Cybersecurity & governanceEmergency IR · forensics

When an attack hits, the first hour shapes everything after

Incident response and digital forensics to contain spread, evict attackers, preserve evidence insurers and regulators expect, and restore operations from clean copies — not panic clicks that erase the trail

Ransomware, business email compromise, and stolen cloud credentials need a practiced response — not improvisation by whoever is available. Manage IT NY helps firms isolate affected systems, hunt for persistence, document chain-of-custody evidence, coordinate with cyber insurance and counsel, and return to service from verified backups. Retainer clients typically target triage within about an hour of engagement; exact clocks depend on contract scope, severity, and how quickly you can reach us — targets, not guarantees.

Technology partners

  • ThreatLocker logo
  • SentinelOne logo
  • Fortinet logo
  • NinjaOne logo
  • Barracuda logo
  • Microsoft 365 logo
  • Google Workspace logo

Incident response is not the same as everyday IT support

Help desk tickets fix printers, reset passwords, and restore a deleted file. Incident response is a different discipline: stop active harm, preserve volatile evidence, hunt for how the attacker got in, and coordinate legal and insurance timelines. Calling your regular MSP to "take a look" without isolation playbooks often means rebooting the one machine that still holds memory artifacts — or leaving a compromised OAuth session active while files encrypt.

Most firms need both layers — daily IT for operations and a documented IR path for when credentials, encryption, or wire fraud appear. Manage IT NY provides emergency containment and forensics alongside the managed detection and immutable backups that reduce how far an incident spreads before someone answers the hotline.

The first 60 minutes — what to do and what not to do

These steps buy time for forensics and reduce how far ransomware or wire fraud spreads. They are not a substitute for a retainer or emergency engagement — but they protect evidence and people while help is on the way.

Do

  • Call your incident response hotline or Manage IT NY at (631) 557-0440 — say 'possible breach' and who is affected.
  • Isolate affected machines from the network (unplug Ethernet or disable Wi‑Fi) — do not power off unless instructed.
  • Preserve what you see: ransom notes, sender addresses, odd login alerts, and screenshots with timestamps.
  • Notify leadership, counsel, and your cyber insurance carrier per your policy — many require prompt notice.
  • Stop shared passwords and force password resets only when IR advises — rushed resets can alert the attacker.

Do not

  • Do not reboot servers or wipe laptops to 'fix' encryption — RAM and logs may hold patient-zero evidence.
  • Do not pay ransom or engage attackers before counsel and IR assess options and backup viability.
  • Do not log into cloud admin portals from the same compromised workstation — use a clean device.
  • Do not delete email threads or 'clean up' files — that complicates forensics and insurance claims.

Four-step incident response workflow

Triage and isolation → forensics and hunting → eradication and rebuild → recovery and reporting. Manage IT NY runs this sequence with plain-language updates for leadership — not only technical tickets. Timelines vary by environment size, scope of encryption, and how segmented your network is; the stages below are the teaching order, not a promise that every phase finishes in a fixed window.

Triage → forensics → eradication → recovery

ACTIVE INCIDENT
      │
      ▼
① TRIAGE & ISOLATION ──► stop spread · preserve RAM/logs · notify IR/counsel
      │
      ▼
② FORENSICS & HUNTING ──► patient zero · C2 · OAuth/mailbox rules · scope
      │
      ▼
③ ERADICATION & REBUILD ──► evict persistence · rebuild AD/M365 · harden
      │
      ▼
④ RECOVERY & REPORTING ──► clean restore · insurance/legal brief · lessons

Read top to bottom with partners. SLA targets (such as triage within about an hour for retainer clients) depend on contract, severity, and reachability — they are goals, not guarantees.

Stage 1

Triage and isolation

Confirm the incident, isolate affected hosts and accounts, preserve volatile evidence, and open a written timeline. Retainer clients typically target engagement within about one hour of the emergency call — actual response depends on contract, after-hours reachability, and severity.

Emergency IR — (631) 557-0440

What emergency incident response covers

Containment, forensics, cloud eradication, and clean recovery — one coordinated program

Manage IT NY designs IR as outcomes you can explain to partners and carriers — not a menu of hourly tasks without accountability.

