Blog

September 4, 2026

What You Lose in the First 24 Hours After a Breach

Digital Forensics

By INGITE Research Team
2026-09-04
8 min read
Digital Forensics

Quick answer

The evidence that explains a breach starts disappearing before anyone even opens a ticket. — volatile memory, session logs, and default-retention firewall data are gone within days, and by the time a formal investigation starts, a lot of the trail is already unrecoverable.

  • Breaches still take 241 days on average to identify and contain, far longer than most logs are kept.
  • Missing logs due to short retention doubled year over year in incident response cases reviewed in 2025.
  • The turn: the biggest forensic gap isn’t a missing tool. It’s a clock nobody set on purpose.

A laptop gets flagged for unusual activity on a Friday afternoon.

IT isolates it, opens a ticket, and moves on. The investigation gets scheduled for Monday.

By Monday, the machine has been rebooted twice — once by a well-meaning technician, once by an automatic update.

The memory that held the attacker’s session is gone. So is half the network log that would have shown where the traffic went.

Nobody destroyed evidence on purpose. It just expired, the way it always does when nobody is racing the clock.

The clock nobody set on purpose

Most incident response plans focus on containment: isolate the device, block the account, rotate the credentials. That part usually works.

What gets skipped is the fact that containment and preservation are not the same action — and doing one without the other can quietly erase the ability to explain what happened.

241 daysaverage time to identify and contain a breach — 181 to detect, 60 to containIBM, Cost of a Data Breach Report, 2025
2xyear-over-year increase in cases where missing logs blocked the investigationSophos, Active Adversary Report, 2026
393 daysaverage dwell time in intrusions using long-term backdoors, longer than most log retention windowsMandiant, M-Trends Report, 2026

Put those three together and the pattern is obvious: the investigation almost always starts after the evidence window has already closed on part of the story.

What actually goes invisible, and how fast

Volatile memory

RAM holds the attacker’s live session, decrypted payloads, and process activity that never touches disk. A reboot — even an automatic one — wipes it completely and permanently.

Firewall and network session logs

Default retention on a lot of firewall appliances is seven days. Some are set to 24 hours. If the investigation opens on day eight, that path is closed for good.

Endpoint process history

What ran, when, launched by what — this is exactly what shows how an attacker moved between machines. Most endpoints don’t keep it long unless something is explicitly recording it.

Cloud and identity provider logs

Login history and API activity from SaaS platforms often live on a rolling window too. Without an export, that record ages out the same as everything else.

Why this matters in an audit

“We contained it” answers one question. “We can show exactly how it happened, on what machines, and when” answers the one an auditor, a regulator, or a cyber insurer actually asks. Only one of those requires evidence that survives past the first day.

Containment stops the damage. Only preservation lets you prove what the damage was.

Fragmented evidence makes the case, one source doesn’t

Even when logs survive, they’re rarely in one place. Palo Alto Networks’ Unit 42 reviewed its 2025 incident response caseload and found investigators needed evidence from two or more distinct sources to establish what happened in 87% of cases — sometimes as many as ten.

Endpoint telemetry, firewall logs, identity provider records, cloud audit trails. Each one alone tells part of the story. None of them, alone, tells all of it.

That’s the real argument for centralizing endpoint evidence before an incident happens, not during one. Reconstructing a timeline from five disconnected consoles under deadline pressure is where investigations lose days they don’t have.

What to lock down in the first 24 hours

  1. Stop the reboot reflex.The instinct to restart a compromised machine is the single most common way volatile memory gets destroyed before anyone captures it.
  2. Snapshot before you isolate.Pull a memory image and a disk snapshot before changing network state, not after — isolation itself can trigger cleanup scripts on some malware.
  3. Export the logs that expire soonest.Firewall and identity provider logs on short retention windows need to be pulled out immediately, before the rolling window closes on their own schedule.
  4. Write down the chain of custody from minute one.Who touched the device, when, and what they did to it. Evidence without a documented chain is evidence a court or an insurer can challenge.
Technical note

Standard forensic practice collects evidence in order of volatility — memory, then network state, then disk, then archived logs — because each layer decays at a different speed. A response plan that jumps straight to disk imaging is already working with an incomplete picture.

How INGITE helps

Cloud Digital Forensics Investigation

Keeps endpoint activity, process history, and event timelines centralized and retained, so an investigation that starts on day eight can still see what happened on day one.

See the solution

Cloud EndPoint Security

Flags anomalous behavior and isolates devices without requiring a reboot, so the machine stays contained and its memory stays intact for the investigation that follows.

See the solution

If an incident started right now, would the evidence still be there tomorrow?

Not whether you’d contain it. Whether, a week from now, you could show exactly what happened and prove it.

  • Does your incident response plan separate containment steps from preservation steps?
  • Do you know the retention window on every log source you’d need — firewall, identity provider, endpoint?
  • Is there a written rule against rebooting a suspect machine before memory is captured?

If the honest answer to any of those is “we’d figure it out in the moment,” the gap isn’t your response speed. It’s that nobody set the clock before it started running.

What is the most important evidence to preserve in the first 24 hours of an incident?
Volatile memory comes first, because it’s destroyed by a simple reboot and holds the attacker’s live session and decrypted activity. After that, network and firewall session logs matter most, since many appliances default to seven days of retention or less. Disk images and archived logs decay more slowly and can typically wait.
How long does it take to detect and contain a data breach in 2026?
According to IBM’s Cost of a Data Breach Report 2025, organizations take 241 days on average to identify and contain a breach — 181 days to detect it and 60 more to contain it. That’s the fastest pace in nine years, but still far longer than most logs are retained by default.
Why do incident investigations rely on more than one log source?
No single system captures the full picture. Palo Alto Networks’ Unit 42 Global Incident Response Report 2026 found that investigators needed evidence from two or more distinct sources in 87% of cases, and up to ten in the most complex ones, combining endpoint, network, identity, and cloud telemetry to reconstruct what happened.
Should a compromised device be rebooted before an investigation starts?
No. Rebooting a suspect machine, even automatically through a scheduled update, destroys the contents of volatile memory permanently. Standard forensic practice is to capture a memory image before making any change to the device’s power or network state.

Make sure the evidence survives long enough to matter

Cloud Digital Forensics Investigation keeps endpoint history and event timelines centralized, so an investigation started days later still has a day-one picture to work from.

Discover Cloud Digital Forensics Investigation