Recognize and declare
Treat these signals as an incident when they cross an authorization, confidentiality, integrity, availability, or safety boundary.
- Unusual downloads, exports, queries, archives, sync, sharing, or outbound transfers
- Sensitive data reaches an unauthorized tenant, identity, repository, model, or destination
- DLP, database, SaaS, cloud, proxy, or endpoint telemetry indicates collection and staging
Preserve the evidence
Collect authoritative records before destructive cleanup whenever operationally safe. Record source, collector, UTC time, integrity hash, access, and retention decision.
- Authoritative data-access, query, object, file, SaaS, and application audit logs
- Proxy, DNS, firewall, CASB, DLP, endpoint, email, and cloud egress records
- Classification, ownership, retention, jurisdiction, tenant, and affected-subject metadata
- Files, archives, hashes, row counts, query text, destination, identity, and UTC timeline
IR-04 · FIRST 15 MINUTES
Reduce immediate uncertainty
- Stop the confirmed egress channel with the narrowest effective block.
- Preserve access and transfer logs, affected-object metadata, queries, and endpoint state.
- Secure involved identities, tokens, applications, shares, links, and destinations.
- Identify data owner, classification, jurisdictions, subjects, and notification stakeholders.
- Separate confirmed transfer from accessed, staged, attempted, and merely reachable data.
Contain → eradicate → recover
PHASE / 01Contain
- Disable unauthorized sharing, exports, sync, API access, and public exposure.
- Block destinations and revoke sessions while retaining investigative access to logs.
- Apply temporary monitoring or approval to equivalent bulk-access paths.
PHASE / 02Eradicate
- Close the initial-access and authorization failure; remove persistence and exposed credentials.
- Revoke shared links, cached credentials, API keys, and third-party access.
- Correct classification, tenant-boundary, retention, and least-privilege control failures.
PHASE / 03Recover
- Restore business access in stages with monitoring and volume controls.
- Validate the exposure calculation with data, legal, privacy, and business owners.
- Document confirmed facts, uncertainty, decision rationale, notifications, and residual risk.
Decision gates
Record the owner, evidence, uncertainty, operational impact, and rollback condition at every transition.
Scope gate
Confirmed transfer is distinguished from access, staging, attempts, and theoretical reach.
Containment gate
Ongoing access and egress are stopped without destroying authoritative evidence.
Recovery gate
Data owners approve scope, notification decisions, controls, monitoring, and residual uncertainty.
Rollback safeguard: define the last known-good state, measurable failure signals, accountable decision owner, and fastest safe return path before restoring service.
AUTHORSHIP & REVIEW
How to trust and adapt this guide
- Author & accountable editor
- Leandro Rocha
- Version
- 1.0
- Published / reviewed
- 18 August 2026
- Review status
- Maintainer-reviewed; independent peer review is not claimed.
Reference basis
- NIST SP 800-61 Rev. 3
- NIST CSF 2.0
- Applicable privacy, contractual, and breach-notification requirements
Assumptions
- The organization has authorized incident leadership, protected communications, and access to relevant telemetry.
- Actions are adapted to business impact, legal obligations, architecture, and available evidence before execution.
Limitations
- This field guide is not a substitute for organization-specific legal, privacy, safety, regulatory, or business-continuity advice.
- Vendor interfaces and log availability vary by product, plan, region, configuration, and retention period.