Skip to content
Tech

Your Company Just Got Breached. What To Do In The First 48 Hours

The earliest decisions after a security incident shape the legal, financial and customer fallout. Here is the order of operations for a small company without a security team.

Feature illustration for “Your Company Just Got Breached. What To Do In The First 48 Hours”

The first sign of a breach rarely looks like one. It is a customer reporting a strange email from your domain, an engineer noticing an unfamiliar login, or a ransom note on a server.

What a company does in the hours that follow shapes everything after: how much data is lost, whether evidence survives, how large the legal exposure becomes and whether customers keep trusting you. Small companies without a security team tend toward two opposite mistakes. They either panic and wipe everything, destroying evidence, or they wait too long hoping the problem is minor.

Hour one: contain without destroying

Your first goal is to stop the damage from spreading while preserving a record of what happened. Disconnect affected machines from the network rather than switching them off, since powering down can erase evidence held in memory. Disable compromised accounts, revoke active sessions, and rotate credentials and API keys that may have been exposed, starting with administrator and cloud accounts.

Do not delete logs, reimage servers or restore from backup yet unless the damage is ongoing and there is no other way to stop it. Investigators need the logs to establish what was accessed, and that answer determines your notification obligations.

Start a written timeline immediately. Record who noticed what, when, and every action taken. Memories fade quickly, and a contemporaneous record is valuable to investigators, insurers and lawyers.

Make three phone calls

Call your cyber insurer if you have a policy. Many policies require prompt notice and give access to approved breach lawyers and forensic firms. Hiring your own vendors before calling the carrier can complicate coverage.

Call a lawyer with data breach experience. Counsel can direct the investigation, advise on notification duties and help shape communications. In some cases, engaging a forensic firm through counsel can help protect the confidentiality of the investigation, though that protection is not guaranteed and depends on how the work is structured.

Call a qualified forensic investigator, through your insurer or counsel. Their job is to determine how the attacker got in, what they accessed and whether they are still inside.

If the incident involves extortion, ransomware or stolen funds, report it to law enforcement. The FBI's Internet Crime Complaint Center accepts reports, and your local FBI field office is another option.

If systems are encrypted and attackers demand payment, do not negotiate on your own. Paying does not guarantee working decryption or deletion of stolen data, and payments to sanctioned parties can create legal problems of their own. Your lawyer, insurer and forensic firm should guide that decision. Check whether your backups are intact and isolated from the affected network before assuming you can restore.

Work out who must be told

Every US state has a data breach notification law, and the laws differ on what counts as personal information, what triggers notice, who must be notified and how quickly. Some require notice to a state attorney general or other regulator as well as to affected individuals. Federal rules may apply in sectors such as health care and financial services, and many customer contracts carry their own notification deadlines.

This is why the scope of the investigation matters so much. You cannot decide who to notify until you know whose data was accessed and what kind. Counsel should map the requirements based on where affected people live, not where your company is based.

Contract obligations often move fastest. Enterprise customers commonly require notice within a short, fixed window after you discover an incident affecting their data. Pull those contracts early.

Communicate carefully

Speak accurately, and only about what you know. Early statements that play down an incident and are later contradicted do lasting damage. Designate one spokesperson, prepare a holding statement and route all outside questions through it.

Tell employees what happened and what to say if a customer asks, and warn them about follow-up phishing. Attackers often exploit the confusion after a breach by impersonating the company or its suppliers.

What to do before it happens

Write a short incident response plan now: who leads, who to call and where the contact list lives offline. Store your insurer's claims number and a breach lawyer's contact details somewhere outside your company systems.

Turn on logging in your cloud, email and identity systems, and confirm logs are retained long enough to be useful in an investigation. Test restores from backup, and keep at least one backup copy that ransomware on your network cannot reach.

Inventory where personal data lives. The faster you can say what was in an affected system, the faster you can meet your obligations and the fewer people you may need to alarm.

This is general information, not legal advice. Speak to a qualified attorney in your jurisdiction before acting on any of it.

Sources

FTC — Data Breach Response: A Guide for Business

NIST — SP 800-61 Rev. 3, Incident Response Recommendations

FBI — Internet Crime Complaint Center (IC3)

Related