Recognise and contain
Record what was observed and when. Isolate affected devices or services where appropriate without deleting evidence, and activate the incident lead / IT support route.
Do not rush blindly back to business as usual. Establish what is affected, get the right technical help, protect critical services and restore in a controlled order.
The exact technical response varies by business and incident. This sequence keeps the first decisions focused on people, the critical service and a deliberate fallback.
Record what was observed and when. Isolate affected devices or services where appropriate without deleting evidence, and activate the incident lead / IT support route.
Identify which critical services, accounts, data and suppliers are affected. Move the business to agreed manual or alternate processes where they are safe.
Use trusted backups and technical recovery procedures. Restore the systems supporting critical services first, validate them, then work back toward normal operation.
Pre-agreed thresholds reduce hesitation and stop a degraded situation from drifting without ownership.
Do not assume the incident is limited to the first machine or user that reported it.
Use documented incident roles and escalation points.
Test restoration and avoid overwriting the only viable recovery copy.
Use an alternate route if the normal communications system may be compromised.
Use current NCSC / law-enforcement / regulatory guidance relevant to the incident and organisation.
Use live provider, emergency-service and regulatory information during a real incident. GPN is the planning layer, not the authority controlling the incident.