Skip to content
Network Breach

Company network breach: contain it without destroying the evidence

An attacker is — or was — inside your network. Your next moves either preserve the ability to answer "what did they take?" or erase it permanently.

Company network breach: contain it without destroying the evidence — Response Red advisory illustration

The essentials

  • Containment and evidence preservation are one decision, not two: isolate systems, don't wipe them.
  • Rebuilding a compromised server before it is imaged destroys the record your insurer, regulator, and lawyers will ask for.
  • Move incident communications out of band immediately — assume the attacker reads your email and chat.
  • Scope before eviction: blocking indicators one at a time teaches the attacker to dig deeper footholds.
  • Start an incident log now — times, observations, actions, and who decided what.

A network breach puts two clocks on the wall. One is the attacker's: what else can they reach, take, or destroy? The other is legal and contractual: notification duties, insurance conditions, and customer commitments that start running whether you are ready or not.

The instinct is to rip everything out and rebuild. Resist it. The organizations that come through breaches well are the ones that contain deliberately — and can later prove exactly what happened.

Do this now

  1. Open an out-of-band channel and name a lead. Pick one incident lead and move coordination to phones or a messenger outside your corporate stack. Ambiguity about who decides costs more than most technical mistakes.
  2. Isolate, don't erase. Disconnect or segment affected systems and disable suspect accounts — but do not wipe, reimage, or "clean" anything. For virtual machines, snapshot with memory before touching them.
  3. Preserve the logs before they rotate. Extend retention and export now: VPN and firewall logs, identity-provider sign-ins, endpoint security alerts, and cloud audit trails. Rotation quietly destroys more breach evidence than attackers do.
  4. Restrict privileged access. Rotate administrator credentials from a known-clean device and revoke active privileged sessions. Sequence service-account changes carefully — breaking production mid-incident helps no one.
  5. Map the blast radius. List what the affected systems and accounts could reach: data stores, backups, payment systems, customer environments. This hypothesis directs both containment and your notification analysis.
  6. Engage responders and notify your insurer early. Professional scoping turns "we think they got in" into a defensible account of what was accessed. Cyber policies often require prompt notice and may mandate approved response vendors — late notice can cost you coverage.

What not to do

  • Do not mass-wipe or reimage machines before they are forensically preserved.
  • Do not announce the breach on email or chat systems the attacker may control.
  • Do not block indicators piecemeal as you find them — coordinate one decisive eviction after scoping.
  • Do not let administrators "look around" on affected hosts; every login contaminates the timeline.
  • Do not delay insurer notification while you investigate on your own.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • Forensic images or memory-inclusive snapshots of affected systems.
  • Exported logs: VPN, firewall, identity provider, endpoint security, cloud audit.
  • Network flow data covering the suspected intrusion window.
  • The incident log: timestamped observations, actions, and decisions.
  • An inventory of affected hosts and accounts as scoping evolves.

Keep a clear head

Breaches run for days, sometimes weeks. This is shift work, not a heroic all-nighter — enforce rest rotations for key staff from day one, because the judgment of an exhausted engineer at 3 a.m. is where second incidents come from.

Leadership's job is cadence: decisions at a steady rhythm, based on evidence, communicated calmly. Panic in the leadership channel travels to the keyboard within minutes.

Questions victims ask

Should we just shut everything down?

Rarely. Full shutdown destroys volatile evidence, can trigger contractual and operational damage, and tells the attacker they are discovered. Targeted isolation of affected segments achieves containment while keeping options open.

Do we have to tell anyone about the breach?

Often yes, on short clocks — GDPR's 72-hour supervisory notification is the best known, and contracts and sector rules add more. The decision needs counsel, but it runs on facts from scoping, which is why evidence preservation comes first.

How do we know if the attacker is still inside?

You usually can't be sure from the inside — persistence is designed to survive obvious cleanup. That question, more than any other, is what professional scoping answers before eviction begins.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.