Incident Response Checklist: Containment, Forensics, Notification Triggers, and Documentation
By Casey Scott McKay ·
The decisions that determine how a breach ends are made in the first four hours by people who do not know they are making them. This checklist runs the response in fourteen phases: contain without destroying evidence, establish the privilege structure, preserve, engage forensics, build the data-element inventory, map residences and deadlines, apply the encryption safe harbor, make and document the risk-of-harm determination, draft the notices, file with regulators and agencies, staff the call center, handle insurance and vendors, address ransomware and sanctions, and run the post-incident review. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear on day one. A worked response runs throughout.
IP and Technology > Privacy Data Security | Checklist | Published 22 March 2025 - Updated 5 January 2026 | Casey Scott McKay - marksy.us
Summary. The decisions that determine how a breach ends are made in the first four hours by people who do not know they are making them. This checklist runs the response in fourteen phases: contain without destroying evidence, establish the privilege structure, preserve, engage forensics, build the data-element inventory, map residences and deadlines, apply the encryption safe harbor, make and document the risk-of-harm determination, draft the notices, file with regulators and agencies, staff the call center, handle insurance and vendors, address ransomware and sanctions, and run the post-incident review. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear on day one. A worked response runs throughout.
Keywords: incident containment, evidence preservation, log retention, forensic engagement through counsel, privilege structure, litigation hold, data element inventory, encryption safe harbor, residence mapping, deadline calendar, risk of harm determination, notification drafting, attorney general filing, credit reporting agency notice, call center script, insurance notice, vendor contract review, ransomware sanctions screening, decision log, post-incident review
How to use this checklist
| Phase | What it covers | When | |---|---|---| | 1 | Contain without destroying | Hours 0–4 | | 2 | The privilege structure | Hours 0–4 | | 3 | Preserve | Hours 4–12 | | 4 | Forensics | Days 1–14 | | 5 | The data-element inventory | Days 2–14 | | 6 | Residences and deadlines | Days 3–7 | | 7 | The encryption safe harbor | Days 3–10 | | 8 | Risk-of-harm determination | Weeks 2–3 | | 9 | Drafting the notices | Weeks 2–4 | | 10 | Regulators and agencies | Per calendar | | 11 | The call center | Before notices land | | 12 | Insurance and vendors | Day 1 onward | | 13 | Ransomware and sanctions | If applicable | | 14 | Post-incident review | After |
Boxes marked [Gate] should clear on day one.
The matter. A payroll services company detected anomalous authentication against an administrative console on a Tuesday evening. The whole response took nineteen days.
Phase 1. Contain without destroying
-
[ ] Isolate systems, revoke credentials, and block the access path.
-
[ ] [Gate] Do not reimage.
- Why. Reimaging a compromised host destroys the evidence that answers whether data left, which is the question everything turns on.
-
[ ] Do not have internal IT "look around."
- Trap. Well-intentioned examination alters metadata and creates a chain-of-custody problem that is entirely avoidable.
-
[ ] Open a decision log immediately.
- Why. Who decided what, when, and on what information. It answers a regulator two years later and it cannot be reconstructed.
-
[ ] Do not send company-wide email about the incident.
- Trap. Every message is discoverable and most speculate.
Phase 2. The privilege structure
-
[ ] [Gate] Engage outside counsel before engaging any forensic firm.
- Why. The structure is decided in the first hours and cannot be retrofitted.
-
[ ] Have counsel retain the forensic firm.
- Why. The statement of work should state the engagement is to assist counsel in rendering legal advice and in anticipation of litigation, and describe a scope different from the firm's ordinary incident response work.
-
[ ] Separate remediation from the legal investigation.
- Why. Two workstreams, two vendors where possible, two reports.
-
[ ] Limit distribution of the legal report.
- Trap. A single report circulated to the board, the insurer, the merchant bank, and the technology organization. Held discoverable, and quoted.
