Incident Response Checklist: Containment, Forensics, Notification Triggers, and Documentation

By ·

The decisions that determine how a breach ends are made in the first four hours by people who do not know they are making them. This checklist runs the response in fourteen phases: contain without destroying evidence, establish the privilege structure, preserve, engage forensics, build the data-element inventory, map residences and deadlines, apply the encryption safe harbor, make and document the risk-of-harm determination, draft the notices, file with regulators and agencies, staff the call center, handle insurance and vendors, address ransomware and sanctions, and run the post-incident review. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear on day one. A worked response runs throughout.

IP and Technology > Privacy Data Security | Checklist | Published 22 March 2025 - Updated 5 January 2026 | Casey Scott McKay - marksy.us

Summary. The decisions that determine how a breach ends are made in the first four hours by people who do not know they are making them. This checklist runs the response in fourteen phases: contain without destroying evidence, establish the privilege structure, preserve, engage forensics, build the data-element inventory, map residences and deadlines, apply the encryption safe harbor, make and document the risk-of-harm determination, draft the notices, file with regulators and agencies, staff the call center, handle insurance and vendors, address ransomware and sanctions, and run the post-incident review. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear on day one. A worked response runs throughout.

Keywords: incident containment, evidence preservation, log retention, forensic engagement through counsel, privilege structure, litigation hold, data element inventory, encryption safe harbor, residence mapping, deadline calendar, risk of harm determination, notification drafting, attorney general filing, credit reporting agency notice, call center script, insurance notice, vendor contract review, ransomware sanctions screening, decision log, post-incident review


How to use this checklist

| Phase | What it covers | When | |---|---|---| | 1 | Contain without destroying | Hours 0–4 | | 2 | The privilege structure | Hours 0–4 | | 3 | Preserve | Hours 4–12 | | 4 | Forensics | Days 1–14 | | 5 | The data-element inventory | Days 2–14 | | 6 | Residences and deadlines | Days 3–7 | | 7 | The encryption safe harbor | Days 3–10 | | 8 | Risk-of-harm determination | Weeks 2–3 | | 9 | Drafting the notices | Weeks 2–4 | | 10 | Regulators and agencies | Per calendar | | 11 | The call center | Before notices land | | 12 | Insurance and vendors | Day 1 onward | | 13 | Ransomware and sanctions | If applicable | | 14 | Post-incident review | After |

Boxes marked [Gate] should clear on day one.

The matter. A payroll services company detected anomalous authentication against an administrative console on a Tuesday evening. The whole response took nineteen days.


Phase 1. Contain without destroying


Phase 2. The privilege structure


Phase 3. Preserve


Phase 4. Forensics


Phase 5. The data-element inventory


Phase 6. Residences and deadlines


Phase 7. The encryption safe harbor


Phase 8. The risk-of-harm determination


Phase 9. Drafting the notices


Phase 10. Regulators and agencies


Phase 11. The call center


Phase 12. Insurance and vendors


Phase 13. Ransomware and sanctions


Phase 14. Post-incident review

Phase 15. The documentation file

Three years after an incident, what protects the company is the file. Confirm each of these exists.


Phase 16. Communications discipline


Phase 17. Law enforcement


Phase 18. The roles, assigned before the incident

Response fails on organization more often than on analysis. Assign these by name, not by title, and confirm each person knows they hold the role.


Phase 19. The six controls to build beforehand

Every post-incident finding reduces to one of these, and the quality of a response is largely determined by which existed already.


Phase 20. Incidents that are not breaches

Not every incident triggers an obligation, and treating every alert as a breach exhausts a response function that needs to be sharp when it matters.


Phase 21. The litigation that follows

Notification starts the next phase. Prepare for it while the response is running rather than afterward.


Phase 22. The tabletop exercise

The plan is worth what the exercise is worth. Run one annually with the people who will actually decide.


Outcome. The security lead called the general counsel rather than the usual vendor, which shaped everything after. Ninety-day log retention covered the full intrusion window. Forensics showed two queries returning aggregate counts with no personally identifiable fields, no exfiltration channel, and no staged archive. The sensitive store was encrypted with keys managed separately and was never accessed. A written risk-of-harm determination was filed with the two attorneys general whose statutes required it, client companies were notified under their contracts, and the matter closed on day nineteen.


Key Authorities at a Glance

| Authority | Proposition | Phase | |---|---|---| | Cal. Civ. Code § 1798.82 | Notification; content and timing | 6, 9 | | Cal. Civ. Code § 1798.29 | Parallel agency obligation | 6 | | Cal. Civ. Code § 1798.150 | Private right of action | 14 | | N.Y. Gen. Bus. Law § 899-aa | Expanded data elements | 6 | | N.Y. Gen. Bus. Law § 899-bb | Reasonable security obligation | 14 | | Tex. Bus. & Com. Code § 521.053 | Sixty-day outer limit | 6 | | 740 ILCS 530/10 | Illinois notification | 6 | | Mass. Gen. Laws ch. 93H § 3 | Prohibits describing the breach | 9 | | 45 C.F.R. § 164.402 | Health breach; four-factor test | 8 | | 45 C.F.R. § 164.404 | Individual notice; sixty days | 6 | | 45 C.F.R. § 164.406 | Media notice | 10 | | 45 C.F.R. § 164.408 | Notice to the regulator | 10 | | 45 C.F.R. § 164.410 | Business associate notice | 12 | | 15 U.S.C. § 6801 | Financial safeguards | 10 | | 15 U.S.C. § 6805 | Functional regulators | 6 | | 15 U.S.C. § 1681c-1 | Fraud alerts and freezes | 9 | | 15 U.S.C. § 45 | Unfair or deceptive practices | 14 | | 18 U.S.C. § 1030 | Computer fraud | 13 | | 18 U.S.C. § 2511 | Interception | 13 | | Fed. R. Civ. P. 26 | Work product; forensic privilege | 2 | | Fed. R. Civ. P. 23 | Class certification | 14 |


The five things people get wrong

One: the technology team calls its usual forensic vendor first. Privilege is decided in the first four hours and cannot be retrofitted. Counsel engages the firm, under a scope different from the firm's ordinary work, with remediation running separately. Fed. R. Civ. P. 26.

Two: they reimage the compromised host. The evidence that answers whether data left is destroyed by the instinct to restore service, and the analysis then proceeds on the assumption that everything left.

Three: they discover the log retention window on day nine. Seven days is common and it is the cheapest control to fix. Without logs there is no defensible no-exfiltration finding.

Four: they map residences in week four. The shortest applicable deadline governs the entire response, and a thirty-day state discovered with nine days left cannot be recovered from. Tex. Bus. & Com. Code § 521.053.

Five: they put a number in a statement on day four. Every early figure becomes the first exhibit in the complaint and the first question in the civil investigative demand. Say what is known, say the investigation continues, and say nothing about scope. See Running a Data Breach Response.


Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Breach obligations turn on specific data elements, states of residence, and sector rules. Marksy is not a law firm.

Read this article on Marksy