Why Do the First Hours Dominate the Outcome?
Three clocks start at discovery: the attacker's, exfiltration and lateral movement continue until real containment; the evidence clock, logs rotate and volatile traces vanish, taking attribution with them; and the regulatory clock, CERT-In's six-hour reporting window for covered incidents and DPDP breach duties do not wait for convenient facts. Panic actions, mass shutdowns, quiet clean-ups, premature denials, routinely destroy more value than the intrusion did.
What Is the 72-Hour Sequence?
The order that experienced responders enforce:
- Contain without destroying: isolate affected segments; do not wipe and rebuild the evidence
- Preserve forensically: images and logs under chain of custody before anything is 'fixed'
- Assess honestly: what data, what systems, how long, scope creep is normal; plan for it
- Notify correctly: CERT-In, DPDP duties, contracts and insurers, with counsel, on the clock
- Communicate once, truthfully: the walked-back denial is the reputational kill-shot
Where Does Investigation Extend Response?
Beyond the technical rebuild: insider-involvement inquiry where access patterns suggest it; dark-web monitoring for the stolen data surfacing; threat-actor engagement assessment in extortion cases; and litigation-grade documentation for the disputes that follow. Garuda pairs its cyber team with forensic investigators for exactly this joint response.