# Initial Incident Checklist

Incident ID: __________  Lead: __________  Opened (UTC): __________

## First 15 minutes

- [ ] Validate the signal and record the original alert, source, and UTC timestamps.
- [ ] Assign an incident lead, scribe, severity, and protected coordination channel.
- [ ] Identify affected identities, endpoints, applications, cloud resources, and business services.
- [ ] Preserve volatile or short-retention evidence before taking disruptive action.
- [ ] Record current hypotheses and confidence; separate known facts from assumptions.

## First 30 minutes

- [ ] Establish the earliest known activity and build an initial UTC timeline.
- [ ] Search for related indicators and behaviors across identity, endpoint, network, cloud, and SaaS telemetry.
- [ ] Determine whether privileged access, data access, persistence, or lateral movement is present.
- [ ] Identify containment options, operational risk, reversibility, authority, and evidence impact.
- [ ] Engage legal, privacy, communications, insurer, or law enforcement when thresholds are met.

## First hour

- [ ] Approve and execute containment; record operator, command/action, target, and UTC time.
- [ ] Confirm containment took effect and monitor for displacement to other systems.
- [ ] Set the next technical and stakeholder update times.
- [ ] Preserve queries, results, exports, hashes, and decision records in the case repository.

Never destroy, wipe, reimage, or disclose externally without documented authority.
