A breach is stressful, but a calm, rehearsed first day limits the damage. Print this and keep it near the office phone.
Hour 0–2: Contain
- Isolate affected systems from the network (unplug/disable Wi-Fi).
- Reset credentials for compromised accounts; enable MFA if off.
- Preserve logs — don't wipe evidence.
Hour 2–8: Assess
What data was exposed? How did they get in? Loop in your IT/Managed Service Provider and, for PHI, review HIPAA breach-notification duties.
Hour 8–24: Notify & document
Notify affected customers and authorities per your obligations and your disclaimer posture. Document every step — it matters for insurers and regulators. Our ransomware guide has the prep that makes this easier.
Frequently Asked Questions
Should I notify customers immediately after a breach?
Yes, within 60 days for most regulations (GDPR 72 hours). Notify law enforcement first if there's an active investigation. Prepare a clear communication plan: acknowledge the breach, explain what happened, what data was involved, what you're doing to fix it, and how customers can protect themselves. Transparency builds trust.
What if we don't have cyber insurance?
You'll bear all costs yourself: forensic investigation, legal fees, notification costs, credit monitoring for affected individuals, regulatory fines, and potential lawsuits. Budget $50,000-$500,000+ for a significant breach. Cyber insurance typically costs $1,000-$5,000/year for small businesses - a small price for protection against catastrophic costs.