The short version
- Call first, fix second. Your cyber insurer's breach hotline, or your broker, should be the first outside call. Many policies require it before you spend money.
- Contain without destroying. Disconnect affected devices from the network, but do not wipe, rebuild, or turn them off until forensics says so.
- If money moved, call the bank now. In 2024, the FBI's Recovery Asset Team froze about 66% of the funds in the fraud cases it worked on. Speed is what makes that possible.
- Do not pay, negotiate, or announce anything without the insurer's breach attorney.
- The clock is running. Washington requires notice to affected residents within 30 days of discovery, and only 17% of notices filed with the Attorney General since March 2020 arrived within 30 days.
The first hour
| Step | Who | Why |
|---|---|---|
| 1. Call your cyber insurer's breach hotline, or your broker | Owner or manager | Gets a breach attorney and forensic team engaged; protects coverage |
| 2. Disconnect affected computers from the network (unplug or turn off Wi-Fi) | IT person or provider | Stops spread without destroying evidence |
| 3. If funds were sent, call your bank's fraud line and request a recall | Whoever controls the account | Money moves fast; the first hours matter most |
| 4. Write down what you know: when it was noticed, by whom, what was seen | Owner or manager | The discovery time starts legal clocks |
| 5. Tell your team to stop using affected systems and to keep quiet externally | Owner | Prevents accidental damage and premature statements |
If you have no cyber insurance, call a breach attorney first. They will engage forensics under attorney-client privilege.
Hours 1 to 24
| Step | Why |
|---|---|
| Preserve evidence: logs, suspicious emails, ransom notes, screenshots | Forensics needs them to determine what happened and what was taken |
| Reset passwords and turn on multifactor authentication for compromised accounts, as the forensic team directs | Removes the attacker's access without tipping them off too early |
| Check email accounts for forwarding rules or new devices | Attackers often set rules to keep watching your mail |
| Locate your backups and confirm they are safe, without connecting them to infected systems | Clean backups are the fastest path back |
| List the data that may be involved: customers, patients, employees, card data | Determines who may need notice |
| Identify every state your affected people live in | Each state's law applies to its residents |
| Report to the FBI at ic3.gov, as your advisors direct | Supports recovery of funds and investigation |
| Start a log of costs: overtime, rentals, IT time, lost sales | Supports business interruption and expense claims |
What not to do
| Don't | Why |
|---|---|
| Wipe, reimage, or rebuild machines | Destroys the evidence that shows what was taken, which decides whether notice is needed |
| Pay or contact the attacker | Payments to sanctioned groups can violate federal law; insurers require approval |
| Hire your own forensic firm or lawyer without the insurer's consent | Costs may not be covered |
| Email about the breach from a possibly compromised account | The attacker may be reading it |
| Post or tell customers before the facts are known | Early statements are often wrong and can create liability |
| Assume the vendor will handle it | If a vendor holding your data is breached, the notice duty usually stays with you |
The Washington clock
Washington's breach law, RCW 19.255.010, sets the deadlines:
| Deadline | Requirement |
|---|---|
| 30 calendar days after discovery | Notify affected Washington residents, unless an exception applies |
| 30 days after discovery | Notify the Attorney General if more than 500 Washington residents are notified |
| Immediately after discovery | A vendor holding your data must notify you |
| Delayed only if | Law enforcement determines notice would impede a criminal investigation, or time is needed to determine scope and restore the system |
Notice may not be required if the data was encrypted and the key was not taken, or if the breach is not reasonably likely to cause harm. Those are judgment calls for the breach attorney, based on forensic findings. Full details are in Washington data breach notification law.
If your affected people include Idaho residents, Idaho requires notice without unreasonable delay when misuse has occurred or is reasonably likely. Health care providers also have HIPAA's rules; see cyber insurance for dental and medical practices.
Days 2 to 30
- Forensics determines scope: how the attacker got in, what they accessed, and whether data left your network.
- The breach attorney decides notice obligations state by state, and whether exceptions apply.
- Restore operations from clean backups, with security gaps closed first.
- Prepare notices: letters to affected people, the Attorney General filing if required, call center and credit monitoring.
- Mail notices by day 30 for Washington residents.
- Document everything for your insurance claim, including lost income.
How your cyber policy helps in the first 24 hours
| Need | Coverage part |
|---|---|
| Someone to take charge | Breach response: breach attorney and incident coordination |
| Find out what happened | Breach response: forensics |
| Deal with a ransom demand | Cyber extortion: negotiators, and an approved payment where lawful |
| Get systems back | Data restoration |
| Cover lost income | Business interruption, after the waiting period |
| Recover stolen funds | Social engineering or funds transfer fraud, if included |
Keep your policy number and breach hotline somewhere you can reach if your computers are down, such as on paper or on a phone. See what cyber insurance covers.
Prepare now: a one-page plan
- Your insurer's breach hotline and policy number, printed
- Your broker's cell phone number
- Your bank's fraud line
- Your IT provider's emergency contact
- Who decides, and who is allowed to talk to customers and press
- Where backups are and how to restore them
- A list of the personal data you hold and roughly how many people it covers