Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

What to Do in the First 72 Hours After a Data Breach

You just found out your systems were breached. Maybe a customer reported suspicious activity. Maybe your monitoring caught unauthorized access. Maybe a security researcher sent you a responsible disclosure email. However you got here, the clock is now ticking.

The next 72 hours will determine whether this incident becomes a manageable event or an existential crisis. Here is the playbook.

Hours 0-4: Confirm and contain

First, confirm you actually have a breach. Not every anomaly is a compromise. Pull your team together, look at the evidence, and make a call. If you are unsure, treat it as a breach until you can prove otherwise.

Once confirmed, your goal is containment. This does not mean pulling the plug on everything. It means stopping the bleeding without destroying evidence.

  • Isolate affected systems from the network. Do not wipe them.
  • Rotate all credentials that may have been exposed: API keys, database passwords, service accounts, admin logins.
  • Revoke active sessions for affected users.
  • Enable enhanced logging on everything. You need to capture what happens next.
  • Preserve forensic evidence: disk snapshots, memory dumps, log exports.

Do not reboot servers. Do not delete anything. Forensic evidence is fragile and you will need it later.

Hours 4-24: Assess the scope

Now you need to figure out what happened. What was accessed? How did the attacker get in? Are they still in your systems?

If you do not have internal forensics capability (most startups do not), this is when you call in an incident response firm. Good ones include CrowdStrike, Mandiant, and Secureworks. Expect to pay $25,000-$75,000 for a typical startup-scale engagement. That sounds expensive until you compare it to the cost of getting this wrong. Having an incident response retainer agreed before you need it is cheaper and far faster than sourcing a firm mid-incident.

While the forensics team works, start documenting everything. Create a timeline. Record every action you take with timestamps. This documentation will be critical for regulators, customers, and your legal team.

Before you need it. Incident response on retainer means the contracts, the access and the runbooks already exist when the pager goes off. See how a retainer works

Hours 24-48: Legal and regulatory

Call your lawyer. If you do not have a lawyer who understands data breach law, find one immediately. Breach notification requirements vary by jurisdiction, and getting them wrong can multiply your liability.

Key regulatory deadlines to know:

  • GDPR: 72 hours to notify the supervisory authority if EU personal data is involved.
  • US state laws: Varies from 30 to 90 days depending on the state. Some states require notification to the Attorney General.
  • HIPAA: 60 days for individual notification, 60 days for HHS if more than 500 records.
  • SEC: Public companies must report material cybersecurity incidents within 4 business days.

Your lawyer will help you determine what applies. Do not try to figure this out on your own.

Hours 48-72: Communication

This is where most companies fail. The instinct is to say as little as possible and hope it goes away. That never works.

Draft your breach notification with these elements: what happened, what data was affected, what you are doing about it, and what affected individuals should do. Be specific and honest. Vague statements like "a limited number of users may have been affected" erode trust faster than the breach itself.

Notify affected customers directly via email. Post a public incident report on your website. Brief your customer-facing teams so they can answer questions. If the breach is significant, consider offering credit monitoring or identity theft protection.

After the first 72 hours

Once the immediate crisis is managed, shift to remediation and prevention. Fix the vulnerability that was exploited. Implement the security controls that would have detected or prevented the breach. Conduct a thorough postmortem (blameless, focused on systems not people). Update your incident response plan based on what you learned.

The startups that survive breaches are the ones that respond quickly, communicate honestly, and emerge with stronger security than they had before.

Need help with breach response?

traztech helps startups build incident response plans before breaches happen and provides hands-on support when they do. We have guided dozens of companies through security incidents.

Book a free strategy call

Call Your Insurer Before You Call Anyone Else

This is the step that costs companies the most money when they skip it. If you carry cyber insurance, your policy almost certainly requires you to notify the carrier promptly and to use forensics, legal, and public relations firms from their approved panel. Engaging a firm outside the panel without written consent can reduce or void coverage for those costs, and the invoices in question are the largest ones in the incident.

Find the policy now, before you need it. What you need on hand is the 24-hour breach hotline number, the policy number, the named insured entity, the retention amount, and the panel list. Put those five things in a document that does not live inside the environment that might be compromised. During an incident, the hotline typically routes you to breach counsel within the hour, and counsel then retains the forensics firm on your behalf. That ordering matters for the next reason.

Privilege, and Why Counsel Hires the Forensics Firm

Forensic reports are among the most damaging documents produced in breach litigation and regulatory review, because they say in plain language what you missed. Where the law allows it, having outside counsel retain the incident response firm, with the report addressed to counsel for the purpose of providing legal advice, gives you a privilege argument. Hiring the firm directly on a standard services agreement generally does not, and courts have compelled production of reports in exactly that posture.

