The organization should:

  • Assess the impact and classify the incident
  • Contain and mitigate the threat
  • Activate the incident response process
  • Prepare for regulatory reporting (if significant)