Incident Response Plan: How to Act in the First 24 Hours of an Attack
The difference between a contained incident and a prolonged crisis usually comes down to the first hours of response. See how to structure an effective incident response plan.

❓What should an incident response plan contain?
An incident response plan should define clear roles and responsibilities, severity classification criteria, containment and isolation procedures, internal and external communication channels, legal notification requirements (such as the LGPD), and a structured post-incident review process.
When a security incident happens, the decisions made in the first few hours have a disproportionate impact on the final outcome.
Companies with a well-defined incident response plan manage to contain the problem, preserve evidence, and meet legal obligations in an organized way. Companies without a plan make important decisions on the fly, under pressure, and usually make mistakes that worsen the impact.
An incident response document that has never been rehearsed is very likely to have gaps that only surface during the real thing, when it is too late to fix them calmly.
What an Incident Response Plan Should Contain
1. Clear Roles and Responsibilities
Who decides to isolate a system? Who communicates with customers? Who brings in legal? These answers need to be defined before the incident, not figured out during it.
2. Severity Classification Criteria
Not every incident calls for the same level of response. Having objective criteria (impact on sensitive data, critical systems affected, number of users impacted) helps size the response correctly, without underreacting or overloading the team unnecessarily.
3. Containment Procedures
Practical steps to isolate compromised systems, revoke credentials, and stop an attack from spreading, minimizing additional impact while the investigation moves forward.
4. Communication Channels
Internal (leadership, employees) and external (customers, partners, press, regulators), with pre-approved messaging for the most likely scenarios, avoiding improvised communication at a moment of high pressure.
5. Legal and Regulatory Requirements
Including LGPD obligations for incidents involving personal data, notification deadlines, and the process for communicating with the ANPD where applicable.
6. Post-Incident Review Process
Once the incident is contained, understanding exactly what happened and why is essential to prevent recurrence, and that analysis should produce concrete improvement actions, not just a report that gets filed away.
The First 24 Hours: A Practical Timeline
First hour: Confirmation and Initial Containment
- Confirm the incident is real (avoid reacting to false positives)
- Isolate compromised systems without abruptly shutting them down
- Activate the incident response team defined in the plan
Next few hours: Impact Assessment
- Identify which systems and data were affected
- Assess whether personal data is involved (which triggers LGPD obligations)
- Preserve logs and evidence for the investigation
Throughout the first day: Communication and Decisions
- Brief executive leadership with a clear assessment of the impact
- Involve legal to evaluate notification obligations
- Define the external communication strategy, if needed
- Bring in external incident response specialists if the internal team lacks the necessary expertise
Common Mistakes During Incident Response
- Shutting systems down abruptly: can destroy important forensic evidence
- Improvised communication: public or internal statements made without alignment can cause more damage than the incident itself
- Ignoring legal obligations: failing to notify when required can lead to additional LGPD sanctions
- Not preserving evidence: hampers both the internal investigation and any legal action against those responsible
- Assuming it's over: closing the response too early, without confirming the attacker no longer has residual access
Conclusion
No company is immune to security incidents, but the difference between a contained crisis and a prolonged one almost always comes down to prior preparation.
A well-structured incident response plan, tested periodically through simulations, turns a moment of panic into an organized process, with decisions already thought through calmly, before the pressure of the real moment.
Does Your Company Have an Incident Response Plan?
LoPrestiSec helps companies structure incident response plans and identify vulnerabilities before they turn into real incidents.
- Security Consulting
- Threat Modeling
- Infrastructure Pentest
❓ Frequently Asked Questions
Get answers to the most common questions
Still have questions? Reach out to us through the contact form or via WhatsApp.
Need help with this topic? Learn about our Digital Security Consulting service →
Need Professional Security Help?
LoPrestiSec delivers end-to-end penetration testing, security consulting and LGPD compliance services. More than 200 companies trust our work.
Get in Touch →