Quick reference

Incident Response Timeline — One Page

What to do in the first hour, first day, and first week of a suspected incident.

Intended audience
Responders, managers, and owners
Difficulty
Intermediate
Estimated time
5 minutes
Access
Free
NIST SP 800-61
NIST SP 800-171
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Sequence the first-hour actions of an incident response: confirming, logging, assigning a lead, and containing.
  • Identify what must happen in the first day, including checking notification clocks and preserving privileged account integrity.
  • Describe the first-week activities that close out an incident, including the after-action review and POA&M updates.

First hour

  • Confirm the report and open a written log with timestamps.
  • Assign an incident lead.
  • Contain: disable affected accounts, isolate devices, revoke sessions.
  • Preserve evidence before wiping or rebuilding anything.

First day

  • Determine what data and systems were involved.
  • Check contractual and regulatory notification clocks.
  • Notify insurer and legal counsel if applicable.
  • Reset credentials and review privileged accounts.

First week

  • Restore from known-good backups and verify.
  • Complete required notifications.
  • Write the after-action review with root cause and improvements.
  • Add resulting gaps to the risk register or POA&M.

Key takeaways

  • Evidence should be preserved before any affected system is wiped or rebuilt, since rebuilding first can destroy the information needed to determine scope and root cause.
  • Many contracts and regulations set a notification clock that starts running from confirmation of an incident, so checking those obligations is a first-day priority, not an afterthought.
  • An after-action review that identifies root cause and adds resulting gaps to the POA&M turns an incident into a documented improvement rather than a one-time scramble.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Template

Incident Response Plan

A short, usable plan: who to call, what to do first, what to write down, and who must be notified.

Intermediate
40 min
Free
NIST SP 800-61
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Quick reference

Compliance Project Timeline — One Page

A realistic phase-by-phase timeline for a small business standing up a program.

Beginner
5 min
Free
NIST CSF
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Template

Access Review Worksheet

A repeatable quarterly review of who has access to what, with a decision recorded for each row.

Intermediate
25 min
Free
NIST SP 800-171
SOC 2

Published · v1.0.0 · 2026-08-01

Template

Asset Inventory Template

One list of the devices, accounts, and services you are actually responsible for protecting.

Beginner
30 min
Free
CIS Controls
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Exercise

Build Your First Asset Inventory

Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.

Beginner
20 min
Free
CIS Controls
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.