled tasks
- Unusual outbound connections
- Unexpected DNS requests
- Modified configuration files
Recommended actionUse centralized logging where available to compare activity across multiple systems.
-
Communication
Do not communicate with an attacker
If ransomware, extortion, or an active intrusion is suspected, avoid communicating with the attacker unless there is a specific incident-response reason to do so.
Do not:
- Follow unknown instructions
- Install software provided by the attacker
- Provide credentials
- Provide remote access
- Delete evidence
- Attempt retaliation
Recommended actionPreserve messages, demands, filenames, contact details, and other evidence without following unverified instructions.
-
Specialist assistance
Consider professional incident response
A significant compromise may require specialized investigation, containment, evidence preservation, and recovery assistance.
Professional assistance may be appropriate when:
- Sensitive information may have been accessed
- Administrator credentials were compromised
- Multiple systems are affected
- Ransomware is involved
- Financial systems may be affected
- The attacker appears to have maintained persistent access
- The organization cannot determine what happened
Recommended actionRequest assistance early when the potential impact is significant or the organization lacks the resources to investigate safely.
-
Recovery
Restore carefully
Reinstalling an affected computer may remove malware, but it does not necessarily answer how the compromise occurred.
Before restoring systems, determine whether:
- The initial vulnerability remains
- Credentials remain compromised
- Other systems were affected
- Backups are trustworthy
- Persistence mechanisms were established
Important considerationIf the original cause is not addressed, the same compromise can potentially happen again after restoration.
-
Documentation
Document everything
Create an incident timeline containing the relevant facts, decisions, evidence, and actions taken.
Record:
- Date and time
- System
- Account
- Source IP
- Event
- Action taken
- Evidence collected
- Person responsible
Why this mattersDocumentation can become important for internal investigations, insurance requirements, legal matters, regulatory obligations, and future security improvements.
Investigation record
Build a simple incident timeline
A timeline helps separate confirmed facts from assumptions and shows how the incident developed.
First observation
Record what was noticed
Note the date, time, device, account, symptoms, and person who first reported the unusual activity.
Evidence review
Connect the event to available logs
Compare authentication, firewall, DNS, endpoint, cloud, and system events where available.
Containment
Record actions taken
Document disconnected systems, disabled accounts, changed credentials, preserved logs, and other response actions.
Recovery
Record what was restored and why
Note restored systems, verified backups, remaining risks, and improvements required before normal operations resume.
The goal of incident response
Contain the problem without losing the evidence
A suspicious event should be handled carefully. The priority is to limit further damage, protect important accounts and systems, preserve useful information, and determine whether additional systems or data may have been affected.
Once the immediate situation is under control, the organization can address the original weakness and improve monitoring, access controls, backups, and response procedures.
Security monitoring
Suspect unusual activity?
A managed security monitoring service can help identify suspicious authentication activity, network connections, intrusion attempts, and other security events before they become difficult-to-understand incidents.
Request a Security Assessment