What Happens in the First 10 Minutes After a Cyberattack?
by Daniil Slesarenko
It Usually Starts With Something Small
A cyberattack doesn't always begin with a dramatic system failure.
It might start with a single employee clicking a convincing phishing link. A suspicious login appears. An unfamiliar application connects to a company account. A server begins behaving differently.
At first, nobody knows exactly what is happening.
The first few minutes matter because the longer an attacker remains unnoticed, the more opportunity they have to access information, compromise additional accounts, and move through the environment.
Minute 1: Something Doesn't Look Right
The first warning could come from almost anywhere.
An employee might report a strange login notification. A monitoring system could detect an unusual connection. An endpoint security tool might identify suspicious activity. A user might suddenly lose access to an account.
The important thing is not immediately knowing exactly what happened. The first step is recognizing that something deserves investigation.
Minutes 2–3: Confirm the Alert
Not every security alert is an attack.
The IT or security team needs to determine whether the activity is legitimate or suspicious. They may examine the affected account, device, source of the activity, and timing of the event.
Questions might include:
Was the user actually attempting to log in?
Is the device normally used by this employee?
Did the activity come from an expected location?
Are there other unusual events happening at the same time?
The goal is to quickly establish whether there is a genuine security incident.
Minutes 4–5: Contain the Problem
If the activity appears malicious, the priority changes from investigation to containment.
Depending on the situation, this could mean disabling a compromised account, ending active sessions, isolating an affected computer, blocking a malicious connection, or temporarily restricting access to a service.
Containment is important because an attacker with working credentials may continue operating while the investigation is taking place.
Stopping access early can limit what happens next.
Minutes 6–8: Find Out What Else Is Affected
Once the immediate threat is contained, the team needs to determine whether the incident is isolated.
A compromised account may have been used to access email, documents, cloud applications, or other systems. A compromised workstation may have communicated with additional devices.
Security and monitoring tools can help identify related activity and answer important questions:
What happened?
When did it start?
What account or device was involved?
What did the attacker access?
Did the activity spread anywhere else?
The answers help determine the scope of the incident.
Minutes 9–10: Start the Response
By this point, the organization should have a clearer understanding of what it is dealing with and can begin following its incident response process.
That may involve escalating the incident, preserving logs and other evidence, notifying appropriate personnel, resetting credentials, blocking additional access, and determining whether customers, partners, or regulators need to be informed.
The exact response depends on the type and severity of the incident.
The important part is having a process before the incident occurs.
The First Ten Minutes Can Make a Difference
There is no universal ten-minute formula for responding to a cyberattack. Different incidents require different responses, and some attacks may remain undetected for much longer.
But the basic priorities remain consistent:
Detect: Recognize suspicious activity
Confirm: Determine whether it is a real incident
Contain: Limit the attacker's access
Investigate: Determine what was affected
Respond: Activate the organization's incident response process
The organizations that respond effectively aren't necessarily the ones that never experience security incidents. They are the ones that know what to do when something goes wrong.
Don't Wait Until the Attack to Build the Plan
When a security incident happens, nobody wants to spend the first ten minutes asking who should be contacted, which systems need to be isolated, or where the relevant logs are stored.
Monitoring, clear responsibilities, documented procedures, and regular security training can make those first decisions much easier.
A cyberattack may start with one compromised account or device. How far it goes can depend heavily on how quickly the organization recognizes and responds to it.