Assign responsibility before discussing technology.
The plan should name who coordinates technical work, business decisions, communication and external support. Staff must know how to reach these people even if normal systems are unavailable.
Isolate affected systems in a controlled way.
Disconnect compromised devices from networks to limit spread, while avoiding indiscriminate shutdowns that may destroy volatile evidence. The appropriate action depends on the situation and should be coordinated.
Protect backups before restoring.
Confirm that backup repositories and administrative accounts are not still exposed. Starting recovery while attackers retain access can compromise the restored environment as well.
The plan must be exercised.
A tabletop exercise reveals missing phone numbers, unavailable credentials and unclear authority before a real incident. Combine the plan with tested backup recovery.
Prepare communication outside normal systems.
Keep independent contact lists and an agreed channel for management, IT, insurers, legal advisers and service providers. Avoid conflicting instructions and unverified public statements.
Preserve evidence and a timeline.
Record times, messages, affected systems and actions taken. Uncoordinated cleanup can remove information needed for analysis, recovery and later reporting.
Do not change every password blindly.
Password changes may be necessary, but changing them on a compromised device can expose the new credentials. Identify affected accounts and use a trusted system in a coordinated sequence.
Close the cause after recovery.
Restored files do not mean the incident is over. Identify and secure entry points, vulnerable systems and compromised accounts before declaring the environment trustworthy again.
