Module 4 · Lesson 4.5
What NOT to do during an incident
Actions taken in panic can make an incident worse. Avoid these common mistakes.
Always watching. Always protecting.
Do NOT:
- Ignore it or assume someone else reported it
- Attempt to “fix” the issue yourself
- Delete suspicious emails or logs
- Power off systems unless instructed
- Discuss the incident publicly or on social media
- Warn a suspected malicious insider directly
Why this matters
Security teams rely on evidence. Deleting files, altering systems, or spreading information can compromise investigations and increase damage.
Remember: Report fast. Preserve evidence. Follow guidance.