-
[ ] Pay through the legal budget.
-
[ ] Avoid the pre-existing master services agreement.
- Why. A firm already engaged for ordinary security work under a general agreement is the fact pattern in which privilege most often fails.
- Authority. Fed. R. Civ. P. 26.
Phase 3. Preserve
-
[ ] Issue the litigation hold within hours.
- Why. Security team, owners of affected systems, executives, and anyone who communicated about the incident.
-
[ ] [Gate] Preserve logs first.
- Why. Firewall, VPN, authentication, database access, endpoint telemetry, email, and cloud audit logs.
- Trap. Seven-day retention discovered on day nine, which converts a scoping question into an assumption that everything left.
-
[ ] Image affected systems before remediation.
-
[ ] Preserve attacker artifacts.
- Why. Malware samples, scripts, staged archives, and command-and-control indicators.
-
[ ] Preserve any communications with the attacker.
-
[ ] Document chain of custody from the first image forward.
Phase 4. Forensics
-
[ ] Scope the engagement to the legal question.
- Why. What was accessed, what left, when, and by whom. Not a general security assessment.
-
[ ] Establish the intrusion window.
-
[ ] Establish whether an exfiltration channel existed and whether archives were staged.
-
[ ] Establish what was actually accessible, not merely what the system holds.
- Why. A query returning aggregates from a table containing sensitive fields did not expose those fields.
-
[ ] Reconcile the insurer's forensic view with yours.
- Trap. Two firms reaching different conclusions on exfiltration, which is discoverable and a genuine problem.
-
[ ] Keep the report factual.
- Why. Recommendations about what the company should have done belong in the remediation workstream, not in the investigative report.
Phase 5. The data-element inventory
-
[ ] [Gate] Build it before answering any legal question.
- Why. Every state analysis runs off it.
-
[ ] Record specific fields, per record, per individual.
- Trap. A record count, which answers nothing.
-
[ ] Go system by system and table by table.
- Why. Legacy stores hold data collected years earlier for a forgotten purpose, and that is where the surprises live.
-
[ ] Record encryption state field by field.
-
[ ] Deliverable: a matrix of population by data element by system by encryption state.
Phase 6. Residences and deadlines
-
[ ] Map affected individuals to states of residence.
- Why. The obligation follows the individual, not the company.
-
[ ] [Gate] Identify the shortest applicable deadline.
- Why. It governs everyone, because notifying different states on different days is operationally impossible and reads worse than a single date.
- Authority. Tex. Bus. & Com. Code § 521.053; Cal. Civ. Code § 1798.82.
-
[ ] Determine the trigger date per state.
- Trap. Discovery versus determination. Run from the earlier where the distinction is contested.
-
[ ] Check the expanded data element states.
- Authority. N.Y. Gen. Bus. Law § 899-aa; 740 ILCS 530/10.
-
[ ] Check the sector deadlines separately.
- Authority. 45 C.F.R. § 164.404; 15 U.S.C. § 6805.
-
[ ] Check the securities obligation for a public company: disclosure within four business days of determining materiality, with the determination itself required without unreasonable delay.
-
[ ] Build the calendar backward from go-live through approval, drafting, forms, print lead time, and call center standup.
Phase 7. The encryption safe harbor
-
[ ] Check it early and field by field.
- Why. It is the finding most likely to end the analysis, and it is the single highest-value control a company can have.
-
[ ] Confirm the standard met, because safe harbors differ — some require a specified standard, some only that data be rendered unreadable, and some also cover redaction or tokenization.
-
[ ] [Gate] Confirm the key was not also acquired.
- Trap. Encrypted data with the key on the same compromised host.
-
[ ] Document the finding with the technical basis.
Phase 8. The risk-of-harm determination
-
[ ] Identify the states that permit it and those that do not.
- Why. Several require notification whenever the definitional trigger is met, and those states set the national floor.
-
[ ] [Gate] Document it in writing.