  • Emergency containment

    Stops this failure mode: encryption spreading while someone waits for Monday IT

    Network isolation, host quarantine, session revocation, and account disablement — executed with a written timeline from the first call, not ad hoc remote desktop sessions.

  • Digital forensics and evidence

    Stops this failure mode: 'we think it was ransomware' with nothing to show counsel

    Disk and memory collection, log preservation, chain-of-custody handling, and scoped impact analysis — artifacts insurers, regulators, and litigation counsel expect.

  • Microsoft 365 and cloud eradication

    Stops this failure mode: cleaned laptops while OAuth and mailbox rules stay active

    Revoke attacker OAuth grants, remove malicious inbox rules, reset compromised admin paths, and hunt persistence in Entra ID and SaaS tenants — not only on-premises endpoints.

  • Insurance and legal coordination

    Stops this failure mode: carrier denial for late notice or missing documentation

    Structured incident reports, preserved log packages, and briefing language aligned to your policy and counsel — we document; your attorney and carrier decide coverage.

  • Clean disaster recovery orchestration

    Stops this failure mode: restoring backups into an still-compromised domain

    Coordinate rebuild of identity and core systems, validate backup integrity, and restore priority workloads from last verified snapshots — alongside immutable backup architecture.

Containment

Stop spread first

Isolation limits encryption and data theft while investigators work. Containment is not recovery — it buys time to scope and preserve evidence.

Forensics

Prove what happened

Forensics answers how the attacker entered, what they touched, and whether they remain — using preserved logs and disk images, not guesswork.

Chain of custody

Evidence that holds up

Chain of custody documents who collected each artifact, when, and how it was stored — so insurers, regulators, or litigation can trust the timeline.

Clean restore

Recover without re-infection

Clean restore means rebuilding trust in identity and core systems before pulling data from backups — not copying encrypted files back onto a still-owned network.

Terms used on this page: C2 (command and control — attacker infrastructure that compromised machines phone home to); patient zero (the first system or account where the intrusion started); chain of custody (documented handling of forensic evidence from collection through storage); OAuth (authorization grants that let cloud apps act on Microsoft 365 or Google Workspace without storing your password — attackers abuse stolen OAuth tokens to persist in mail and files).

What good looks like

A short readiness checklist before incident day — walk through it with leadership, not as a vendor scorecard.

  • IR plan documented?

    Written steps for who calls whom, how to isolate, and when to notify counsel and insurance — reviewed at least annually.

  • Emergency hotline saved?

    Partners and office managers know (631) 557-0440 (or your retainer IR number) without searching email during panic.

  • Insurance contacts ready?

    Policy number, carrier breach line, and required notice window are in the IR plan — not only in a broker's drawer.

  • Immutable backups tested?

    A last verified snapshot exists off the production path — and someone has restored from it in the last year.

  • MDR or EDR running?

    Endpoints report telemetry and alerts reach humans who can isolate — not only antivirus with yesterday's signatures.

How incident response maps to your industry

Breach notification rules, IRS and FTC expectations, and CMMC reporting windows each change what "done" looks like after containment. Here is how Manage IT NY maps IR to the obligations law, accounting, and defense firms actually face — in language partners can follow.

Law firms and breach notification

Client confidentiality and state breach laws expect counsel to assess whether privileged or personal data left the firm — and to notify clients or regulators when required. IR preserves logs and scope documentation so partners can make notification decisions with facts, not assumptions, and explain reasonable efforts to malpractice carriers.

Law firm cybersecurity

Frequently asked questions

Straight answers on response time, insurance documentation, ransomware first steps, IR versus everyday IT, MDR overlap, and forensic evidence.

Retainer and emergency clients typically target triage within about one hour of reaching Manage IT NY at (631) 557-0440 — isolation and scoping follow as quickly as access and severity allow. Exact clocks depend on your contract, after-hours reachability, environment size, and whether key people answer the first call. We communicate realistic next steps rather than promising instant eradication.