Skip to content
Incident response · the first minute

You have fifteen seconds. Spend them on three things.

This is a one-page plan for the moment you suspect a machine or an account has been taken over. It covers what to do in the first 15 seconds, the data on why the window is that short, and what your team needs in the minute after you call.

29min

average time for an eCrime intruder to move sideways, 2025

CrowdStrike, 2026 Global Threat Report; 65% faster than 2024

27sec

fastest observed breakout

CrowdStrike, 2026 Global Threat Report

4min

to the start of data exfiltration in one intrusion

CrowdStrike, 2026 Global Threat Report

Isolate, freeze, call

Fifteen seconds is too short for one person to deal with an incident. It is long enough to stop the spread, lock the door behind you and get a trained team on the line.

Isolate
0 to 5 s
Freeze
5 to 10 s
Call
10 to 15 s
0 to 5 s

Cut the network, keep the power

Do
  • Pull the Ethernet cable from the affected machine.
  • Turn Wi-Fi off on the device.
Do not

Do not hold the power button or pull the plug.

Shutting down wipes memory, which holds the traces an investigator needs to identify the malware.

This stops ransomware reaching other machines and stops data leaving, and it costs one cable.

5 to 10 s

Freeze the accounts that matter

Do
  • Use a phone on its own 4G or 5G connection, not the affected network.
  • Change the password of the account you suspect is taken over, starting with administrator accounts.
  • Choose “sign out of all active sessions”.
Do not

Do not log in from the affected machine.

If the machine is compromised, a keylogger or session thief sees the new password too.

Identity weaknesses played a material role in nearly 90% of the investigations in Unit 42's 2026 report.

10 to 15 s

Raise the alarm with three facts

Do
  • Call the emergency hotline, or send the pre-agreed message, to your IT or security team.
  • Give the three facts below and hand over control.
Say it in this order
DEVICE: [device or system name]
SEEN: [what you see, for example a ransom note on screen]
DONE: Network unplugged at [time]. Power left on. Accounts reset from my phone.

Checklist

0 of 9 done
0 to 5 s · Isolate
5 to 10 s · Freeze
10 to 15 s · Call

The window is short because attackers are fast

These figures measure different things and come from different reports, so read each label. All of them sit on one logarithmic time axis: each gridline is a multiple of the one before.

  1. 15 s · your window

    The 15-second plan on this page.

  2. 27 s · fastest breakout

    Fastest observed eCrime breakout in 2025. CrowdStrike, 2026 Global Threat Report.

  3. 4 min · exfiltration begins

    In one intrusion, data exfiltration began within four minutes of initial access. CrowdStrike, 2026 Global Threat Report.

  4. 29 min · average breakout

    Average eCrime breakout time in 2025, 65% faster than 2024. CrowdStrike, 2026 Global Threat Report.

  5. 72 min · fastest cases: exfiltration

    In the fastest cases investigated, 72 minutes from initial access to exfiltration, four times faster than the year before. Palo Alto Networks, 2026 Unit 42 Global Incident Response Report.

Sources: CrowdStrike, 2026 Global Threat Report (breakout, first exfiltration); Palo Alto Networks, 2026 Unit 42 Global Incident Response Report (fastest-case exfiltration). As of 2 October 2026.

After the call, four questions decide the next minute

Once the team is on the line, the clock is still running. They need four facts about the thing in front of them, in seconds, with a source for each. Here is why the usual ways of getting them are slow.

Is this vulnerability being exploited right now?

Live web crawl

The answer sits on a government catalogue page. Fetching and parsing live pages under a deadline depends on someone else's server.

Plain RAG

A retrieved passage may be a blog post from before the exploitation started.

A structured reference graph

A single lookup that returns the date it entered the exploited-vulnerability catalogue and its due date.

Which attack technique does it enable?

Live web crawl

Technique pages are written for people. Matching a CVE to a technique across several sites is a research task.

Plain RAG

Chunks of text carry no relationships, so the link between CVE, weakness and technique is guessed by the model.

A structured reference graph

A stored link that says which source stated it, or that we inferred it.

What already detects it?

Live web crawl

Detection rules live in separate repositories with different formats.

Plain RAG

Similar-looking rule text comes back, not the rules mapped to this technique.

A structured reference graph

Detection rules from several public rule sets, linked to the technique.

What does the response look like?

Live web crawl

Playbooks are PDFs and wiki pages.

Plain RAG

A procedure comes back with no link to the detection that triggered it.

A structured reference graph

A link from a detection to the procedure that handles it, where one exists.

Always check the snapshot date before acting on an answer from any reference source.

A source that answers in milliseconds leaves your agent time to think

Lattice is a read-only MCP server over a cybersecurity knowledge graph: CVEs, ATT&CK techniques, weaknesses, threat actors, detections and response procedures. Each link says which source stated it and whether it was stated or inferred. There is no model in the path and no write tool, so a lookup does one thing and returns.

Median tool time is under 100 ms for every tool. The slowest median we measured is 17.8 ms, so the claim leaves room for your network and for slower days.

Median round trip per tool, in milliseconds, against a 100 ms budget

  • graph_lookup4.1
  • graph_search3.9
  • graph_meta4.1
  • graph_path · cve-to-defense5.9
  • graph_path · technique-coverage10.4
  • graph_path · actor-ttps17.8

Measured 30 September 2026. Full MCP round trip, median of 200 sequential calls per case, measured on the same host as the server. It is not the hosted service over a network; add your own round trip.

about 20 ms

for a three-call enrichment of one CVE (4.1 + 5.9 + 10.4).

under 0.2%

of the 15-second window. The rest is left for reasoning.

What an agent does with it

  1. T+0 msgraph_lookup id=CVE-…4.1 ms
  2. T+4 msgraph_path template=cve-to-defense5.9 ms
  3. T+10 msgraph_path template=technique-coverage10.4 ms
  4. Then your agent reasons over the stated and inferred links. Set it to propose reversible actions first and to ask a person before anything irreversible.

Read these limits first

Request a trial key for Lattice →

Last verified 2 October 2026. Attack-speed figures are quoted from the publishers named above. This page gives general guidance; follow your organisation's own incident plan where it differs.

Start with one piece of work.

Give us one piece of work and read access to one system. We map it and come back with what we found, what we would build and what it would take — before any commitment. You decide using our output, not our pitch.

Talk to us