Back to Blog
Security Management

Incident Response Plan: How to Act in the First 24 Hours of an Attack

The difference between a contained incident and a prolonged crisis usually comes down to the first hours of response. See how to structure an effective incident response plan.

Lucca Lo Presti
7/24/2026
10 min read
Incident ResponseSecurity ManagementLGPDCybersecurityBusiness Continuity
Incident Response Plan: How to Act in the First 24 Hours of an Attack
DIRECT ANSWER

What should an incident response plan contain?

An incident response plan should define clear roles and responsibilities, severity classification criteria, containment and isolation procedures, internal and external communication channels, legal notification requirements (such as the LGPD), and a structured post-incident review process.

When a security incident happens, the decisions made in the first few hours have a disproportionate impact on the final outcome.

Companies with a well-defined incident response plan manage to contain the problem, preserve evidence, and meet legal obligations in an organized way. Companies without a plan make important decisions on the fly, under pressure, and usually make mistakes that worsen the impact.

A plan only works if it has been tested beforehand.

An incident response document that has never been rehearsed is very likely to have gaps that only surface during the real thing, when it is too late to fix them calmly.

What an Incident Response Plan Should Contain

1. Clear Roles and Responsibilities

Who decides to isolate a system? Who communicates with customers? Who brings in legal? These answers need to be defined before the incident, not figured out during it.

2. Severity Classification Criteria

Not every incident calls for the same level of response. Having objective criteria (impact on sensitive data, critical systems affected, number of users impacted) helps size the response correctly, without underreacting or overloading the team unnecessarily.

3. Containment Procedures

Practical steps to isolate compromised systems, revoke credentials, and stop an attack from spreading, minimizing additional impact while the investigation moves forward.

4. Communication Channels

Internal (leadership, employees) and external (customers, partners, press, regulators), with pre-approved messaging for the most likely scenarios, avoiding improvised communication at a moment of high pressure.

5. Legal and Regulatory Requirements

Including LGPD obligations for incidents involving personal data, notification deadlines, and the process for communicating with the ANPD where applicable.

6. Post-Incident Review Process

Once the incident is contained, understanding exactly what happened and why is essential to prevent recurrence, and that analysis should produce concrete improvement actions, not just a report that gets filed away.


The First 24 Hours: A Practical Timeline

First hour: Confirmation and Initial Containment

  • Confirm the incident is real (avoid reacting to false positives)
  • Isolate compromised systems without abruptly shutting them down
  • Activate the incident response team defined in the plan

Next few hours: Impact Assessment

  • Identify which systems and data were affected
  • Assess whether personal data is involved (which triggers LGPD obligations)
  • Preserve logs and evidence for the investigation

Throughout the first day: Communication and Decisions

  • Brief executive leadership with a clear assessment of the impact
  • Involve legal to evaluate notification obligations
  • Define the external communication strategy, if needed
  • Bring in external incident response specialists if the internal team lacks the necessary expertise

Common Mistakes During Incident Response

  • Shutting systems down abruptly: can destroy important forensic evidence
  • Improvised communication: public or internal statements made without alignment can cause more damage than the incident itself
  • Ignoring legal obligations: failing to notify when required can lead to additional LGPD sanctions
  • Not preserving evidence: hampers both the internal investigation and any legal action against those responsible
  • Assuming it's over: closing the response too early, without confirming the attacker no longer has residual access

Conclusion

No company is immune to security incidents, but the difference between a contained crisis and a prolonged one almost always comes down to prior preparation.

A well-structured incident response plan, tested periodically through simulations, turns a moment of panic into an organized process, with decisions already thought through calmly, before the pressure of the real moment.

Does Your Company Have an Incident Response Plan?

LoPrestiSec helps companies structure incident response plans and identify vulnerabilities before they turn into real incidents.

  • Security Consulting
  • Threat Modeling
  • Infrastructure Pentest

Get in touch to structure your company's plan.

❓ Frequently Asked Questions

Get answers to the most common questions

Yes. Companies of any size that process data or depend on digital systems to operate benefit from having at least a basic plan. Defining who does what during an incident is far more effective when done calmly, before the problem happens.
The LGPD requires that the ANPD and the affected data subjects be notified within a reasonable timeframe, without setting a fixed number of hours in the law itself. The practical guidance is to act as quickly as possible once the incident is confirmed and its impact assessed.
Ideally, a combination of IT/security, legal, communications/PR, and executive leadership. Security incidents are rarely just a technical problem; they involve legal, communication, and business decisions.
It depends on the company's internal maturity. Many organizations lack in-house incident response expertise and benefit from specialized external support, especially for forensic investigation and containment of more sophisticated attacks.

Still have questions? Reach out to us through the contact form or via WhatsApp.

Last updated: 7/24/2026
Author: Lucca Lo Presti - Offensive Security Specialist

Need Professional Security Help?

LoPrestiSec delivers end-to-end penetration testing, security consulting and LGPD compliance services. More than 200 companies trust our work.

Get in Touch →