In this non-enterprise scenario there are basically 6 broad layers this problem could be. Application, Security, OS, Network device, or Server. Many paths. It can be paralyzing, this is where experience comes in.
In large incidents you may encounter varying levels of "hot potato" between departments where no path is selected because there is no incident command. You can learn to be that person.