Almost everything that matters has a shelf life measured in days, and the clock started before you were told.
Start a conversation with the Incident Concierge, already scoped to evidence preservation. Pick a starting point, or describe the incident directly.
The forensic record of a security incident degrades on three separate clocks, and none of them waits for counsel to be retained. Volatile memory holds the running malware, active network connections and sometimes decrypted credentials, and it is gone the instant a machine is rebooted — which is frequently the first thing a well-meaning administrator does. System logs sit on retention schedules that are commonly thirty days and sometimes shorter, so an intrusion discovered eight weeks after initial access may have lost the evidence of how it began. And remediation itself is destructive by design: reimaging a compromised host is correct, and it ends that host's forensic history. The organizations that end up with a defensible evidentiary position are the ones where somebody said "image it first" in the first hours.
Ordered by urgency. The top of this list is measured in minutes.
Running processes, live connections, decrypted keys. Gone at reboot, unrecoverable.
Active sessions and current connections, which show what the attacker was doing right then.
Commonly 30-day retention, sometimes 7. The oldest entries are usually the most important.
Varies enormously by provider and license tier. Establish yours before assuming.
A reimaged machine is forensically gone. Image before you rebuild.
Both evidence of the pre-incident state and, sometimes, the only surviving copy of altered data.
What to do in the first hours.
Whether any of the later analysis is possible at all.
It takes minutes, costs almost nothing, and is irreversible in the other direction — logs that roll over are gone. More cases are crippled by ordinary retention policies quietly doing their job than by anything an attacker did.
No, though it is worse than it needed to be, and it is worth establishing quickly what survived. Centralised logging, if it existed, is unaffected by what happened to the endpoint. Cloud and SaaS audit logs live with the provider. Network flow data, email gateway records, EDR telemetry already shipped off-host, and backups all persist independently. What is genuinely gone is the volatile state and anything that existed only on the reimaged machine. Establishing what still exists is the first task, and it is usually more than people fear.
That is a legal question for counsel rather than a technical one, and the answer generally attaches to when litigation became reasonably foreseeable — which, after a significant breach, is early. What is worth understanding technically is that a preservation obligation and a normal retention policy actively conflict: the policy is deleting on schedule unless somebody stops it. Spoliation findings in these matters frequently arise from an automated process nobody suspended, rather than from any deliberate act.
Almost always the non-email systems. A hold that reaches mailboxes but not the ticketing system, the internal chat, the EDR console, the SIEM, the vendor and MSP records, or the cloud provider audit trail leaves most of the useful record unprotected. Third-party systems are the most commonly missed and the hardest to recover, because the vendor is running its own retention schedule and has no idea an incident occurred unless you tell it.
That sequencing question is genuinely consequential and belongs with counsel, urgently. Whether incident-response work product attracts privilege is contested and depends heavily on how the engagement is structured, who directs it, and what it was created for. It is enough to know that the structure matters and that decisions made in the first hours are difficult to restructure later. The preservation steps on this page, by contrast, are not privilege-sensitive: capture the evidence now, and settle the engagement structure in parallel.
Describe what has happened and what has been done. The Institute will help you triage what is still recoverable.