Incident response
Vendor-neutral first-response guidance for founders, CTOs, CISOs, and incident commanders — grounded in CISA, NIST SP 800-61r2, SANS, and the FTC. Not legal advice.
We've been breached — what do we do now?
First moves after a cyber incident: isolate, preserve evidence, name a commander. Do not reimage, delete logs, or tip the actor. CISA, NIST, SANS, FTC.
First 15 minutes after a cybersecurity incident
A single-screen checklist for the first 15 minutes of a cyber incident: declare, name a commander, preserve volatile evidence, and do not power down or reimage yet.
First hour after a breach
First-hour runbook after a breach: scope systems and accounts, decide contain versus observe, engage leadership, legal, insurer, and begin a UTC timeline. Not legal advice.
First 24 hours after a breach
First 24 hours after a data breach: keep the timeline, hold evidence, map which reporting clocks may have started, and decide who is informed. Not legal advice.
First 72 hours after a breach
First 72 hours after a breach: map GDPR Article 33 and CRA Article 14 clocks that may apply, document facts, and decide who to notify. Not legal advice.
First week after a breach
First week after a breach: validate recovery, plan individual notice, start the CRA 14-day final-report window, and hand off to post-incident review. Not legal advice.
Who should you call after a cybersecurity breach?
Who to call after a breach: commander, legal, exec, comms internally; then insurer, counsel, DFIR, law enforcement, regulators. Decision tree, not a ranking. Not legal advice.