🗃️ Data Breach (General)
You suspect or have confirmed that data was accessed, exposed, or exfiltrated without authorization.
Right now
- Contain the exposure — revoke access, take affected systems offline if needed, and stop ongoing data loss.
- Do not delete logs or evidence — you'll need them for investigation and any required notifications.
- Notify your Incident Lead and, if you have one, your cyber insurance carrier.
First few hours
- Determine what data was involved (personal data, health data, payment data, etc.) and how many individuals may be affected.
- Engage legal counsel promptly — notification timelines and requirements vary significantly by data type, state, and industry.
- Preserve logs, system images, and other evidence for investigation.
Recovery & notification
- Work with legal counsel to determine notification obligations — this may include individuals, state attorneys general, HHS (for PHI), or credit reporting agencies, depending on what was exposed.
- Prepare clear, factual communication for affected individuals if notification is required.
- Conduct a post-incident review and update your Incident Response Policy and controls based on lessons learned.
Notification obligations
Notification requirements vary widely: most US states have their own breach notification laws with different timelines and thresholds; HIPAA requires notification within 60 days for PHI breaches (sooner for large breaches); GDPR requires notification to regulators within 72 hours for EU personal data. This is genuinely complex — engage legal counsel promptly rather than guessing at your obligations.