Checklist of actions following a cybersecurity incident

  • Defining critical assets, risks, and dependencies with third parties allows for prioritizing protection and incident response.
  • Strong access controls, encryption, training, and maintenance reduce the likelihood and impact of an attack.
  • Monitoring, a clear response plan, and a defined team are key to detecting, containing, and eradicating incidents in a timely manner.
  • Proven backups, business continuity, and cyber insurance strengthen the company's recovery and resilience.

Checklist of actions following a cybersecurity incident

Cybersecurity incidents have become commonplace for businesses of all sizes. Ransomware attacks, email scams, data breaches, and outages of critical services are no longer isolated cases, but a constant reality in today's business environment.

Although defensive technologies have advanced significantly and mature frameworks like NIST exist, many organizations still lack clear prevention policies and, above all, a practical checklist of actions to take immediately after an incident. That moment is crucial: what you do (or don't do) in the first few hours makes the difference between a controlled scare and an operational, financial, and reputational disaster.

What is a cybersecurity incident and how to recognize it

A cybersecurity incident is any event that affects the confidentiality, integrity, or availability of an organization's information or systems. It can result from a deliberate attack (malware, intrusions, fraud) or from human error and technical failures that ultimately open doors for cybercriminals.

To consider it an incident, it is enough that one of these three main pillars is compromised: that data is accessed without permission, that systems or information are altered improperly, or that services cease to be available when the company needs them.

Key indicators to determine if an incident has occurred

When assessing whether you are facing a real incident, it is advisable to check if any of these situations have occurred, which are common parameters for triggering alarms :

  • Confidentiality at risk: unauthorized access to databases, customer histories, financial information, or sensitive documentation.
  • Altered integrity: changes to files, settings, or applications that no one on the team recognizes as their own.
  • Availability committed: critical service outages, extreme slowness, or complete shutdown of key systems.
  • Improper access: logins from unusual locations or times, or with accounts that should be deactivated.
  • Data loss or destruction: files missing, encrypted or damaged without apparent explanation.
  • Abnormal activity: strange processes, unexplained spikes in network traffic, or mass emails sent from a compromised account.
  • Exploitation of security flaws: Exploitation of known or newly discovered vulnerabilities in software or hardware.

Common examples of security incidents

Management teams often have a better understanding of risk when they are aware of specific incidents that occur daily in companies across all sectors:

  • Identity Theft: obtaining credentials, personal or banking data to impersonate employees, suppliers or managers.
  • Phishing and mail fraud: Messages that impersonate banks, providers, or the address itself to obtain transfers or steal passwords.
  • Malware and ransomware: Malicious software that encrypts information, steals data, or leaves backdoors open without the user noticing.
  • DDoS attacks: Saturation of websites, online stores, or services exposed to the Internet so that they become unusable for legitimate customers.
  • Exploitation of vulnerabilities: Exploitation of vulnerabilities in outdated applications, operating systems, or network devices.
  • Network intrusions: unauthorized remote access to servers, user equipment, or network devices.
  • Loss or theft of devices: Laptops, mobile phones, or external hard drives with critical information that disappear without being encrypted.
  • Data exfiltration: Silent extraction of databases or documents by external attackers or disgruntled employees.
  • Social engineering: Direct manipulation of people (telephone, mail, messaging) to obtain access, codes or internal information.
  • Internal fraud: malicious use of privileges by personnel with access to sensitive information or systems.

Complete checklist based on the 5 NIST functions

To organize the response to incidents, it is advisable to rely on a recognized framework such as that of the NIST (National Institute of Standards and Technology) , which organizes cybersecurity into five major functions: Identify, Protect, Detect, Respond and Recover.

The following checklist is designed to allow management and the technical team to quickly assess the company's level of preparedness and, if necessary, know what steps should have been covered before, during, and after the incident.

1. Identify (ID): know what you have and what hurts the most

The first line of defense is to clearly identify which assets are critical and what risks affect them . If you don't know what you have, it's impossible to protect it properly or react in time.

