Incident Response

🗃️ Data Breach (General)

You suspect or have confirmed that data was accessed, exposed, or exfiltrated without authorization.

Right now
  • Contain the exposure — revoke access, take affected systems offline if needed, and stop ongoing data loss.
  • Do not delete logs or evidence — you'll need them for investigation and any required notifications.
  • Notify your Incident Lead and, if you have one, your cyber insurance carrier.
First few hours
  • Determine what data was involved (personal data, health data, payment data, etc.) and how many individuals may be affected.
  • Engage legal counsel promptly — notification timelines and requirements vary significantly by data type, state, and industry.
  • Preserve logs, system images, and other evidence for investigation.
Recovery & notification
  • Work with legal counsel to determine notification obligations — this may include individuals, state attorneys general, HHS (for PHI), or credit reporting agencies, depending on what was exposed.
  • Prepare clear, factual communication for affected individuals if notification is required.
  • Conduct a post-incident review and update your Incident Response Policy and controls based on lessons learned.
Notification obligations

Notification requirements vary widely: most US states have their own breach notification laws with different timelines and thresholds; HIPAA requires notification within 60 days for PHI breaches (sooner for large breaches); GDPR requires notification to regulators within 72 hours for EU personal data. This is genuinely complex — engage legal counsel promptly rather than guessing at your obligations.

Developed and supported by iConsulting — a working vCISO practice.Contact us for vCISO services →