Privilege is not a reason to hide anything or to slow down the technical work. It is a reason to be deliberate about who commissions which document. Two practical habits follow from it. Keep incident communications in a defined channel with a limited membership rather than spread across every Slack room, and coach the team that speculation typed into a channel at 2am is discoverable. Write observations, not conclusions, until you have facts. There is a real difference between "the access log shows requests from this IP to this endpoint between these timestamps" and "we think they took the whole customer table."

Who Is Actually in Charge

Most small companies discover during their first real incident that everyone is doing everything and nobody is deciding anything. Assign four roles in the first hour, by name, out loud. If nobody on staff has run an incident before, this is one of the clearest arguments for a fractional CISO on standing engagement, because the commander role is judgment under pressure and it does not go well the first time.

The incident commander owns decisions and does not do hands-on technical work. Their job is to keep the effort ordered, to decide when to contain versus observe, and to be the one person who can say stop. The scribe maintains a timestamped log of every observation, decision, and action, including who did it. This is tedious and it is the single most valuable artifact you will produce, both for the forensics firm and for the regulator. The communications lead owns all outbound messages to customers, staff, and press, and no one else speaks. The technical lead runs the investigation and containment.

One more decision belongs to the incident commander explicitly: contain now or watch first. Isolating a compromised host immediately tells the attacker they have been seen, and if they have persistence elsewhere they will burn it or escalate. Watching costs you exposure time. For most startups, containment wins, because the ability to conduct covert observation without tipping off an attacker is a capability you probably do not have. Make the call consciously rather than by default.

The Canadian Obligations People Miss

The article above lists GDPR, HIPAA, and US state timelines. If you operate in Canada or hold data about people in Canada, two more apply and they work differently from what most engineers expect.

Under PIPEDA, a breach of security safeguards must be reported to the Office of the Privacy Commissioner of Canada as soon as feasible if it creates a real risk of significant harm, and affected individuals must be notified as well. There is no fixed hour count, which sounds forgiving and is not: "as soon as feasible" is judged after the fact. Separately, and this is the part that gets missed, you must keep a record of every breach of security safeguards for 24 months, including ones you concluded did not create a real risk of significant harm. The Commissioner can ask for that log. Most companies have no log at all.

Quebec's Law 25 uses the term confidentiality incident, requires notification to the Commission d'acces a l'information and to affected individuals where there is a risk of serious injury, and also requires an incident register. The assessment factors include the sensitivity of the information, the anticipated consequences, and the likelihood it will be used for a harmful purpose.

Then there are your contracts, which frequently bite before any regulator does. Enterprise master services agreements and data processing agreements routinely require notice to the customer within 24, 48, or 72 hours of becoming aware, and some define awareness as the moment any employee suspects. Pull the notification clauses from your ten largest contracts and put the shortest window on a card. Discovering a 24-hour contractual obligation on day three is a bad way to find out.

If Someone Is Asking You for Money

Extortion changes the shape of the response. A few things to know before it happens rather than during.

Paying may be legally restricted, not merely distasteful. If the group behind the attack is subject to sanctions, a payment can expose your company and anyone facilitating it to sanctions liability, and specialist counsel and negotiators check this before any funds move. Payment also does not reliably work: decryptors are often slow or partial, and data theft claims cannot be undone by a receipt.

Separate the two questions that get tangled. Can you recover without the key, which is a backup and restore question you should already know the answer to, and can you prevent publication, which you largely cannot. Decide in advance who has authority to authorize any payment, because it will not be the engineer reading the ransom note.

When You Do Not Need to Hire Anyone

Plenty of incidents do not warrant a five-figure forensics engagement, and we would rather say that than take the work.

If a researcher reported a vulnerability, your logs show no exploitation, and the affected component has complete request logging you trust, you can fix it, document the review, and move on. A disclosure is not a breach.

If one employee laptop was hit by commodity malware, the device was enrolled in EDR that quarantined it, and that user had no standing production access, rebuild the machine, rotate their credentials, and record the decision. Bringing in an incident response firm for that is a way to spend $30,000 confirming what your own tooling already told you.

If a single API key leaked in a public repository and your provider logs show no use of it before revocation, rotate, add secret scanning, and write it up.

Where outside help genuinely earns its cost is when you cannot answer the scope question: you do not know what was accessed, your logs do not cover the relevant period, the attacker had administrative access, or the answer will be read by a regulator or a court. That is a different situation, and it is the one worth having contracts and access arranged for in advance. Rebuild your logging and detection afterwards so the next incident is answerable in-house, which is usually the most valuable thing to come out of the first one.

Before you need it. Incident response on retainer means the contracts, the access and the runbooks already exist when the pager goes off.

See how a retainer worksOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on incident response. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.