- Why. The facts relied on, the analysis, the conclusion, and the date.
- Trap. An undocumented conclusion, which regulators treat as no conclusion.
-
[ ] File it with the attorney general where required.
-
[ ] Know what supports it.
- Why. Data recovered before use, a device located intact, encryption falling just short of the safe harbor, confirmed deletion after an internal misdirection, or access logs showing no retrieval.
-
[ ] Know what does not.
- Trap. The absence of evidence of misuse, standing alone.
-
[ ] For health information, run the four-factor assessment.
- Authority. 45 C.F.R. § 164.402.
- Why. A presumption of breach applies unless the assessment demonstrates a low probability of compromise.
Phase 9. Drafting the notices
-
[ ] Plan for multiple versions.
- Trap. Mass. Gen. Laws ch. 93H § 3 prohibits describing the nature of the breach; Cal. Civ. Code § 1798.82 requires a general description. One national notice cannot satisfy both.
-
[ ] Differentiate by exposure where the population differs.
-
[ ] Be precise about dates and explicit about what remains under investigation.
-
[ ] Avoid characterizations of severity.
- Trap. "A sophisticated attack" and "a minor incident" both appear verbatim in complaints.
-
[ ] Describe fraud alerts and freezes with the mechanism and agency contacts.
- Authority. 15 U.S.C. § 1681c-1.
-
[ ] State the monitoring offer, its period, and its deadline.
- Trap. Conditioning it on a release, which several states prohibit.
-
[ ] Follow the format rules.
- Why. Conspicuous, not commingled with marketing, and using any prescribed heading.
-
[ ] Prepare substitute notice where cost or population thresholds are met.
-
[ ] Assume the regulator version becomes public.
Phase 10. Regulators and agencies
-
[ ] File with each state attorney general on its own form and portal.
-
[ ] Notify credit reporting agencies where the affected resident count exceeds the state threshold.
-
[ ] File with sector regulators.
- Authority. 45 C.F.R. § 164.408; 15 U.S.C. § 6801.
-
[ ] Provide media notice where required above a population threshold.
- Authority. 45 C.F.R. § 164.406.
-
[ ] Keep the regulator narrative consistent with the individual notices.
- Why. Regulators compare them.
-
[ ] Retain every confirmation.
Phase 11. The call center
-
[ ] Stand it up before the notices land.
-
[ ] Script it, and have counsel review the script.
- Trap. Careful drafting undone by an agent improvising an answer about scope.
-
[ ] Provide an escalation path for people reporting actual fraud.
-
[ ] Log every call and its disposition.
-
[ ] Brief the internal teams that will field questions, including sales and support.
-
[ ] Designate one spokesperson and one approved statement for media and partners.
Phase 12. Insurance and vendors
-
[ ] Notify insurers immediately.
- Trap. Four weeks of costs incurred before tender, and a consent-to-incur argument the insured loses.
-
[ ] Check the panel provisions.
- Why. Many policies require panel counsel and forensic firms, and using your own must be endorsed at renewal rather than argued at claim time.
-
[ ] Track costs by policy category from day one.
-
[ ] Understand that betterment is not covered, and it is usually the largest post-incident line item.
-
[ ] Read the vendor contract on day one where a provider is involved.
- Why. Its notice deadline to you, cooperation obligation, indemnity, and whether it may notify anyone without your approval.
- Authority. 45 C.F.R. § 164.410 for the health analogue.
-
[ ] Demand the data-element inventory for your records, not a two-paragraph assurance.
-
[ ] Do not let the vendor notify your customers.
-
[ ] Conduct your own analysis regardless of the vendor's conclusion.
Phase 13. Ransomware and sanctions
-
[ ] Determine whether encryption alone triggers the definition in each state.
- Why. States requiring acquisition may not be triggered; states reaching unauthorized access may be.
-
[ ] Assume exfiltration unless the logs exclude it.
