The decisions made in the first 48 hours after discovering a suspected data breach can significantly affect both the outcome and your insurance claim. Here's a general framework.

Hour 1: Contain, Don't Panic

Isolate affected systems from the network if you can do so without destroying evidence. Avoid the instinct to immediately wipe or rebuild systems — forensic investigators need to examine them first, and premature action can complicate both the investigation and your claim.

Notify Your Cyber Insurer Immediately

Most cyber policies require prompt notification, and many have a dedicated breach response hotline that connects you directly with approved forensic and legal vendors — using your insurer's panel of pre-approved vendors is often required for costs to be covered.

Engage Legal Counsel Early

Breach notification laws vary by state, and having communications with counsel protected by attorney-client privilege matters, especially if litigation follows. Many cyber policies connect you with breach counsel as part of the response.

Don't Communicate Publicly Yet

Resist the urge to post on social media or notify customers before you understand the actual scope of the breach — premature or inaccurate communication can create legal exposure and needs to be coordinated with counsel and your insurer.

Document Everything

Keep a timeline of what was discovered, when, and what actions were taken — this documentation matters both for your claim and for regulatory notification requirements.

Understand Your Notification Obligations

Most states require notifying affected individuals within a specific timeframe once a breach involving personal information is confirmed. Your legal counsel and insurer's breach response team will typically guide this process — timeframes and requirements vary by state and by the type of data involved.

After the Immediate Response

Once contained, focus shifts to full forensic investigation, system hardening, credit monitoring for affected individuals if applicable, and a post-incident review to close the gap that allowed the breach.

This is a general framework, not a substitute for your specific incident response plan or your cyber insurer's breach response protocol — if you don't have either, that's worth addressing now, before an incident happens.