Index / Investigation and response

Containment: The First Hour

kind
Procedure
domain
Casework
stage
Investigation and response
read
3 min
assumes
No prior programme in place

The decisions taken before anyone understands the situation, and how to avoid the ones that destroy the case.

The first hour of a suspected insider incident is where most cases are won or ruined. The pressure is to act; several of the obvious actions are the wrong ones.

Decide what you actually know

Before anything else: is this an insider acting deliberately, a compromised account, or a legitimate process nobody recognised?

The response diverges completely, and choosing wrong wastes the window. A compromised account needs immediate containment. A legitimate process needs nobody's attention. A deliberate insider needs preservation before any visible action.

When uncertain, preserve first and act second. Preservation is reversible; a tipped-off subject is not.

Preserve before you touch anything

Mailbox, home directory, endpoint state, relevant logs. Take copies, work from copies.

Do this before access changes, because revocation can trigger deletion, and because the state at the moment of discovery is what matters.

Extend log retention on the relevant systems immediately. Default retention is frequently shorter than an investigation, and evidence expiring mid-case is a common and entirely avoidable failure.

Record what you did and when. Contemporaneously.

The access decision

Whether to suspend access is the hardest early call and it needs to be made by someone authorised, not by whoever is on shift.

Arguments for immediate suspension: ongoing exfiltration, high-value data at risk, evidence of destruction.

Arguments against: it tells the subject you know, it may be premature if the explanation is innocent, and it disrupts someone who may have done nothing wrong.

The middle option, usually correct: narrow access to the sensitive categories while leaving ordinary access intact. Reduces exposure without announcing an investigation.

Have the authorisation path established in advance. Who can approve suspension, and how they are reached at 9pm on a Friday. Organisations that work this out during the incident lose hours.

What not to do in the first hour

Do not confront the person. It compromises the process, it may prompt destruction, and if there is an innocent explanation you have caused real harm.

Do not tell their manager reflexively. The manager may be involved, may tip them off inadvertently, or may act unilaterally. Confidentiality decisions belong to the investigation, not to reporting lines.

Do not remotely examine their machine while they are using it. It alters state and it can be visible to them.

Do not delete or block anything on their account. Preservation first.

Do not send email about it to a wide group. Insider cases leak, and the leak usually comes from the response.

Who to bring in

Legal, immediately, on anything that might become disciplinary or criminal. Their early involvement determines whether the evidence is usable.

HR, when a person's conduct is in question. They lead once it becomes an employment matter.

Not the whole security team. Restrict to those who need to know, and log who was told.

The compromised-account branch

If the working hypothesis is compromise rather than malice, containment is ordinary incident response and it is urgent: reset credentials, revoke sessions and tokens, check for persistence, look for lateral movement.

And tell the employee. They are a victim and they will help you. Treating them as a suspect while their account is being used by someone else wastes the fastest route to understanding what happened.

After the hour

Move from reaction to a defined investigation with scope, authorisation and documentation. The first hour is about not foreclosing options โ€” preserve, contain proportionately, get the right people involved, and avoid the actions that cannot be undone.