Prepare for an incident before it happens
What to write in advance
Who leads, who talks to customers, who faces the regulator, and how you communicate outside systems that may be compromised. A contact list for critical vendors, and insurance details if any.
Basic procedures: how to cut access, how to revoke tokens, how to freeze an environment while preserving evidence.
The order of actions
Stop the spread, preserve evidence, assess scope, fix, and only then return to normal. Don't delete a compromised system before collecting what's needed — that's destroying evidence that will come back to you.
Document every action with a time. That's later the basis of the report.
Reporting
There are cases with an obligation to notify authorities and those affected, sometimes on a short timeline. Check this in advance with someone qualified — not in the middle of the incident.
Going deeper
Run a tabletop drill once a year: a scenario, a clock, and all the role-holders in the room. The drill always reveals two or three basic gaps — a permission nobody has, a contact who left, or a procedure relying on a system that, in the scenario itself, isn't available.