-
[ ] [Gate] Screen any payment for sanctions exposure before it is made.
- Trap. Payment to a designated person or entity carries strict liability exposure, and screening must precede the transfer.
-
[ ] Understand that payment does not resolve notification.
- Why. A deletion assurance from a criminal is not a forensic finding.
-
[ ] Treat restoration as separate from resolution.
-
[ ] Keep the negotiation record inside the privileged workstream.
-
[ ] Note the attacker's separate criminal exposure.
- Authority. 18 U.S.C. § 1030; 18 U.S.C. § 2511.
Phase 14. Post-incident review
-
[ ] Run it under privilege.
- Trap. A document listing every failure, written outside privilege, produced in discovery.
-
[ ] Expect the recurring findings.
- Why. Short log retention, no data inventory, unencrypted legacy stores, detection by an external party, an untested plan, and vendor contracts with three-week deadlines.
-
[ ] Fix the six controls in order of leverage.
- Why. Encryption at rest with separated key management, log retention, data minimization, a maintained field-level inventory, vendor contract terms, and a tested plan.
-
[ ] Assign names, not titles, in the plan.
- Why. A decision-maker with spending authority, counsel pre-engaged, a forensic firm pre-selected, a communications owner, a notification project manager, an insurer liaison, and a scribe for the decision log.
-
[ ] Report to the board with findings and completion dates.
- Why. The oversight claim turns on whether the board was informed and what it did.
-
[ ] Close the items.
- Trap. An open finding two years later, discovered in discovery, is worse than the original failure.
-
[ ] Prepare for the litigation.
- Authority. Cal. Civ. Code § 1798.150; Fed. R. Civ. P. 23; 15 U.S.C. § 45.
Phase 15. The documentation file
Three years after an incident, what protects the company is the file. Confirm each of these exists.
-
[ ] The decision log. Every material decision, who made it, when, and on what information.
- Why. Regulators ask why notification took eleven days, and the answer is either a documented sequence of investigative findings or an absence.
-
[ ] The forensic conclusions, in the privileged workstream, with remediation kept separate.
-
[ ] The data-element matrix, with version history showing how the population estimate changed and why.
-
[ ] The encryption findings, field by field, with the technical basis.
-
[ ] The risk-of-harm determination, where relied on.
-
[ ] The residence map and the deadline calculation, showing which statute governed and why.
-
[ ] Every notice version and the population that received it.
-
[ ] Every regulator filing and its confirmation.
-
[ ] The call center log, including complaints and escalations.
-
[ ] The cost record by policy category.
-
[ ] The post-incident review and the remediation plan, with completion dates.
- Trap. An identified deficiency with no completion date is worse than no review at all.
-
[ ] The board reporting record.
- Why. The oversight claim turns on whether the board was informed and what it did.
Phase 16. Communications discipline
-
[ ] One spokesperson, one approved statement, updated only when the facts change.
-
[ ] Treat employee communications as external.
- Why. They are forwarded, screenshotted, and produced. Write them as though a regulator will read them, because one will.
-
[ ] Script the customer-facing teams before the notices land.
-
[ ] Read the enterprise customer contracts early.
- Trap. Several impose notice deadlines shorter than any statute, and some require notice of an incident rather than a confirmed breach.
-
[ ] Coordinate investor communications with the materiality determination for a public company, and with information rights in shareholder agreements for a private one.
-
[ ] Keep the regulator narrative and the individual notices consistent.
-
[ ] Date and archive the website posting.
-
[ ] Say none of the following, in any channel.
- Why. A number before it is settled. A characterization of the attacker's sophistication. An assurance that no data was misused. A claim that security "exceeded industry standards." Each appears verbatim in complaints.
Phase 17. Law enforcement
-
[ ] Weigh the referral deliberately.
- Why. It can support a delay request, it is expected by regulators, and it occasionally produces useful intelligence. It also means losing control of the timeline.
