Skip to main content

The "Something's wrong" panic button

A guided response for a suspected breach: preserve evidence into a hashed, read-only bundle, contain the threat with preview and undo, and start the NIS2 clock.

Written for whoever runs IT8 min readUpdated

The red Something's wrong button on Home is for the moment you suspect a real breach and are not sure what to do first. It walks you through three things, in order: say who or what this is about, preserve the evidence you already have before anything else changes, and then decide what to contain. It also starts an informational NIS2 24-hour/72-hour clock from the moment you say you first noticed, so you never lose track of it while you work.

Starting a guided response

Pick what this is about — a person with a Qorionix account, an external identity such as a Microsoft 365 account that has never signed in to Qorionix, or a device — and say in a sentence what made you suspicious. Then answer one more question: when did you first notice this? If it was earlier than right now, say so. That moment, not the moment you opened this page, is what starts the NIS2 clock.

Preserving evidence

Before you contain anything, pick the recent SIEM incidents that belong to this session. The server fetches each one itself from the record — it never trusts what your browser sends — and builds one snapshot containing their details, then computes a sha256 hash of that exact snapshot. The result is stored read-only: the database itself refuses any later attempt to edit or delete it, by anyone, including Qorionix's own systems. That is what makes the hash worth anything — a record that could quietly change afterwards would prove nothing.

You can preserve evidence more than once as a session develops; each capture is its own permanent, hashed snapshot.

Containment: preview, approve, undo

This step does not reinvent anything: it opens the same containment plan builder used everywhere else in the console (from a person's row in Access, from a device's row in Threats). You get a dry-run preview of every step — ending sessions, disabling the Microsoft 365 / Entra ID session where connected, isolating a device, queuing credential rotation — before anything runs. Nothing executes until you approve it, and most steps can be undone afterwards from the plan's own page. See Containment plans for what each step does and which can be undone, and Isolating a machine for what isolating a device costs.

The NIS2 clock

NIS2 Article 23 expects an early-warning notice within 24 hours of becoming aware of a significant incident, and a fuller notification within 72 hours. This page shows both deadlines computed from the moment you stated, and marks either as overdue in red once it passes. This is informational only — it is not itself a filing, and nothing is sent anywhere automatically.

Once you have built a containment plan for this session, its own status page can draft the NIS2 early-warning notice from the same facts — the plan, its steps and their timing — the same evidence-bound drafting described in Evidence-bound drafts. A human still reviews, edits and files it; nothing leaves the product on its own.

Who did what

Every session records who started it and when, who preserved which evidence, which containment plan (if any) belongs to it, and who closed it and why. Closing a session is a separate, explicit step — it only marks the session itself as resolved; a linked containment plan keeps its own independent status, and preserved evidence is never affected by closing the session it belongs to.

Who can use this

The panic button uses the same permission as building a containment plan (response:containment.execute). A role without it does not see the button at all on Home, rather than seeing it disabled — the same rule this console applies to every destructive, admin-only action.

Was this article wrong?

If a procedure here does not match what you see, or a limit we described has changed, tell us and we will fix the page. Email us about this article, or see how to get help if you need an answer rather than a correction.

Everything in alerts and response