The first hours of a suspected breach are a bad time to decide who is in charge, where the logs are or which attorney to call. A response plan should make those decisions before the pressure is on.
A suspected data breach requires coordinated technical, legal and business action.
This guide is informational and is not legal advice. Businesses should work with qualified counsel to determine their specific notification and regulatory obligations.
First Priority: Contain the Incident
The organization may need to:
- Isolate compromised systems
- Disable compromised accounts
- Block malicious remote access
- Revoke active sessions
- Reset credentials
- Preserve security logs
- Protect backup systems
- Prevent additional data access
Containment actions should be coordinated so evidence is not unnecessarily destroyed.
Preserve Evidence
Evidence can be important for determining what happened and what data may have been accessed.
Relevant evidence can include:
- Firewall logs
- Endpoint telemetry
- Microsoft 365 audit logs
- Email records
- Authentication logs
- VPN records
- Server logs
- Backup records
- Security alerts
- Attack artifacts
Contact Legal Counsel and Cyber Insurance
Cyber incidents can involve reporting requirements, contractual obligations, privacy issues and potential litigation.
Cyber-insurance policies may also specify approved incident-response vendors or notification procedures.
Texas Attorney General Reporting
The Texas Attorney General states that a breach of system security affecting 250 or more Texans must be reported to the OAG as soon as practicably possible and no later than 30 days after discovery.
Reports are submitted electronically through the Texas Attorney General's breach-reporting process.
Notice to Affected Texans
Texas law also includes requirements for notifying affected individuals.
The Texas Attorney General states that notice generally must be provided as quickly as possible and no later than 60 days after determining that the breach occurred, subject to statutory provisions and exceptions.
Legal counsel should determine the applicable timeline and content.
Determine the Scope
The investigation should determine:
- When unauthorized access began
- How access occurred
- Which systems were affected
- Which user accounts were compromised
- What data was accessible
- Whether evidence indicates data was acquired
- Whether persistence remains
- Whether third-party systems were involved
Restore Safely
Recovery should not simply reconnect the same compromised systems.
Teams may need to rebuild devices, patch vulnerabilities, rotate credentials, remove persistence, review administrative accounts and validate security before restoring normal operations.
Communicate Carefully
Incident communications should be accurate and coordinated.
Avoid speculation before facts have been established.
External communications may need input from legal counsel, management, insurance and public relations.
Post-Incident Improvement
After containment and recovery, document:
- Root cause
- Control failures
- Timeline
- Business impact
- Notification requirements
- Recovery performance
- Corrective actions
- Owners and deadlines
Build the Plan Before the Incident
Organizations respond more effectively when roles and contacts are documented in advance.
A written incident-response plan should be maintained and exercised periodically.
Sources and further reading
This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.
