Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you suspect a nation-state intrusion, activate your incident-response plan, coordinate a controlled containment decision, preserve evidence before making changes, and investigate beyond the first affected device or alert. Bring security, IT, leadership, legal, communications, and business-continuity teams together, and contact qualified incident responders and appropriate authorities. Do not assume that shutting everything down is safest—or that removing visible malware means the attacker is gone.

What to do first

Treat a credible alert as a potential enterprise incident until investigators establish its scope. CISA’s November 2022 advisory on an Iranian government-sponsored APT compromise recommends isolating affected systems, reviewing logs and artifacts, capturing memory and forensic images, considering third-party incident-response support, and reporting to CISA or the FBI. That sequence applies to the activity covered by that advisory; it is not an instruction to disconnect every system in every environment.

  1. Activate the incident-response plan. Name an incident lead, establish who can approve containment and service interruptions, and open a trusted communications channel that does not rely on accounts or systems that may be compromised.
  2. Contain based on the evidence and operational risk. Work with responders and system owners to isolate affected devices or services in a controlled way. Consider business-critical dependencies before disrupting systems.
  3. Preserve evidence before making changes. Before wiping, rebuilding, or applying changes that could destroy evidence, have responders consider what must be collected and how. Preserve relevant logs and artifacts; capture system memory and forensic images where appropriate.
  4. Expand the investigation. Look beyond the first alert for lateral movement or persistence in connected systems, domain controllers, identity services, cloud environments, networks, email, remote access, administrator accounts, and relevant third-party access.
  5. Bring in qualified help and notify appropriate authorities. Use incident-specific expertise where internal capacity, independence, or forensic capability is insufficient. Have counsel promptly assess reporting duties as well as voluntary reporting options.

Should you shut down affected computers?

Not automatically. Shutting down a device can interrupt attacker activity, but it can also destroy volatile evidence, including information in memory. Leaving a system connected can allow activity to continue. The right choice depends on what is happening, what the system supports, the risk to other systems, and what evidence responders need.

Make a controlled containment decision

Consult incident responders and the relevant system owner as quickly as circumstances allow. They can weigh isolation, disconnection, shutdown, or another containment measure against the need to preserve evidence and keep essential operations running. CISA’s Iranian APT advisory calls for immediate isolation of affected systems in the incident pattern it addresses, alongside log and artifact review and memory capture. It should not be read as a universal instruction to power off or disconnect every device in a suspected intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Preserve the evidence that can answer what happened

Depending on the environment, preserve identity-provider, cloud, endpoint, network, email, remote-access, and administrator logs. Keep an incident timeline, record decisions and system changes, and restrict access to collected evidence. Coordinate collection and handling with responders so investigative work does not accidentally overwrite or alter material needed for analysis.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to find out whether the attacker still has access

The first compromised system is not necessarily the only one. CISA’s Iranian APT case guidance specifically calls for investigation of connected systems and domain controllers for lateral movement. CISA and NSA’s joint advisory on PRC state-sponsored activity, whose version history runs through September 3, 2025, describes activity affecting enterprise environments and customer-facing systems and provides tactics, techniques, and procedures for detection and threat hunting.

Scope the systems and access paths your organization uses

  • Identity: Review relevant accounts, administrator access, authentication activity, and access to identity services.
  • Endpoints and servers: Investigate connected systems and domain controllers, as well as devices or servers implicated by alerts and collected evidence.
  • Cloud and network: Examine relevant cloud environments, network activity, and customer-facing systems for signs that match the incident evidence.
  • Email, remote access, and third parties: Include these paths when they are part of your environment or could provide access to affected systems.

Use the evidence to decide how far to extend the investigation; do not treat this list as proof that every category is compromised. Ask responders to assess what access or persistence needs to be revoked and how to validate that the suspected intrusion has been contained and eradicated.

Who should be involved and who should you call?

Set up a decision-making team

Include the CISO or security lead, IT and cloud administrators, executive decision-makers, legal counsel, communications, business-continuity staff, and relevant product or service owners. Involve the cyber insurer or managed provider if your existing arrangements call for it. Assign one incident lead and use a communications channel that is not dependent on potentially compromised accounts or systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

CISA leadership guidance emphasizes including senior business leadership and board members in incident plans, and empowering the CISO in company risk decisions. Before an incident, a tabletop exercise can clarify who has authority to approve containment, service interruptions, customer communications, and recovery decisions.

Engage incident responders when internal capability is not enough

CISA’s Iranian APT advisory recommends considering a third-party incident-response organization to help ensure eradication and reduce the risk of residual issues enabling follow-on exploitation. When assessing a provider, consider its experience with relevant state-sponsored intrusions, forensic and cloud or identity expertise, availability, independence, evidence-handling practices, scope and deliverables, and commercial terms. Government advisories cited here do not rank or endorse providers.

Contact the appropriate authorities

For U.S. organizations, CISA and the FBI are reporting channels identified in the cited CISA advisory. Confirm current agency contacts and reporting procedures directly with official sources. Outside the United States, contact your national cyber authority and consider law enforcement, the privacy or sector regulator, and local counsel as applicable.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Do you have to report the incident, and how quickly?

There is no single reporting deadline established for every organization by the cited sources. Requirements depend on where you operate, your sector, contracts, what information was affected, and the facts of the incident. CISA’s joint advisory says organizations should consider mandatory reporting requirements under applicable laws and regulations, alongside voluntary reporting to appropriate cyber or law-enforcement agencies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ask counsel to determine the applicable obligations promptly. A voluntary report does not replace a mandatory report. CISA’s small-business guidance also encourages victims to report incidents promptly; reporting can help agencies understand targeting, deploy resources, and share warnings with other defenders.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to recover after containment

Do not equate removing visible malware with eradicating an intrusion. Recovery decisions depend on the evidence and the systems involved; the cited advisories do not prescribe one recovery sequence for every organization.

  1. Work with responders to confirm the scope of compromised systems and identities, and determine what access or persistence must be revoked.
  2. Assess the environment and protect backups and recovery credentials before restoring services.
  3. Restore from known-good sources only after the team has evaluated the environment and is ready to validate recovery.
  4. Document the incident, remediate exploited weaknesses, and monitor for signs of recurrence.

What to improve after the incident

Preparedness work is separate from urgent containment and investigation. CISA recommends phishing-resistant multifactor authentication (MFA) where feasible. FIDO/WebAuthn is one phishing-resistant option: an authenticator may be a separate physical USB or NFC token, or it may be built into a laptop or phone.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Before choosing an MFA approach, check support in your identity provider and applications, enrollment procedures, backup authenticators, account-recovery controls, manageability at your organization’s scale, and accessibility for users. A physical security key can be part of an account-protection plan; it does not detect, investigate, or contain an active intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.