Inventory of critical assets and data

  • Maintain an up-to-date inventory of hardware, software, cloud services, and industrial or business-specific systems.
  • Identify and expressly record which data are sensitive: personal information, financial information, intellectual property, contracts, etc.
  • Assign a responsible party or owner to each asset to facilitate decision-making during an incident.
  • Classify assets and data by criticality (high, medium, low) according to their impact on the business.
  • Review this inventory periodically to ensure it does not become obsolete when the infrastructure changes.

Risk, threat and vulnerability analysis

  • Perform regular vulnerability assessments on servers, workstations, networks, and applications.
  • Analyze both external threats (cybercriminals, organized groups) and internal threats (errors, privileged personnel).
  • Estimate probability of occurrence and potential impact to prioritize efforts.
  • Sort the vulnerabilities by risk level and plan their correction.
  • Document findings and share them with management to align technical and business decisions.

Dependencies on third parties and suppliers

  • Identify which services and data depend on technology providers, integrators, or partners.
  • Verify the security of VPN connections, remote access, and cloud services managed by third parties.
  • Include cybersecurity clauses and response times in service level agreements (SLAs).
  • Review the security maturity level of these third parties with some frequency.
  • Integrate these dependencies into risk management and business continuity plans.

Classification by criticality of systems and information

  • Define clear criteria to decide what is critical, important, or dispensable in the short term.
  • Label information and systems according to that classification and apply differentiated measures to it.
  • Adjust access permissions and backups to the defined criticality.
  • Review this classification when there are relevant business or technological changes.
  • Communicate the importance of this classification to all staff, not just the IT team.

2. Protect (PR): preventive barriers before the incident

Once you know your assets and risks, it's time to deploy protection controls that reduce the likelihood of a serious incident or at least limit its scope.

Access and identity controls

  • Implement robust password policies and mandatory rotation on critical systems and applications.
  • Apply role-based access control, preventing accounts with excessive permissions.
  • Configure multi-factor authentication (MFA) on email, VPN, admin panels, and essential business tools.
  • Regularly review which users have what access and justify elevated privileges.
  • Immediately deactivate accounts of employees who leave the organization or change roles.

Encryption of information in transit and at rest

  • Protect communications with secure protocols (SSL/TLS) on exposed websites, VPNs, and internal services.
  • Use strong encryption (e.g., AES) for laptop disks, servers, and backups.
  • Configure encryption for emails that contain personal data or particularly sensitive information.
  • Periodically audit that encryption is applied where it is truly needed and is working.
  • Train users in the proper handling of encrypted information and which channels they should use.

Training and awareness of staff

  • Design a continuous training program on phishing, passwords, device usage, and data handling.
  • Conduct at least one annual training session for all staff, with clear materials and real-world examples.
  • Organize phishing simulations to measure the level of exposure and correct bad habits.
  • Evaluate content assimilation with short tests or questionnaires.
  • Update training based on new threats, regulatory changes, or incidents experienced.

Maintenance, patching and hardening of systems

  • Define a schedule for updating operating systems, applications, and firmware of network devices.
  • Apply priority security patches as soon as it is business feasible.
  • Review default settings and disable unnecessary services or open ports.
  • Perform regular configuration audits and security tests.
  • Document critical changes and communicate them to the parties involved to avoid surprises.

3. Detect (DE): to find out in time that something is wrong

Time is of the essence in a cybersecurity incident. That's why it's crucial to have monitoring and alert mechanisms in place to detect suspicious behavior before the damage becomes irreparable.

Intrusion detection systems (IDS/IPS) and SIEM

  • Deploy IDS/IPS solutions capable of analyzing network traffic and blocking malicious patterns.
  • Integrate these systems with a SIEM platform that centralizes security logs and events.
  • Monitor traffic in real time and set up dashboards with key indicators.
  • Conduct regular effectiveness tests to ensure that the rules detect current threats.
  • Keep detection signatures and reputation lists up to date.

Log management and analysis

  • Centralize server logs, firewalls, critical applications, and cloud systems in a SIEM or similar tool.
  • Define appropriate retention times to be able to investigate incidents with a historical perspective.
  • Analyze logs automatically to look for anomalous or repetitive patterns.
  • Configure alerts based on well-thought-out rules to reduce false positives.
  • Manually review summaries and periodic reports to detect worrying trends.

