At that point, you very likely have something that occurred to indicate that there is an incident, so you may very well have sensitive data being actively exfiltrated from the environment, so doing nothing at all could be extremely detrimental/harmful to the organization.On the other hand, grabbing systems, running AV scans, deleting files, even wiping systems and reinstalling them can also be har