# If you think you're compromised right now — a first-60-minutes reference **What this is NOT:** a complete incident response plan, a substitute for your state drinking-water primacy agency's requirements, or professional incident-response support. It's a one-page orientation for the first hour, sized for a utility without a security team — consistent with `PHASED_ROLLOUT.md` Phase 4's own framing ("a one-page playbook, not a SOC"). ## First, and above everything else below **Safety of the water system and the people who depend on it comes before anything in this document.** If continuing safe operation requires an action that conflicts with any step below, do the safe thing. Evidence preservation is always secondary to public health and safety — nothing here should ever delay an action needed to keep the system operating safely. ## Call, don't wait - **CISA, 24/7:** report@cisa.gov · **(888) 282-0870** — report anomalous activity even before you're fully sure. That's what the line is for. - **Ask about mandatory reporting on that first call.** There is a federal reporting regime — **CIRCIA**, the Cyber Incident Reporting for Critical Infrastructure Act — with a **72-hour** clock for a covered entity's substantial cyber incidents and **24 hours** for a ransom payment. Whether, and exactly when, it binds *your* utility turns on rulemaking status and your covered-entity determination, and this document deliberately will not answer that for you. But make it your first question on the call: if a clock is running, it started when the incident did, not when you finish investigating. - **Your state drinking-water primacy agency.** Many states have their own incident-reporting requirement on top of the federal one; this varies by state and isn't something this document can state accurately for all fifty — check locally. - **EPA's Cybersecurity Technical Assistance Program** (see `RESOURCES.md`) can be engaged for ongoing help, not only active emergencies. ## Before you touch anything, if it's safe to wait even a few minutes - **Don't reimage, reboot, or "test if it's fixed" by reconnecting to the internet** before someone has looked at what's there. A wiped device can't be examined afterward. - **Do write down what you saw and when** — what looked wrong, what time, who noticed it, what's different from normal. Plain notes are real evidence. - **Do preserve logs if you can do it safely** — PLC event logs, engineering-workstation logs, firewall/network logs, HMI alarm history. Copy them off rather than letting normal rotation overwrite them. - **Do isolate, if it doesn't compromise safe operation** — pull the affected segment off the network rather than the internet at large, if that's enough and operations allow it. - **Do coordinate off the suspect network.** If an intruder is in your email or your network, planning the response *there* tells them exactly what you know and how fast you're moving. Use phones, or accounts that don't live on the affected systems, until you know what's clean. ## After the immediate moment - Work the phased rollout (`PHASED_ROLLOUT.md`) — Phase 0's exposure check and inventory apply doubly once you know something happened. - Loop in an integrator or the EPA technical assistance program before making permanent configuration changes under pressure. --- *l0gic — Patrick Crosby, 2026-08-03. General orientation only — not a substitute for your primacy agency's requirements or professional incident-response support.*