Minutes 0–15: Stop the bleeding Confirm the loss: amount, beneficiary, time of sendCall your bank's fraud line immediately — push for SWIFT recall on internationalFreeze related accounts if there's any chance of follow-on activityPreserve evidence — full email headers, screenshots, logs (no edits) Minutes 15–30: Activate the response team Incident commander: typically CISO, CFO, or legalCommunications: tight loop only — don't broadcast yetExternal counsel + IR retainer (Cyberphoenix or equivalent)Filing: FBI IC3 for US, plus local cybercrime authority Minutes 30–60: Contain and assess Identify how the attacker got in — compromised inbox, lookalike domain, BEC chainForce-reset credentials and revoke all sessions for impacted accountsSearch for parallel activity — is this a single wire or a campaign?Notify partners and vendors if they may be next Hour 1+: Recovery + post-mortem Engage on-chain forensics if crypto involvedDocument a factual timeline for insurance and regulatorsPlan the post-incident drill for the same scenario// Continue the conversationNeed help applying this?Talk to a senior Cyberphoenix consultant - free, no obligation.Book a consultation