Response
What to do in the first hour after a breach
Panic wastes the window that matters. A calm, ordered sequence for the moment you realise something is wrong.
Dico.tel Editorial · May 8, 2026 · 6 min read
The first hour determines how expensive an incident becomes. The goal is simple: stop the access, then contain what it reached.
The sequence
- —Secure the email account first — it unlocks everything else
- —Sign out all sessions and rotate the password
- —Check for forwarding rules, filters and recovery address changes
- —Rotate passwords on anything sharing that credential
- —Notify your bank before checking your balance
- —Write down times and details while they're fresh
Then slow down
Once access is closed, resist the urge to wipe devices immediately — evidence of how entry happened prevents the same thing recurring next month. Members with managed detection have analysts running this sequence with them rather than alone at midnight.
Keep reading
MTD vs MDR: what's the difference, and which do you need?
One protects your devices in real time. The other puts human analysts behind your accounts. Here's how to choose — or why you might want both.
Why your email address is the real target
Attackers rarely want your inbox. They want the password resets it unlocks. A secured personal mailbox changes the maths.
Seven signs a message is a scam
Modern phishing is well written and well designed. These are the patterns that still give it away.