-
[ ] Understand the delay is not automatic.
- Why. Most statutes require a documented request that notification would impede an investigation, and the delay ends when law enforcement says it may.
-
[ ] Expect information to flow one way.
-
[ ] Be precise about what is handed over.
- Trap. Material given to law enforcement may lose confidentiality protections.
-
[ ] Note the attacker's separate criminal exposure.
- Authority. 18 U.S.C. § 1030.
Phase 18. The roles, assigned before the incident
Response fails on organization more often than on analysis. Assign these by name, not by title, and confirm each person knows they hold the role.
-
[ ] The decision-maker. One executive with authority to spend, to notify, and to make the materiality call, available at any hour.
- Trap. A committee that must convene. It meets on Monday.
-
[ ] Outside counsel, engaged in advance with conflicts already cleared and an engagement letter ready to sign.
-
[ ] The forensic firm, pre-selected, engageable through counsel within hours, and not already retained under a general master services agreement.
-
[ ] The internal lead, running containment and remediation, reporting to the decision-maker and coordinating with counsel rather than directing the legal investigation.
-
[ ] The communications owner, working from counsel-approved statements.
-
[ ] The notification project manager.
- Why. Notification is logistics — versions, populations, print vendors, portals, staffing, deadlines — and it needs someone who runs projects rather than someone who practices law.
-
[ ] The insurer liaison, tracking costs by policy category from day one.
-
[ ] The scribe, maintaining the decision log.
- Why. It is nobody's job by default and it is the document that answers a regulator two years later.
-
[ ] Test the assignments annually in an exercise with the executives who will actually make the decisions.
- Trap. A plan naming titles, or naming people who have since left.
Phase 19. The six controls to build beforehand
Every post-incident finding reduces to one of these, and the quality of a response is largely determined by which existed already.
-
[ ] Encryption at rest, with key management separated from the data.
- Why. The safe harbors convert a notifiable event into a non-event when the key was not also acquired. Highest leverage on the list, and it is per store rather than per system.
-
[ ] Log retention long enough to exclude exfiltration.
- Why. Ninety days is a workable floor for authentication, database access, network egress, and cloud audit trails. Cheapest control on the list and the most commonly deficient.
-
[ ] Data minimization on a schedule that runs.
- Why. Records deleted before the incident are not in the breach, and the recurring finding is years of data retained for no reason.
-
[ ] A maintained field-level data inventory.
- Why. It converts a five-week scoping exercise into a two-day one, which is the difference between meeting a thirty-day deadline and missing it.
-
[ ] Vendor contract terms.
- Why. Notification to you within days, cooperation with access to findings, indemnity bearing some relationship to notification costs, and a prohibition on the vendor notifying anyone without your approval.
-
[ ] A tested plan with named people, pre-engaged counsel, a pre-selected forensic firm, and an insurance endorsement permitting your counsel if you want it.
-
[ ] Confirm none of these is exotic or expensive relative to a single response.
- Why. They are absent because each is invisible until the night it matters.
Phase 20. Incidents that are not breaches
Not every incident triggers an obligation, and treating every alert as a breach exhausts a response function that needs to be sharp when it matters.
-
[ ] Confirm whether personal information was involved at all.
- Why. An intrusion into a build server holding no personal data is a security incident and not a notifiable breach, though it may trigger contractual notice to customers.
-
[ ] Confirm acquisition or access, as the state defines it.
- Trap. A misconfiguration that made data reachable in principle, with logs showing nobody reached it, is a different case from one where the logs are absent.
-
[ ] Confirm the data elements meet a definition somewhere.
- Why. Names alone, business contact information, and publicly available government record information are outside most definitions.
-
[ ] Apply the encryption and redaction safe harbors.
-
[ ] Check the good-faith employee acquisition exception.
- Why. Most statutes exclude good-faith acquisition by an employee or agent for a legitimate purpose, provided the information is not further used or disclosed.
