Response within the first four hours dramatically improves outcomes. Immediately isolate affected accounts, reset credentials, and notify financial institutions if any funds transfer was attempted. Speed is critical for potential fund recovery and preventing attackers from expanding access.
Document everything for forensic analysis rather than deleting suspicious emails. Contact your MS-ISAC representative for incident response support—this free service exists specifically for public sector organizations.


