The first hour of an incident decides the cost of the months that follow.
The First Hour is a free eight-page playbook by Zamak Technologies: the six decisions a company makes in the first sixty minutes of a cyber incident, who makes each one, and why.
Download the complete playbookSee the six decisions, minute by minute ↓
Free eight-page PDF · English, Portuguese and Spanish · Based on NIST and CISA guidance
Eight pages, written for the hour when nobody has time to read.
Print it, fill it in before you need it and keep it with the person who decides. It reads without any context, so it can go to leadership exactly as it is.
Inside
- p. 2Why the first hour decides the costHow an attack unfolds before anyone notices, and the three things decided in that hour.
- p. 3The sixty minutes, step by stepSix decisions, with who makes each one and why.
- p. 4Who does whatFive roles, each with an owner and a backup to name today.
- p. 5What never to do, and the four numbersThe mistakes that cost evidence and money, and the contacts to fill in now.
- p. 6The one-page version for leadershipFive questions and the list to close before the next time.
- p. 7The pocket cardCut it out and keep it next to the phone.
Get the playbook by email
The PDF reaches your inbox in seconds, in the language of this page.
Zamak uses your details to deliver the playbook and to follow up on it. One click unsubscribes.
The first hour is not about technology. It is about decisions.
A ransomware attack rarely starts at the moment it is noticed. The intrusion comes first, often through a stolen password or a phishing email; the attacker moves through the network, copies data and only then encrypts the systems.
When the alert arrives, three things are decided at the same time: how long the operation stays down, how much the company pays in recovery, fines and contracts, and what customers, press and regulators will say about it.
CISA, the U.S. Cybersecurity and Infrastructure Security Agency, recommends identifying the affected systems and isolating them immediately, powering a device down only when it cannot be disconnected from the network. NIST, the U.S. National Institute of Standards and Technology, treats incident response in SP 800-61 Rev. 3 (April 2025) as part of the company's risk management, not as an isolated IT task.
What to do in the first hour of a cyber incident: six decisions, in order.
The clock starts when someone notices something is wrong, not when the problem is confirmed. This is the summary; the minute marks are Zamak's structuring of the guidance in the sources below, and the playbook adds who makes each decision and the space to name them.
- 0-5Minutes
Disconnect, do not wipe
Take the affected systems off the network without wiping or reformatting anything. Power down only if you cannot disconnect.
WhyStops the spread and preserves what the investigation will need.
- 5-15Minutes
Declare the incident
One lead, one communication channel outside the affected systems, one log with the time of every decision.
WhyWithout an owner, each area decides alone and the company loses time and evidence.
- 15-30Minutes
Preserve
Confirm the backups are isolated and intact; freeze images of the affected systems; nothing is rebooted to see if it comes back.
WhyRebooting can destroy evidence the investigation needs.
- 30-45Minutes
Call the four numbers
IT and security partner, cyber insurer (if there is a policy), legal counsel and the competent authority.
WhyPolicies typically require prompt notice; data protection laws set deadlines; the authority guides and records.
- 45-55Minutes
One voice
Leadership defines what the company says to employees and customers; nobody speculates or posts on social media.
WhyReputation is decided by the consistency of what is said in the first hours.
- 55-60Minutes
Decide the next hour
Known scope, continuity plan activated, who talks to customers and when.
WhyTurns reaction into a plan and gives the company back control of the clock.
Sources: NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management (April 2025) · CISA and FBI, #StopRansomware Guide and Ransomware Response Checklist

Five questions leadership can ask today, before any incident.
If the answers come quickly and in writing, the first hour is already under control. If they do not, that is where to start.
Who decides in the first hour, and who decides if that person is not available?
A good answerTwo names, in writing, known to the whole leadership.
How many hours can the operation stay down before it becomes irreversible loss or news?
A good answerOne number per critical area, and a continuity plan for each.
Where is the backup, is it isolated from the network, and when was the last recovery actually tested?
A good answerAn immutable copy, out of the attacker's reach, with the date of the last recovery test.
Who speaks for the company, and what do they say, in the first hours?
A good answerOne spokesperson and one base message approved before it is needed.
Which contracts, policies and laws require notice, and how quickly?
A good answerA list with the deadlines, reviewed by legal and finance.

For the companies Zamak serves, the first hour starts before the incident.
Detection and response on every endpoint, immutable backup copies with recovery that can be tested, and service in English, Portuguese and Spanish, within the scope each company engages. For companies with their own IT team, Zamak works alongside it as an operations and security center.
Talk to Zamak about your first hour
Microsoft Solutions Partner · Addee (N-able) Elite Group · Great Place to Work
Questions about the first hour.
Sixty minutes. Six decisions. One voice.
Keep the playbook by the phone of the person who decides, and talk to Zamak about what happens before the first minute.
