What to Do in the First 24 Hours After a Data Breach in Washington

In the first 24 hours after a suspected breach: call your cyber insurer's breach hotline or your broker, isolate affected systems without wiping them, preserve logs and emails, secure compromised accounts, and call your bank immediately if money moved. Do not contact attackers or hire vendors on your own. Washington's 30-day clock to notify affected residents starts when the breach is discovered.

By Trella Commercial · Updated October 4, 2026

The short version

  • Call first, fix second. Your cyber insurer's breach hotline, or your broker, should be the first outside call. Many policies require it before you spend money.
  • Contain without destroying. Disconnect affected devices from the network, but do not wipe, rebuild, or turn them off until forensics says so.
  • If money moved, call the bank now. In 2024, the FBI's Recovery Asset Team froze about 66% of the funds in the fraud cases it worked on. Speed is what makes that possible.
  • Do not pay, negotiate, or announce anything without the insurer's breach attorney.
  • The clock is running. Washington requires notice to affected residents within 30 days of discovery, and only 17% of notices filed with the Attorney General since March 2020 arrived within 30 days.

The first hour

StepWhoWhy
1. Call your cyber insurer's breach hotline, or your brokerOwner or managerGets a breach attorney and forensic team engaged; protects coverage
2. Disconnect affected computers from the network (unplug or turn off Wi-Fi)IT person or providerStops spread without destroying evidence
3. If funds were sent, call your bank's fraud line and request a recallWhoever controls the accountMoney moves fast; the first hours matter most
4. Write down what you know: when it was noticed, by whom, what was seenOwner or managerThe discovery time starts legal clocks
5. Tell your team to stop using affected systems and to keep quiet externallyOwnerPrevents accidental damage and premature statements

If you have no cyber insurance, call a breach attorney first. They will engage forensics under attorney-client privilege.

Hours 1 to 24

StepWhy
Preserve evidence: logs, suspicious emails, ransom notes, screenshotsForensics needs them to determine what happened and what was taken
Reset passwords and turn on multifactor authentication for compromised accounts, as the forensic team directsRemoves the attacker's access without tipping them off too early
Check email accounts for forwarding rules or new devicesAttackers often set rules to keep watching your mail
Locate your backups and confirm they are safe, without connecting them to infected systemsClean backups are the fastest path back
List the data that may be involved: customers, patients, employees, card dataDetermines who may need notice
Identify every state your affected people live inEach state's law applies to its residents
Report to the FBI at ic3.gov, as your advisors directSupports recovery of funds and investigation
Start a log of costs: overtime, rentals, IT time, lost salesSupports business interruption and expense claims

What not to do

Don'tWhy
Wipe, reimage, or rebuild machinesDestroys the evidence that shows what was taken, which decides whether notice is needed
Pay or contact the attackerPayments to sanctioned groups can violate federal law; insurers require approval
Hire your own forensic firm or lawyer without the insurer's consentCosts may not be covered
Email about the breach from a possibly compromised accountThe attacker may be reading it
Post or tell customers before the facts are knownEarly statements are often wrong and can create liability
Assume the vendor will handle itIf a vendor holding your data is breached, the notice duty usually stays with you

The Washington clock

Washington's breach law, RCW 19.255.010, sets the deadlines:

DeadlineRequirement
30 calendar days after discoveryNotify affected Washington residents, unless an exception applies
30 days after discoveryNotify the Attorney General if more than 500 Washington residents are notified
Immediately after discoveryA vendor holding your data must notify you
Delayed only ifLaw enforcement determines notice would impede a criminal investigation, or time is needed to determine scope and restore the system

Notice may not be required if the data was encrypted and the key was not taken, or if the breach is not reasonably likely to cause harm. Those are judgment calls for the breach attorney, based on forensic findings. Full details are in Washington data breach notification law.

If your affected people include Idaho residents, Idaho requires notice without unreasonable delay when misuse has occurred or is reasonably likely. Health care providers also have HIPAA's rules; see cyber insurance for dental and medical practices.

Days 2 to 30

  1. Forensics determines scope: how the attacker got in, what they accessed, and whether data left your network.
  2. The breach attorney decides notice obligations state by state, and whether exceptions apply.
  3. Restore operations from clean backups, with security gaps closed first.
  4. Prepare notices: letters to affected people, the Attorney General filing if required, call center and credit monitoring.
  5. Mail notices by day 30 for Washington residents.
  6. Document everything for your insurance claim, including lost income.

How your cyber policy helps in the first 24 hours

NeedCoverage part
Someone to take chargeBreach response: breach attorney and incident coordination
Find out what happenedBreach response: forensics
Deal with a ransom demandCyber extortion: negotiators, and an approved payment where lawful
Get systems backData restoration
Cover lost incomeBusiness interruption, after the waiting period
Recover stolen fundsSocial engineering or funds transfer fraud, if included

Keep your policy number and breach hotline somewhere you can reach if your computers are down, such as on paper or on a phone. See what cyber insurance covers.

Prepare now: a one-page plan

  • Your insurer's breach hotline and policy number, printed
  • Your broker's cell phone number
  • Your bank's fraud line
  • Your IT provider's emergency contact
  • Who decides, and who is allowed to talk to customers and press
  • Where backups are and how to restore them
  • A list of the personal data you hold and roughly how many people it covers

Common questions

What is the first thing to do after a data breach?

Call your cyber insurer's breach hotline or your broker. They engage a breach attorney and forensic investigators, and many policies require their involvement before you incur costs. At the same time, disconnect affected systems from the network without wiping them.

How long do I have to notify customers after a breach in Washington?

No more than 30 calendar days after discovering the breach, and sooner if possible, under RCW 19.255.010. The Attorney General must also be notified within 30 days if more than 500 Washington residents are affected.

Should I turn off my computers after a ransomware attack?

Disconnect them from the network, but do not wipe or rebuild them, and follow your forensic team's instructions before powering anything down. Evidence on the machines shows what the attacker did and whether data was taken.

Do I need to report a data breach to the police or FBI?

Washington's breach law does not require a police report, but reporting to the FBI through ic3.gov can help freeze stolen funds and supports investigation. Your breach attorney will advise on timing and other required notices.

What if I don't have cyber insurance?

Call a breach attorney first. They can engage forensic investigators under privilege and guide notification. You will carry the costs directly, but the legal deadlines are the same.

Sources

This page is general information, not legal advice. After a breach, follow the direction of your breach attorney and insurer. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.