Alerts, notifications, and trigger criteria

  • Establish clear thresholds for generating alerts: failed login attempts, configuration changes, unusual traffic, etc.
  • Configure notifications to the appropriate people based on the severity of the event.
  • Define a workflow for each type of alert, ensuring that none go unattended.
  • Test and periodically adjust the sensitivity of the alerts so that they are useful and not ignored.
  • Document what alerts exist and who is responsible for responding to each one.

Screening tests and internal exercises

  • Simulate cyberattacks (network team exercises, phishing, ransomware simulations) to verify detection capability.
  • Organize incident response exercises with participation from IT, communications, legal and management.
  • Measure detection, reaction, and recovery times during these drills.
  • Record results and areas for improvement identified during testing.
  • Adjust tools, procedures and training based on lessons learned.

4. Respond (RS): what to do when the incident has already occurred

Once an incident is confirmed, the company needs a clear plan, a defined team, and a script of action that avoids chaos and improvisation.

Formalized Incident Response Plan

  • Have a document that describes step by step what is done from the moment an incident is detected until it is closed.
  • Define severity levels and types of incidents (personal data, continuity, fraud, etc.).
  • Include in the plan how to scale internally and how to notify key suppliers or partners.
  • Review and update this plan at least once a year or after a major incident.
  • Ensure that the plan is available even in the event of an internal system failure.

Incident Response Team (IRT/CSIRT)

  • Appoint an incident manager to coordinate decisions and serve as a single point of contact.
  • Assign specific functions (technical analysis, communications, legal/compliance, relationship with insurer, etc.).
  • Have an up-to-date contact list with alternative phone numbers and email addresses.
  • Train the team in forensic tools, containment procedures, and crisis management.
  • Conduct regular drills to check the team's readiness and coordination.

Containment and eradication of the threat

  • Act quickly but without rushing to isolate affected systems (segmentation, network disconnection, user blocking).
  • Collect evidence (logs, disk images, traffic captures) following forensic criteria.
  • Apply corrective actions to remove malware, close gaps, and fix vulnerable configurations.
  • Verify that the threat has truly been eradicated before returning to normal.
  • Document each action taken and who authorized it, also considering future analyses or possible claims.

Incident recording, analysis, and reporting

  • Record chronologically when it was detected, how it was identified, which systems were affected, and what impact it had.
  • Notify internal stakeholders (management, area managers) clearly and without unnecessary technical jargon.
  • Assess whether it is mandatory to inform authorities (for example, in the case of personal data) or affected customers and suppliers.
  • Prepare a post-incident report with root causes, economic impact and proposed preventive measures.
  • Update the response plan and security policies by integrating lessons learned.

5. Recover (RC): to resume safe operation

Once the most critical phase is over, it's time to restore systems, resume operations, and strengthen resilience for the next incident (because, whether we like it or not, there will be more).

Business continuity and disaster recovery plans

  • Having a continuity plan that prioritizes which processes should be restored first and within what timeframes.
  • Define disaster scenarios (serious cyberattack, data center failure, cloud provider unavailability, etc.).
  • Allocate the necessary human and technical resources for each phase of the recovery.
  • Test these plans periodically through realistic simulations.
  • Adjust RTO (Recovery Time Objective) and RPO (Restore Point) to the reality of the business.

System and data restoration

  • Define clear procedures for restoring servers, applications, and databases from backups.
  • Prioritize the recovery of systems identified as critical in the Identify phase.
  • Verify the integrity of the restored data and check that the malware does not run again.
  • Introduce additional measures (segmentation, MFA, firewall rules) when bringing systems up.
  • Record all restoration steps for reuse in future incidents.

Impact assessment and continuous improvement

  • Calculate the overall cost of the incident: downtime hours, data loss, potential penalties, and reputational damage.
  • Identify the technical, organizational, and human areas that have failed or performed worse than expected.
  • Define an action plan with concrete measures, responsible parties and deadlines to raise the level of security.
  • Incorporate changes in policies, procedures, and technological solutions based on real-world experience.
  • Review cybersecurity budget and investment priorities with management.