-
[ ] Check the internal misdirection scenario.
- Why. An email sent to the wrong internal recipient, confirmed deleted and not forwarded, frequently supports a no-notification determination — documented.
-
[ ] Check contractual obligations separately from statutory ones.
- Trap. Enterprise customer agreements requiring notice of any security incident regardless of whether the statutory threshold is met. This is where most notices actually originate for business-to-business companies.
-
[ ] Document the no-notification conclusion anyway.
- Why. A decision not to notify is a decision, and it should have a written basis with a date. The absence of a file is how a defensible call becomes an indefensible one two years later.
-
[ ] Track the near misses.
- Why. A pattern of incidents that fell just short is the strongest internal argument for funding the six controls, and it is the record a regulator will find if it looks.
Phase 21. The litigation that follows
Notification starts the next phase. Prepare for it while the response is running rather than afterward.
-
[ ] Expect consumer class actions within days of notice.
- Why. Negligence, breach of implied contract, unjust enrichment, and state consumer protection theories. The perennial difficulty is injury, and courts divide on whether increased risk, monitoring time, and diminished value of personal information suffice.
-
[ ] Expect the statutory claim where California residents are affected.
- Authority. Cal. Civ. Code § 1798.150.
- Why. Statutory damages per consumer per incident for a breach of enumerated elements resulting from a failure to maintain reasonable security. It removes the injury problem for the categories it covers.
-
[ ] Expect financial institution claims where payment card data was involved, usually constrained by the economic loss rule and the card network's own liability allocation.
-
[ ] Expect securities and derivative claims for a public company following disclosure.
-
[ ] Expect a multistate attorney general inquiry above a meaningful population, frequently resolving with a compliance program, assessments, and payments.
-
[ ] Assess class certification early.
- Authority. Fed. R. Civ. P. 23.
- Why. Predominance is contested where data elements differ across the population, where some individuals were notified and others not, and where injury varies. A breach exposing identical elements for everyone is far more certifiable.
-
[ ] Expect the notice to be quoted in the first paragraph of the complaint.
- Trap. A notice that overstates certainty and is later corrected supplies the deception allegation; one that understates and is later expanded supplies the concealment allegation. Precision about what is known, with explicit acknowledgment of what remains open, survives both.
-
[ ] Reconcile preservation with any deletion requests arriving under privacy statutes during the litigation.
-
[ ] Keep the privileged and unprivileged workstreams separate through discovery.
- Authority. Fed. R. Civ. P. 26.
Phase 22. The tabletop exercise
The plan is worth what the exercise is worth. Run one annually with the people who will actually decide.
-
[ ] Use a realistic scenario.
- Why. Detection by a third party, ambiguous forensic findings, an involved vendor, and a partial answer at the point a decision is required. Scenarios where the facts are clear teach nothing.
-
[ ] Start at the wrong hour.
- Why. Incidents are detected on Friday evenings and holiday weekends, and the plan's assumption that everyone is reachable is the assumption most likely to fail.
-
[ ] Force the privilege decision in the first ten minutes.
- Why. It is the decision that gets made wrong in real incidents, and the exercise should surface whether people know to make it.
-
[ ] Force a communications decision under pressure.
- Why. A reporter calls on day two with a partially correct account. What is said, by whom, and approved by whom.
-
[ ] Include the insurer and the vendor, at least as roles played by someone in the room.
-
[ ] Test the data-element question.
- Why. Ask what fields live in a named legacy system. If nobody in the room can answer, that is the finding.
-
[ ] Test log retention by asking how far back the authentication logs go. Confirm the answer against reality afterward.
-
[ ] Record the findings and assign owners with dates.
-
[ ] Re-run the unresolved findings at the next exercise.
- Trap. An annual exercise that generates the same findings every year is a documented record of known deficiencies left unaddressed.
