# Responding to an incident: the first minutes and the alert chain

URL : https://skillrung.com/en/courses/cybersecurity/reacting-to-an-incident
Topic: Cybersecurity · Duration: 25-30 min · Updated on 2026-09-15

## In brief

Between the moment something seems wrong and the moment the alert is raised, the attack keeps progressing. The two costliest reflexes are human ones: trying to fix it alone, and waiting to be certain before disturbing anyone. Isolate the device without switching it off, note the time and what is displayed, raise the alert immediately: these actions are decided in calm conditions, because in the heat of the moment no one improvises properly.

## Programme

- 1. Why the first minutes decide the rest : Identify what makes an incident worse before it is even understood
- 2. Responding to an incident : Apply the five emergency reflexes and alert the right people in time
- 3. Your action plan : Turn the course into five dated actions and measure your level

1 content sections, each with its quiz. Three level quizzes: Beginner, Intermediate, Expert.

## Free preview (first 4 slides)

### 1. The delay costs more than the mistake

Almost everyone will click one day: making the click feel natural is the attacker's job. What separates a minor incident from a major one is not the click, it is the time that passes before the alert. An alert raised for nothing costs a few minutes; an alert raised too late costs your structure days of work.

### 2. What you will be able to do at the end

- Apply the five emergency reflexes in order
- Alert the right people without wasting time
- Recognise what falls under a notification obligation

### 3. What makes an incident worse, every time

Four understandable reflexes, and costly ones.
- Trying to fix it alone before telling anyone
- Waiting to be certain so as not to disturb anyone
- Switching off the device, which destroys the traces
- Replying to the attackers, even just to buy time

### 4. Where do you stand?

One question to place your reflexes, with no score and no judgement. Answer before you continue.
_Self-assessment of 1 questions in the player._

## Access

The first four slides of every course and the Beginner-level quiz are free, with no account. From the fifth slide onwards a subscription is required: €29.99/month incl. VAT, no commitment, cancellable online. skillrung is not a French training body certified under the Qualiopi scheme; its content is not eligible for the French CPF, OPCO or DPC schemes.

## Frequently asked questions

### Should you switch off the computer during an attack?

No. A hard shutdown destroys traces that are useful to whoever intervenes next. The right action is to isolate the device from the network — unplug the cable, switch off the Wi-Fi — leaving it switched on, then raise the alert without waiting until you are certain what is happening.

### Should you pay a ransom to get your files back?

The French authorities recommend not paying. Nothing guarantees that the files will be returned, nothing prevents the publication of data already copied, and the payment directly funds the next attacks. The right answer is prepared beforehand: a recent, disconnected and tested backup.

### Does an attack always mean an authority has to be notified?

Not always, and the course sets out the criterion. The notification obligation arises from a personal data breach that presents a risk to the people concerned. Your role is not to assess the incident alone: it is to report it early enough for someone to assess it.

## Sources

- Notifier une violation de données personnelles : CNIL, 2018-05-24, https://www.cnil.fr/fr/notifier-une-violation-de-donnees-personnelles
