0–4 hours — contain and preserve. The defensible order is not a fixed product list: confirmed compromise or possible ICS Level 3/2/1 reach outranks product severity. If evidence is otherwise equal, handle internet-exposed Cisco FMC first, F5 APM second, and TeamCity third. Check Point jumps to first place on unauthorized VPN sessions, directory scanning, unknown administrators, or configuration changes; disable the affected VPN gateway or fail over to a known-clean unit, revoke sessions, and preserve logs. Disconnect Cisco FMC on unknown admin/API activity, configuration manipulation, or movement toward managed firewalls; remove an F5 APM VIP from service on unexplained privileged sessions, policy changes, or command execution; isolate TeamCity server and agents and freeze releases on rogue builds, plugins, users, or token use. Disconnect MikroTik equipment on unauthorized configuration, scheduler/script changes, unexpected tunnels, or evidence of process-network reach. A vulnerable Linux kernel alone does not justify isolation; isolate only on privilege-escalation evidence, unexpected kernel modules, root persistence, or credential access. Immediately export VPN/session, authentication, administrative audit, configuration-change, network-flow, EDR, TeamCity build/agent, and Linux audit/kernel logs to immutable storage before rebooting anything.
By 24 hours — close access and establish integrity. Restrict every affected management plane to approved administration networks; stage and test vendor fixes or documented mitigations before production deployment, prioritizing exposed systems. Exact affected versions, fixed releases, and validated detection signatures are not established in the evidence available here, so change teams must confirm them against the relevant vendor advisory. Revoke active sessions and API tokens immediately, then rotate credentials reachable from any confirmed-compromised appliance: device administrators and directory bind accounts for network appliances; VCS, registry, cloud, deployment, signing, and agent credentials for TeamCity; root, service, SSH, and cloud-instance credentials for compromised Linux hosts. Do not rotate CA keys merely because Check Point certificate validation was exploited—do that only if key access, export, or signing misuse is found. Rebuild rather than patch any device with integrity loss, and validate restored configurations against a known-good baseline.
By 72 hours — eradicate and recover. Finish tested patching or replacement across the remaining exposed tier, reboot updated Linux systems where required, re-enrol clean TeamCity agents, and conduct a retrospective hunt across identity, VPN, directory, build, firewall-management, and east-west traffic. FCEB agencies must map actions to BOD 26-04; other organizations should treat it as prioritization guidance, not a binding deadline. What can wait: non-exposed systems with compensating access controls and no compromise evidence, enterprise-wide credential resets unrelated to reachable secrets, CA re-keying without theft evidence, and AI-specific tooling—the immediate problem is exploit speed and scale, not a new exploit class.