SecureSMB Consult an Expert
Article

The First 24 Hours of a Data Breach: A Small-Business Checklist

Last updated: July 2026 · 7 min read · By the SecureSMB Editorial Team

A breach is stressful, but a calm, rehearsed first day limits the damage. Print this and keep it near the office phone.

Hour 0–2: Contain

Hour 2–8: Assess

What data was exposed? How did they get in? Loop in your IT/Managed Service Provider and, for PHI, review HIPAA breach-notification duties.

Hour 8–24: Notify & document

Notify affected customers and authorities per your obligations and your disclaimer posture. Document every step — it matters for insurers and regulators. Our ransomware guide has the prep that makes this easier.

Frequently Asked Questions

Should I notify customers immediately after a breach?

Yes, within 60 days for most regulations (GDPR 72 hours). Notify law enforcement first if there's an active investigation. Prepare a clear communication plan: acknowledge the breach, explain what happened, what data was involved, what you're doing to fix it, and how customers can protect themselves. Transparency builds trust.

What if we don't have cyber insurance?

You'll bear all costs yourself: forensic investigation, legal fees, notification costs, credit monitoring for affected individuals, regulatory fines, and potential lawsuits. Budget $50,000-$500,000+ for a significant breach. Cyber insurance typically costs $1,000-$5,000/year for small businesses - a small price for protection against catastrophic costs.

S

About the SecureSMB Editorial Team

Our reviewers are security practitioners who write plain-English guidance for small businesses. Every guide is reviewed for accuracy and updated as the threat landscape changes.

Was this helpful?

Get our free 10-employee security checklist and a monthly roundup of new guides. Join the newsletter →