Outcome. The security lead called the general counsel rather than the usual vendor, which shaped everything after. Ninety-day log retention covered the full intrusion window. Forensics showed two queries returning aggregate counts with no personally identifiable fields, no exfiltration channel, and no staged archive. The sensitive store was encrypted with keys managed separately and was never accessed. A written risk-of-harm determination was filed with the two attorneys general whose statutes required it, client companies were notified under their contracts, and the matter closed on day nineteen.
Key Authorities at a Glance
| Authority | Proposition | Phase | |---|---|---| | Cal. Civ. Code § 1798.82 | Notification; content and timing | 6, 9 | | Cal. Civ. Code § 1798.29 | Parallel agency obligation | 6 | | Cal. Civ. Code § 1798.150 | Private right of action | 14 | | N.Y. Gen. Bus. Law § 899-aa | Expanded data elements | 6 | | N.Y. Gen. Bus. Law § 899-bb | Reasonable security obligation | 14 | | Tex. Bus. & Com. Code § 521.053 | Sixty-day outer limit | 6 | | 740 ILCS 530/10 | Illinois notification | 6 | | Mass. Gen. Laws ch. 93H § 3 | Prohibits describing the breach | 9 | | 45 C.F.R. § 164.402 | Health breach; four-factor test | 8 | | 45 C.F.R. § 164.404 | Individual notice; sixty days | 6 | | 45 C.F.R. § 164.406 | Media notice | 10 | | 45 C.F.R. § 164.408 | Notice to the regulator | 10 | | 45 C.F.R. § 164.410 | Business associate notice | 12 | | 15 U.S.C. § 6801 | Financial safeguards | 10 | | 15 U.S.C. § 6805 | Functional regulators | 6 | | 15 U.S.C. § 1681c-1 | Fraud alerts and freezes | 9 | | 15 U.S.C. § 45 | Unfair or deceptive practices | 14 | | 18 U.S.C. § 1030 | Computer fraud | 13 | | 18 U.S.C. § 2511 | Interception | 13 | | Fed. R. Civ. P. 26 | Work product; forensic privilege | 2 | | Fed. R. Civ. P. 23 | Class certification | 14 |
The five things people get wrong
One: the technology team calls its usual forensic vendor first. Privilege is decided in the first four hours and cannot be retrofitted. Counsel engages the firm, under a scope different from the firm's ordinary work, with remediation running separately. Fed. R. Civ. P. 26.
Two: they reimage the compromised host. The evidence that answers whether data left is destroyed by the instinct to restore service, and the analysis then proceeds on the assumption that everything left.
Three: they discover the log retention window on day nine. Seven days is common and it is the cheapest control to fix. Without logs there is no defensible no-exfiltration finding.
Four: they map residences in week four. The shortest applicable deadline governs the entire response, and a thirty-day state discovered with nine days left cannot be recovered from. Tex. Bus. & Com. Code § 521.053.
Five: they put a number in a statement on day four. Every early figure becomes the first exhibit in the complaint and the first question in the civil investigative demand. Say what is known, say the investigation continues, and say nothing about scope. See Running a Data Breach Response.
Related Documents
Articles
- The First Seventy-Two Hours
- Your Face as Data
- The Data Behind the Marketing
- Who Owns the Data
- The Legal Layers of a Website
Guides
- Running a Data Breach Response
- Building a Biometric Compliance Program
- Building a Privacy Compliance Program for a Consumer Brand
- Negotiating a Technology Agreement
Checklists
- Biometric Data Checklist
- Technology Agreement Checklist
- Marketing Privacy Compliance Checklist
- Data Collection and Scraping Risk Checklist
Toolkits
- Incident Response and Breach Notification Toolkit
- Biometric and Sensitive Data Toolkit
- Privacy and Marketing Data Toolkit
- Software, Data, and Open Source Toolkit
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Breach obligations turn on specific data elements, states of residence, and sector rules. Marksy is not a law firm.