I’ve worked a lot of incident response cases, and one question that almost always comes up is, “How long will this take?” Or the client has an expectation that they’ll be up and running in a few hours. Unless they have parallel, unaffected infrastructure, or have the ability to snapshot the currently compromised environment so it can be forensically analyzed offline, and then perform an instant restore of the live environment to prior to the cyber event, they need to have proper expectations set.
I came up with this infographic to lay out the typical timeline of events from compromise to business resumption and share it when appropriate. Let me know if you find it useful.
(Click to enlarge)

Viscount Jan Broucinek
