Incident Response
The RiskPart 2 of 4

The First 24 Hours: What Actually Happens During a Breach

What actually happens during a breach.

4 min read

Most people's mental picture of a security incident comes from movies: a dramatic alert, a scramble of experts, a resolution within the hour. The real version looks nothing like that, and the gap between expectation and reality is exactly where organizations make their worst decisions.

Here is a more honest timeline of what the first 24 hours of a real incident tend to look like.

Hour 0

The discovery is rarely clean

Incidents are almost never discovered the way people expect. It is not usually a security tool flashing red. More often it is a staff member noticing something odd: files renamed with strange extensions, an email that went out that nobody remembers sending, a vendor calling to ask why they got an invoice from an address that looks slightly wrong. By the time anyone realizes what is happening, the attacker has often had access for days, sometimes weeks or much longer.

This delay is normal, and it is worth knowing that in advance so the first reaction is not panic about how long the attacker was inside, but focus on what to do next.

Hours 1–6

Confusion, not clarity

The next few hours are usually the hardest, not because of technical complexity, but because of ambiguity. Nobody is fully certain what happened, how far it spread, or what data was touched. People are starting to ask questions that cannot yet be answered: is this ransomware or something else? Did they get customer data? Do we need to shut everything down?

This is precisely the period where a named decision-maker matters most. Without one, these hours fill with parallel conversations, conflicting instructions, and delay. With one, the organization can make imperfect but timely calls: isolate this system, preserve that log, call this number, while the full picture is still forming.

Hours 6–12

The outside world shows up

Somewhere in this window, the incident usually stops being internal. A ransomware note names a deadline. An insurance carrier needs to be notified, often within a specific window defined by your policy. Legal counsel starts weighing in on notification obligations, some of which have strict statutory clocks attached, particularly for organizations holding health, financial, or donor data.

This is also when the instinct to keep everything quiet collides with the reality that quiet rarely lasts. Staff talk. Clients notice outages. Speculation fills the silence faster than facts do.

Hours 12–24

The shape of the decision emerges

By the end of the first day, most organizations have a rough sense of scope, even if details are still developing. Decisions start to firm up: whether to pay a ransom demand, what to tell clients or donors and when, whether law enforcement should be involved, how operations continue in the meantime.

None of these decisions are improved by exhaustion, and most organizations reach this point running on very little sleep. This is the strongest argument for preparation. A plan made in a calm afternoon produces better decisions than judgment exercised at hour eighteen of a live incident.

Why this matters before it happens

Walking through this timeline in advance does something subtle but important: it removes the shock value from the experience. Organizations that have thought through this sequence, even briefly, tend to move faster and make calmer decisions than organizations encountering all of this for the first time in real time.

A plan made in a calm afternoon produces better decisions than judgment exercised at hour eighteen of a live incident.

Next week's post gives you a sequenced plan that maps directly onto this timeline: who decides, who you call, what you tell people, and what you preserve, so that when hour one arrives, you are executing a plan instead of inventing one.

Ready for a clearer picture of where you actually stand?

A 30-day Security Business Review gives you a clear picture of your highest-priority gaps and a practical roadmap you can act on. No enterprise complexity. No vendor pitches. Just defensible decisions.

Start a Conversation
Incident Response Breach Timeline Ransomware Small Business Nonprofit