Communication with stakeholders during recovery

  • Inform management, business officers and, where appropriate, customers and suppliers about the progress of the recovery.
  • Establish specific channels (email, intranet, emergency phone) for questions and updates.
  • Avoid prolonged silence so as not to increase distrust or fuel rumors.
  • Coordinate messages with the legal department and, if available, with corporate communications or public relations.
  • Document how everything has been communicated to use it as a basis in future crises.

Executive checklist: points that management should review

For senior management, it is key to have an executive vision that allows them to ask the right questions to the IT team or supplier without getting into too much technical jargon, but with a focus on the real risk.

This executive checklist is organized into areas that any company, whether or not it has its own IT department, should review to minimize the risk of suffering a serious incident.

Perimeter protection and network

A poorly segmented network without an advanced firewall is practically an open door to external attackers . The perimeter layer remains essential, especially when services are exposed to the internet.

  • Next-generation firewall with properly configured IPS, web filtering, and network antivirus.
  • Network segmentation using VLANs to separate departments, production, guests, and critical systems.
  • Secure VPNs for remote access, always protected with robust authentication and MFA.
  • Periodic review of firewall rules to remove obsolete or overly permissive access.
  • Continuous traffic monitoring and detection of suspicious patterns.

Endpoint and server security

Many incidents originate on a neglected user's computer or an unpatched server . Having a consistent security policy is essential.

  • Centralized corporate antivirus, with automatic updates and uniform policies.
  • Advanced anti-spam filters in email to reduce the entry of phishing and malware.
  • Active patch management in operating systems and business applications.
  • Mobile device management (MDM) solutions to control access from smartphones and tablets.
  • Strict control of privileges, limiting the use of administrative accounts to the bare minimum.

Identity, access, and MFA

Attackers typically target credentials because they are, in practice, the organization's master key . Identity and multi-factor authentication are no longer optional.

  • MFA enabled on corporate email, VPN, admin panels, and critical tools.
  • Strong password policies, with expiration dates and a ban on reusing old passwords.
  • Periodic review of user permissions, detecting and correcting improper privileges.
  • Immediate deactivation of accounts of staff who leave the company or change roles.
  • Logging and auditing of access on key platforms (ERP, CRM, email, production systems).

Backup and recovery

Without reliable and tested backups, a ransomware attack can cripple a business . Backups are the last line of defense.

  • Automated backups and stored outside the main system (another data center, cloud, isolated storage).
  • Hybrid backup strategies (local + cloud) to combine speed and resilience.
  • Regular restoration tests, at least monthly, to confirm that the backups are usable.
  • Encryption and strict access control to the backup repository.
  • Documented recovery plan following a cyberattack or technical disaster, with assigned responsibilities.

24/7 monitoring and response

An unmonitored environment is practically a system that operates blindly . Many attacks occur outside of business hours, when no one is watching.

  • Real-time monitoring of servers, networks, applications, and cloud services.
  • Automatic alerts for crashes, abnormal access, consumption spikes, or suspicious changes.
  • Correlated analysis of security events to detect complex attacks.
  • Periodic reports for management with status, detected incidents and recommendations.
  • Clear procedures for responding to critical alerts, with well-defined responsibilities.

Safety training and culture

The human element remains the weakest link. No matter how good the firewall is, if someone clicks where they shouldn't , everything gets complicated. Internal culture makes all the difference.

  • Annual training program for all staff on phishing, secure use of devices and data protection.
  • Internal phishing simulation campaigns to measure the real risk.
  • Clear protocols on how to act in the face of suspicious emails or attachments.
  • Internal rules for the use of personal devices, remote access, and information storage.
  • Confidentiality agreements and data protection commitments signed by employees.

Audit and continuous review

Without periodic review, it is impossible to know if the company is still truly protected or has fallen behind in the face of new threats.

  • Annual audit of systems, networks and security policies, internal or with external support.
  • Periodic review of privileged accounts, external access, and special permissions.
  • Updated risk assessment and prioritized action plan.
  • Up-to-date IT inventory, with identification of critical and obsolete applications.
  • Report to management with conclusions, risks and investment proposals in security.

