Experienced a breach? Here’s what to do right now.
A breach doesn’t wait. Neither should you. Find out exactly what to do in the first 24 hours, what a breach response timeline looks like, and how Illumio can help.

What to do immediately after a security breach
If you suspect an active breach, take these steps right away. The speed of containing a breach directly affects the size of the damage.
Segment or disconnect compromised systems right away. Microsegmentation lets you do this without taking your whole network offline. Don't shut systems down entirely. It destroys key evidence.
Find out into which systems and data were accessed, where the attacker went, and what they touched. The faster you know the scope, the faster you can stop the damage.
Save logs, system snapshots, and network data before they're lost. You'll need this for your investigation, compliance reporting, and any legal action that follows.
Don't wait on this step. Contact your security team, legal counsel, and leadership immediately. Many companies must notify regulators or affected users within set time limits.
A typical breach response timeline
Incident response follows a clear pattern. Knowing what to focus on at each stage helps your team move fast under pressure.
First 1–24 hours
- Activate your incident response plan
- Isolate compromised systems and block lateral movement
- Identify the initial entry point
- Save key evidence, including logs, snapshots, and traffic data
- Notify internal leadership and legal counsel
First 48–72 hours
- Map what the attacker reached across your environment
- Find out what data was accessed or stolen
- Begin root cause analysis
- Check your reporting deadlines and legal obligations
- Bring in outside incident response help if needed
First 7 days
- Restore affected systems from clean backups
- Revoke and rotate compromised credentials
- Patch the vulnerability the attacker used
- Update your security policies to close any gaps
- Notify regulators and affected parties as required
How Illumio can help
Illumio gives you the visibility and control to stop lateral movement, find the blast radius, and contain the breach fast across your entire hybrid multi-cloud environment.
See everything, instantly
You can't secure what you can't see. Illumio maps every connection across your cloud, data center, and endpoint environments in real time. You'll know exactly where the attacker is and where they're headed.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Stop the spread
Illumio microsegmentation lets you isolate compromised systems with a single click. No taking the whole network offline. Just a clean, fast cut to block the attacker's path before they reach your critical assets.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Find the attack blast radius
Know the full scope fast. Illumio maps every workload, connection, and dependency in your environment so your team knows exactly what was touched, what wasn't, and where to focus next.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Get back to business faster
Breach containment is just the start. Illumio helps your team close the gaps the attacker used, harden your environment, and make sure the next breach stops where it starts. That’s Zero Trust in practice.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Nous nous adaptons à vos besoins
Adaptez vos méthodologies de projet, telles que les modèles traditionnels en cascade, agiles, hybrides ou prédictifs, pour atteindre les résultats souhaités.
Breaches are more common and costly than ever
The number of confirmed breaches Verizon analyzed across 145 countries in its 2026 DBIR.
The global average cost of a data breach in 2025.
Most organizations that get hit by ransomware never fully recover their data.

Simplifier la segmentation
Cyber threats move fast, spread quietly, and exploit trusted connections. Prevention alone can’t stop them. To stay resilient, organizations must focus on containing attacks before they escalate. This ebook delivers a clear, phased roadmap to deploy segmentation with minimal risk and measurable value.
Need help containing an active breach?
Découvrez comment l'isolation des incidents alimentée par l'IA aide votre équipe à accomplir plus avec moins de ressources.
Breach Containment FAQs
A breach is stressful. Knowing what to expect and what to do makes all the difference. Here are answers to the questions we hear most from organizations navigating an active incident or recovering from one.
Common signs include unusual login activity, systems running slower than normal, unexpected file changes, locked accounts, or alerts from your security tools. Some breaches are loud, such as ransomware which makes itself known fast. Others are silent; an attacker may be inside your network for weeks before anything looks wrong. If something feels off, treat it as a potential incident until you can rule it out.
Be honest, be fast, and be specific. Tell them what happened, what data was affected, what you have done to contain it, and what steps they should take to protect themselves. Vague or delayed communication damages trust far more than the breach itself. Work with your legal and communications teams to align on messaging before going public.
It varies widely depending on the size of the attack, how quickly it was contained, and how prepared your organization was beforehand. Some incidents are resolved in days. Others take months. Organizations with a tested incident response plan and strong backup and recovery processes consistently recover faster and at lower cost.
Lateral movement is how attackers navigate through your network after they get in. Rather than stopping at the first system they compromise, they move from machine to machine, gathering credentials, escalating privileges, and working toward your most valuable assets. It’s the primary reason breaches grow from small incidents into major crises. Stopping lateral movement early is the single most effective way to limit damage.
Investigating a breach typically involves reviewing logs and traffic data to trace the attacker's path, identifying the initial entry point, mapping which systems and data were accessed, and determining whether any data was stolen or altered. Larger organizations often bring in a third-party forensics team to lead or support the investigation, particularly when regulatory reporting is involved.
Zero Trust assumes attackers will get in and limits what they can do once they're inside. A key part of any Zero Trust strategy is microsegmentation, which cuts off lateral movement so one compromised system doesn't hand an attacker the keys to everything else. Zero Trust is how you contain inevitable breaches and keep your environment resilient to attacks.
Longer than most organizations expect. IBM's 2025 Cost of a Data Breach Report put the global average breach lifecycle at 241 days. That’s time an attacker spent inside the network before anyone knew they were there. The longer they stay, the more systems they reach, the more damage they do, and the more it costs to recover. Faster detection matters, but so does limiting how far an attacker can move while you're still looking for them.






