The First 72 Hours: What Really Happens When Your Organisation Is Breached
Published by the 0g0 research team
The first 72 hours after a confirmed cyber breach are the most critical period in your organisation's response. How you use those hours determines whether a security incident becomes a manageable disruption or an existential crisis. Yet most organisations — including large government agencies — discover through painful experience that their plans for this period are far less effective than they believed.
This is what actually happens, what needs to happen, and how the difference between those two things is measured in millions of dollars and months of recovery time.
Hour 0-4: Detection and Initial Response
The way an organisation discovers a breach matters enormously. The best case — and increasingly the norm for organisations with mature security programmes — is detection by internal monitoring systems, typically triggered by anomalous network traffic, unusual authentication events, or endpoint detection and response alerts. In this scenario, the response clock starts while the attacker may still be in the reconnaissance phase, before any data has been exfiltrated and before any encryption has occurred.
The realistic case for many organisations is discovery by an external party: law enforcement contacts your agency to inform you that your data is for sale on a criminal forum, a partner organisation flags unusual communications from your systems, or employees attempting to work discover that their files have been encrypted. In these cases, the attacker has likely been in the environment for weeks, has already completed their primary objective, and you are beginning your response from a position of maximum disadvantage.
Whatever the discovery method, the first four hours should accomplish:
Confirm the incident: Alert fatigue and false positives mean that not every unusual system event is a breach. However, confirmation efforts should be proportionate to the severity of the initial indicators. If endpoint tools are reporting encryption events, do not spend three hours trying to rule out a false positive — escalate immediately.
Activate your Incident Response Team: This means having a pre-defined team with clear roles, contactable at any hour. Security lead, IT operations lead, legal counsel, communications lead, and executive sponsor should all be reachable and aware within the first four hours.
Isolate, do not shut down: The natural instinct when discovering a breach is to shut everything down. Resist this instinct. Shutting systems down destroys volatile memory evidence that is critical for understanding the attack. Isolation — disconnecting affected systems from network access while keeping them powered — preserves evidence while limiting the attacker's ability to continue operating.
Preserve evidence: Before making any changes to affected systems, capture memory images, log files, and network traffic captures. Evidence collected in the first hours is the foundation of every subsequent investigation, legal action, and insurance claim.
Hours 4-24: Containment and Assessment
With the immediate crisis stabilised, the next phase is understanding the true scope of the incident. This is typically where organisations most significantly underestimate their situation. The visible impact — the encrypted files, the compromised mailboxes, the defaced website — is almost never the full extent of the intrusion.
Competent attackers establish multiple persistence mechanisms. They create additional administrative accounts, install backdoors in legitimate software, and compromise systems that are not obviously connected to their primary objective. Containment without comprehensive discovery leaves footholds in place that enable re-entry once the incident response effort relaxes.
This phase requires:
Network traffic analysis: Examine all outbound communications from the affected environment going back at least 30 days. Look for connections to unusual destinations, large data transfers, and beaconing patterns (regular small connections to external systems that indicate command-and-control communication).
Authentication log review: Every account that has authenticated to affected systems in the 30 days prior to detection should be considered potentially compromised. Look for lateral movement: a user account that normally only accesses their own workstation suddenly accessing file servers, domain controllers, or other systems it has no business reason to touch.
Scope definition: Define the confirmed blast radius — the systems and data you can confirm were accessed or modified — and the potential blast radius — the systems the attacker could have accessed given what you know about their initial foothold and the network architecture.
Stakeholder notification: Legal counsel should be engaged by hour 4 to advise on notification obligations. Many regulatory frameworks — HIPAA, various state breach notification laws, SEC rules for publicly traded companies — impose notification timelines measured in days or weeks from discovery. Missing these timelines has its own legal and regulatory consequences.
Hours 24-72: Eradication and Communication
Eradication means removing the attacker from your environment completely. This is harder than it sounds. Complete eradication typically requires rebuilding compromised systems from known-good images rather than attempting to clean them. It requires resetting all credentials — not just those you have confirmed were compromised, but all of them, because you cannot be certain which credentials the attacker accessed. It requires reviewing and removing all persistence mechanisms that forensic analysis has identified.
Communication during this phase must balance transparency with operational security. Premature or inaccurate public communication during an active incident can complicate law enforcement cooperation, enable attackers to adapt their techniques based on public reporting of what has been detected, and expose the organisation to legal liability if the communicated scope later proves inaccurate.
The communication framework should include:
- Internal communications to staff that inform without causing panic or enabling insider exfiltration
- Stakeholder communications to partners and customers whose data may be affected
- Regulatory notifications as required by applicable frameworks
- Law enforcement engagement if criminal activity is suspected (and in most significant incidents, it is)
- Public/media communications, drafted in advance and released only when the immediate crisis is stabilised
What Good Preparation Looks Like
Organisations that navigate the first 72 hours most effectively share several characteristics that are established long before an incident occurs:
A written, tested Incident Response Plan that assigns specific responsibilities to specific roles, with contact information, and has been rehearsed at least annually through tabletop exercises.
Pre-established relationships with external incident response support — because the worst time to select and onboard an incident response firm is during an active breach.
Logging and monitoring infrastructure that actually captures the data needed for forensic investigation. Many organisations discover during an incident that they lack the logs to answer basic questions about what the attacker did.
Pre-arranged legal and communications resources, including insurance policies that actually cover the response costs they will incur.
The Bottom Line
The difference between organisations that contain a breach in 72 hours and those still responding 72 days later is almost never the sophistication of the attackers. It is almost always preparation, monitoring capability, and the speed of the first response. These are things that can be built before an incident occurs, when the pressure is manageable and the time is available.
0g0 Aegis offers Incident Response planning and testing services specifically designed for government and enterprise organisations. We also provide 24/7 retainer-based IR support, so that when the call comes at 3am, there is an experienced team ready to respond immediately.
Need a product briefing?
Talk about the 0g0 Appliance for your environment — available now. Services are light support as the practice grows.
Request a BriefingFree Assessment Tools
Test your own security posture with our free tools — no account required.
Explore free toolsProtect your organisation
Request a briefing on the 0g0 Appliance. Research is context — the product conversation is next.
Request a Briefing