The first 48 hours of a cyber crisis are the most critical. This is the period when quick decisions are made under pressure and often in the dark. Getting these early decisions right or wrong often make the difference between a quick resolution or protracted and complex response. This session delves into the components of the first 48 hours of a response and provides attendees useful insights regarding how to set up the technical elements of a response and what the objectives should be within the first 48 hours. Actions that can impact the overall response, either positively or negatively, will be examined. Takeaways and lessons from the frontline of cyber incident response will also be shared.