The first and most important step.
WHY IT COMES FIRST
Evidence is destroyed by ordinary activity, quickly and permanently.
WHAT DESTROYS IT
Continued use of the system Restarting or shutting down Logging in to examine Running software on it Deleting files Rebuilding Logs rotating and expiring
WHY RESTARTING MATTERS
Information held only in memory is lost, and some systems clear temporary data.
WHAT TO DO FIRST
Stop using the system.
WHAT TO DECIDE
Whether to leave it running or power it off.
WHY IT IS A DECISION
Leaving it running preserves memory and risks continued activity; powering off preserves the disk and loses memory.
WHAT TO CONSIDER
Whether harm is continuing Whether the memory content matters Whether encryption means powering off loses access
WHAT TO ESTABLISH
That the decision is made deliberately and recorded.
WHAT TO PRESERVE
Disk contents Memory, where the capability exists Logs, from the system and from elsewhere Network records Anything with a retention period about to expire
WHY LOGS ELSEWHERE
Logs on the affected system may be altered; logs collected centrally may not.
WHAT TO PRIORITISE
Anything that expires soonest.
WHAT TYPICALLY EXPIRES QUICKLY
Firewall and network records Provider logs Authentication records
WHAT TO DO
Request retention from providers immediately.
WHY IMMEDIATELY
They discard on a schedule and cannot recover afterwards.
WHAT TO RECORD
What was preserved, when, by whom and how.
WHAT TO ESTABLISH
Where preserved material is held, securely.