Confirm the people and communication routes.
Identify who leads an incident, who can make business decisions, and who communicates with customers, suppliers and other stakeholders. Keep approved contact routes accessible if normal collaboration tools are unavailable.
Understand what your sources can show.
Document the identity, endpoint, network, email and cloud sources available to the response team. Review permissions, retention and collection health. Record gaps rather than assuming a connected system provides complete evidence.
Preserve a reliable record.
Keep source references, timestamps and an incident timeline. Record what was observed separately from what is inferred. Preserve relevant evidence through the approved process before making changes that could remove it.
Make action boundaries explicit.
Agree who may authorise containment and other changes. Consider affected business services and recovery options. A monitoring connection does not itself grant permission for a disruptive action.
Prepare for recovery and review.
Define how systems will be checked before returning to service. After the incident, review the decisions, evidence gaps and response outcomes. Convert the lessons into owned improvements and test them in a later exercise.
ThreatShield brings investigation evidence, response tickets and governed action into a shared operating picture.
Explore security operations