Case study: real impact of an incident on an SME

To better understand what all this entails, it is worth reviewing a very typical example: an industrial SME suffers a ransomware attack that enters through a phishing email that bypassed an outdated antivirus.

The network was flat, without segmentation, and MFA had not been implemented in corporate email or productivity tools. The attacker managed to move laterally, encrypt several servers, and paralyze production for two full days, generating direct losses exceeding €10.000-€12.000 , not including reputational damage.

Following the incident, the company decided to implement:

  • A next-generation firewall with revised policies and hardened rules.
  • Centralized corporate antivirus and enterprise-level antispam filtering.
  • Multi-factor authentication for email, VPN, and critical business applications.
  • 24/7 monitoring with security log analysis and automated alerts.

In the following months, the organization saw incidents decrease dramatically , response times improve, and customer and supplier confidence in its resilience capacity increase.

Incident management, key tools, and the role of cyber insurance

Beyond prevention, every company should have a well-structured incident management plan and tools that facilitate the effective detection, analysis, and response to attacks.

Phases of an incident management plan

A good incident management plan is usually based on several linked stages that mark the complete incident cycle, from before it occurs to subsequent learning.

  • Preparation: Definition of policies, roles, training and procedures to activate in case of an incident.
  • Detection and analysis: continuous monitoring to detect signs of attack and assess its scope and criticality.
  • Containment and mitigation: isolation of affected systems, change of credentials, restriction of access.
  • Eradication: Removal of malicious elements, closing of vulnerabilities, and coordination with external specialists if necessary.
  • Recovery: Restoration of services and data from reliable backups.
  • Learned lessons: Post-incident analysis to correct weaknesses and improve existing plans.

How to act step by step in the event of a cyberattack

When an attack is already underway, it is crucial to follow a sequence of actions that combines calmness, method, and speed :

  • Stay calm and avoid impulsive decisions that could worsen the problem.
  • Activate the incident management protocol and assemble the designated team.
  • Identify the type of attack (phishing, ransomware, data breach, DDoS, etc.).
  • Assess severity and scope, documenting evidence from the very beginning.
  • Implement the response plan and begin containing the attack.
  • Analyze the origin and trajectory of the incident within the network or systems.
  • Proceed to eradicate the threat using the available tools.
  • Recover systems and data from clean backups.
  • Notify suppliers, authorities and affected parties when required by regulations (e.g., GDPR).
  • Assess damages and document the incident in a detailed report.
  • Review and update cybersecurity measures to close the detected vulnerabilities.

Tools and resources for effective management

To ensure that all of the above doesn't just remain on paper, it's important to rely on technological solutions and specialized resources that facilitate the work:

  • Monitoring and alert systems that supervise the infrastructure for anomalies.
  • SIEM platforms for centralized security event management.
  • Advanced firewalls, EDR/XDR and forensic analysis tools for investigating incidents.
  • Managed cybersecurity services (24/7 SOC) for companies without a large in-house team.
  • External CSIRT/IRT teams that provide experience, methodology and support in critical moments.

The role of cyber risk insurance

In a context of increasing incidents, more and more organizations are turning to cyber risk insurance to mitigate the economic and operational impact of a major attack.

These types of policies can cover, among other things:

  • Incident response costs and specialized technical support.
  • Costs of data recovery, system repair and service restoration.
  • Liability for privacy breaches, regulatory sanctions, and legal proceedings.
  • Costs of notifying affected parties and reputational damage mitigation campaigns.
  • Loss of profit resulting from business interruption.
  • Payments related to cyber extortion are always under strict supervision and in compliance with the law.

In addition, some policies include extra coverage such as compensation for court appearances, compensation for employees in certain cases, advertising expenses to manage the crisis, or extended discovery periods.

After reviewing all these elements, it is clear that no organization is completely safe from suffering a cybersecurity incident, but it can greatly reduce its impact with a solid checklist, a well-rehearsed incident management system, appropriate tools, and, when it makes sense, the support of a good cyber insurer. Those who work on these points in advance will be in a much better position when the next attack arrives, which is not so much a remote possibility as a matter of time.

Cloud incident response plan for Azure and Microsoft 365
Related article:
Cloud incident response plan for Azure and Microsoft 365

Add as preferred source in Google