The First Hour Matters: Triage Before the Incident Outgrows the Team
Key Takeaway: August’s New Zealand figures show that stable reporting volumes can conceal an increase in incidents with wider consequences. Effective response depends on recognising severity early, escalating before certainty is available and containing the threat without destroying the evidence needed for later decisions.
The NCSC’s second-quarter figures contain an important operational lesson. It received slightly fewer reports than in the previous quarter, yet the number requiring specialist technical support rose from 77 to 92. A small group of incidents also caused most of the reported financial loss. The practical risk is not that every alert becomes a crisis. It is that the serious incident initially looks ordinary and remains in a routine queue while access, data loss or disruption continues. Early triage is therefore more than a technical sorting exercise. It is the point at which an organisation decides who must know, which authority is needed, what evidence must be protected and whether external support should be engaged. Delay at this stage compounds every later problem. Logs expire, accounts are changed, affected people remain exposed and executives receive an incomplete picture just as consequential decisions are required.
Volume is not severity
A useful triage model should look beyond the number of devices, records or alerts. The ATF breach involved a standalone system, yet the information related to investigation targets and the event was treated as a major incident. Victorian court data included family violence and children’s matters, even though parts of the exposed dataset appeared to be ordinary meeting metadata. Boston Scientific’s incident was not yet fully understood when it became material to operations because ordering and shipping were disrupted. Four signals should accelerate escalation: sensitive information or vulnerable people; privileged access to identity, remote management or production systems; uncertainty about continuing access or evidence; and dependency on a system for essential operations. Any one may justify specialist support. Several together should move the event out of normal service management even if the technical scope still appears small.
Contain without erasing the story
The instinct to act quickly is correct, but uncoordinated action can remove the evidence needed to establish what happened. Resetting accounts, rebuilding a server or deleting a malicious file may interrupt the attacker while also destroying volatile logs, timestamps or persistence mechanisms. The response team should record the reason for each containment action, preserve available cloud and identity logs, capture relevant system state and maintain a clear timeline of who changed what. Containment should also be proportionate. Disabling a compromised administrator account may be immediate and low risk. Disconnecting an order-management, clinical or industrial system may create safety or continuity consequences. The decision needs technical, operational and executive input, with a named person authorised to accept the temporary business impact. That authority should be agreed before the incident.
The first executive update
The first update should not wait for a complete forensic answer. It should distinguish established facts from working assumptions, describe the immediate threat and business effect, identify what remains unknown, record the actions taken and state when the next decision will be required. Confidence levels are more useful than premature certainty. A disciplined update might say that access has been interrupted, but the period of access and volume of copied information remain under investigation. This structure helps leaders avoid two common errors: under-reacting because impact has not been proved, and overstating the incident before the evidence supports it. It also gives legal, privacy, communications and operational teams a shared set of questions rather than separate versions of the event.
Make escalation executable
An incident plan should specify more than names and telephone numbers. It should define severity triggers, the authority to isolate systems or suspend accounts, the route for engaging forensic and legal support, and the minimum information required for an executive briefing. External responders should have a workable way to gain approved access to evidence without waiting for new procurement, confidentiality or identity arrangements. The best test is a short simulation in which the initial facts are incomplete. Give the team a credible alert, a business system that cannot be casually disconnected and a supplier that has not yet confirmed the scope. Observe when the event is escalated, which evidence is requested, who can authorise containment and whether the first executive update supports a real decision. The result will show whether the first hour is governed or improvised. Incident Response Solutions can assist organisations to define practical triage thresholds, establish forensic-ready response procedures and test early escalation through executive cyber simulations.
AI and Cyber Incidents: Practical Steps to Soften the Blow
Artificial intelligence is changing cyber security for both attackers and defenders. The NCSC’s Opportunities for AI in Cyber Defence guidance highlights how AI can support governance, detection, response and recovery, while reinforcing that it should strengthen existing cyber practices rather than replace them. For leaders, the priority is not simply adopting AI, but preparing for what happens when an AI-enabled service is compromised, unavailable or produces unreliable results. Good governance can reduce disruption by ensuring roles, dependencies and recovery priorities are understood before an incident occurs.
Know where AI matters
Organisations should understand where AI is being used, what information it can access, which business processes depend on it and which suppliers are involved. Particular attention should be given to services that handle sensitive information, support important decisions or connect with other systems. This helps identify which AI-enabled services would create the greatest business disruption if they failed, were manipulated or could no longer be trusted. Our new service, KiwiGen.AI, provides an opportunity to apply these principles from the outset by considering ownership, access, data handling, supplier dependencies and incident response as part of AI adoption.
Decide who makes the calls
Clear decision-making can significantly reduce incident impact. Organisations should know in advance who can disable an AI service, restrict access, disconnect integrations, engage external specialists, notify key stakeholders and approve recovery. These responsibilities should be agreed before an incident rather than worked out during one. Escalation thresholds should also be clear so that potentially serious issues reach the right decision-makers quickly.
Plan for failure
AI should not become a single point of failure for a critical process. Organisations should maintain alternative ways to continue important activities if an AI service becomes unavailable or cannot be trusted. The same applies to AI used in cyber security. It can help analyse alerts and large volumes of information quickly, but important containment, recovery and communication decisions should retain appropriate human oversight.
Contain and recover quickly
Organisations should be able to revoke credentials, isolate services, disable integrations and restrict access to sensitive information when required. Relevant logs and evidence should also be retained to support investigation and recovery. Data minimisation, least-privilege access and removal of unnecessary accounts or integrations can further reduce the impact of a compromise by limiting what an attacker can reach.
Test the response
A simple tabletop exercise can reveal gaps before a real incident occurs. Scenarios might include an AI service exposing confidential information, becoming unavailable, producing unreliable outputs or being compromised through a connected system. Leaders should be able to answer a few basic questions: what do we shut down, who makes the decision, how do we keep critical services running, who needs to be informed and what needs to be restored first?
Focus on resilience
AI may help organisations detect and respond to threats faster, but sound governance remains essential. Understanding dependencies, limiting unnecessary access, assigning clear authority, maintaining fallback options and testing recovery arrangements can significantly soften the impact when something goes wrong. The aim is not perfect prevention, but stronger resilience and better decision-making when an incident occurs.
About the Bulletin:
The NZ Incident Response Bulletin is a monthly high-level executive summary containing some of the most important news articles that have been published on Forensic and Cyber Security matters during the last month. Also included are articles written by Incident Response Solutions, covering topical matters. Each article contains a brief summary and if possible, includes a linked reference on the web for detailed information. The purpose of this resource is to assist Executives in keeping up to date from a high-level perspective with a sample of the latest Forensic and Cyber Security news.
To subscribe or to submit a contribution for an upcoming Bulletin, please either visit https://incidentresponse.co.nz/bulletin or send an email to bulletin@incidentresponse.co.nz with the subject line either “Subscribe”, “Unsubscribe”, or if you think there is something worth reporting, “Contribution”, along with the Webpage or URL in the contents. Access our Privacy Policy.
This Bulletin is prepared for general guidance and does not constitute formal advice. This information should not be relied on without obtaining specific formal advice. We do not make any representation as to the accuracy or completeness of the information contained within this Bulletin. Incident Response Solutions Limited does not accept any liability, responsibility or duty of care for any consequences of you or anyone else acting, or refraining to act, when relying on the information contained in this Bulletin or for any decision based on it.
