Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Who should you call after a cybersecurity breach?

Updated

Name a commander, then page legal, an executive owner, and comms on an out-of-band channel. Next: the cyber insurer and, if you cannot image hosts, DFIR. Law enforcement and regulators are duty questions for counsel. Decision tree, not a vendor list. Not legal advice.

Operational guidance, last verified 7 September 2026 against CISA incident-reporting guidance, NIST SP 800-61r2, the FTC Data Breach Response guide, the SANS Incident Handler's Handbook, and FBI IC3. It is not a notification determination, not a substitute for counsel, your insurer, or a retained DFIR firm, and not a ranking of vendors.

This is a calling order, not a vendor list

Audience: a founder, CTO, CISO, or on-call lead who does not have an incident-response retainer and needs to know who to reach — and who not to reach yet — in the first hour. The first-15-minutes checklist on this site names a commander and opens an out-of-band bridge. This page is the contact map that commander works: internal (commander, legal, executive, comms) versus external (insurer, outside counsel, DFIR, law enforcement, regulator), in an order with reasons.

It is a decision tree. It does not rank law firms, carriers, or DFIR vendors, and it does not name any. NIST SP 800-61r2 expects the team to notify appropriate internal parties as the incident is handled, and to establish lines of communication with legal, public affairs, management, and law enforcement before an incident — through designated people, not a blast. The FTC Data Breach Response guide, which is US regulator guidance for businesses rather than a statute, tells firms to assemble a team that can include legal, forensics, information security, operations, communications, and management. CISA asks organizations to report cyber incidents; that ask is not the same as a legal duty to file. Last verified 7 September 2026. Not legal advice.

  • Internal first, on a channel the actor cannot see. CISA: do not tip the actor.
  • Counsel before outside vendors when you can. That is common practice so counsel can direct the investigation; it is not a legal conclusion that privilege will attach on your facts.
  • The insurer when your policy's notice condition says to — often before you pick a DFIR firm. Read YOUR policy. This page does not interpret it. The contact-cyber-insurance page on this site is the notice-and-panel checklist.
  • DFIR if you cannot capture memory and disk yourselves. Page the retained firm or the insurer's panel. A dedicated DFIR guide is not on this site yet.
  • Law enforcement and regulators are a different kind of call. Some are legal requirements when they apply; CISA and FBI IC3 reporting is, today, voluntary sharing for most operators. Counsel maps YOUR facts. Mapping is not filing.

Internal: commander, legal, executive, comms

Split command is how two stories, two evidence holds, and two public statements get born. Name one commander first — the first-15-minutes page is the checklist. Then the commander pages the rest of the internal roster. NIST SP 800-61r2 treats legal, public affairs, and management as groups the incident team must already have a line to. The FTC guide's team list is the same idea in business language: legal, information security, operations, communications, investor relations, and management, scaled to the company.

Internal contacts (operational; confirm against your plan — not a filing)
WhoWhenWhy, and the limit
Incident commanderImmediately. If no one is named, name one now.Owns the call order, the UTC log, and the contain-versus-observe decision. Everyone else reports to that person for the hour. The first-15-minutes checklist on this site is the naming step.
In-house legal (or the lawyer your plan names)As soon as the incident is declared — not after you 'know everything'.Whether the event is a notifiable breach is a legal determination. This page does not make it. Counsel also tells you how to keep the working papers so they are usable. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
Executive owner (founder, CEO, or whoever your plan names)As soon as the incident is declared, in parallel with legal.Service impact, spend, and any public statement need a single executive owner. A board update follows your governance plan; it is not a customer notice and not a regulator filing.
Communications / public affairsOn the need-to-know bridge so they do not freelance. Not so they publish.NIST SP 800-61r2: discuss information sharing with public affairs, legal, and management before an incident, and keep one current-status statement. One spokesperson. CISA: a public or in-band message is how you tip the actor. Workforce-wide, customer, press, and status-page notice are not the default in the first hour.
IT, cloud, identity, and anyone who can destroy evidenceAs soon as isolation and an evidence hold are in play.They must receive the hold: do not rotate logs, reimage, or tidy. They do not need the full attack narrative on a channel the actor can see. See the first-24-hours page on this site.

External: insurer, counsel, DFIR, law enforcement, regulator

External calls are how you get coverage, privilege, forensics, and — only when a duty applies — a filing. They are also how you pick the wrong firm, void a notice clause, or file with the wrong authority. Order matters. The contact-cyber-insurance page on this site is the notice-and-panel checklist. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. A dedicated 'when you need DFIR' guide is not on this site yet; until it is, that role stays on this map.

External contacts (operational; confirm against your plan, policy, and counsel — not a vendor ranking)
WhoWhenWhy, and the limit
Outside breach counselWhen you have no in-house privacy or incident lawyer, or when in-house counsel wants outside help — often immediately.Common practice is that counsel retains DFIR so the investigation sits under attorney-client privilege and work-product. That is practice, not a guarantee that privilege will attach on your facts. Privilege is a legal question for counsel. This page is not legal advice.
Cyber insurerWhen your policy's notice condition says to. Many policies require prompt notice of an incident, sometimes before you retain a firm from their panel.Read the notice clause on YOUR policy. Late notice, or a unilateral DFIR/counsel engagement the panel does not recognise, is a coverage argument you do not want. This page does not interpret your contract.
DFIR / forensicsIf you cannot capture memory and disk yourselves and evidence is at risk. The first-24-hours page on this site is the hour-to-day-one capture checklist.Page the retained firm, or ask counsel and the insurer which panel firm to call. Do not wait for a perfect scope. They cannot image a host you already rebuilt. This page does not rank firms.
Law enforcement (local police, FBI, U.S. Secret Service)The FTC guide tells businesses to consider notifying law enforcement, to call local police, and if local police are not equipped for an information compromise, to contact the local FBI or U.S. Secret Service field office. FBI IC3 is the internet-crime complaint path.Whether you must, and to whom, is jurisdiction- and sector-specific. Ask counsel. NIST SP 800-61r2: contact law enforcement through designated individuals, consistent with law and your procedures — one primary point of contact. This page does not file a report.
CISA (US federal cyber reporting path)CISA asks every organization that experiences a cyber incident to report it, and publishes 24/7 paths (cisa.gov/report, report@cisa.gov, 1-844-Say-CISA). That is an operational ask and voluntary sharing today for most operators.CIRCIA (the Cyber Incident Reporting for Critical Infrastructure Act of 2022) will require covered entities to report covered incidents and ransomware payments once the final rule is in effect. Last verified 7 September 2026: the CIRCIA final rule is not in effect; CISA is still in rulemaking. Do not treat a CISA report as a GDPR, CRA, or US-state filing. Counsel maps YOUR duties.
Regulators and supervisory authoritiesOnly when a legal duty applies to YOUR facts — and on counsel's clock, not this page's.Examples that are legal requirements only when they apply: US state (and territory) breach-notification statutes; sector rules such as HIPAA or the FTC Health Breach Notification Rule; GDPR Article 33 to a supervisory authority; CRA Article 14 to a CSIRT and ENISA. Filing one never discharges another. The first-24-hours and first-72-hours pages on this site map clocks; they do not start one.

Decision tree — who to call, in order

Walk top to bottom with the commander and counsel. 'Yes' does not mean you skip the later questions. A 911 call does not replace the insurer notice; a CISA report does not replace a GDPR filing. Last verified 7 September 2026. Not legal advice.

Who should you call? (questions for the commander and counsel — not a determination; not legal advice)
QuestionIf the facts point yesIf the facts point no
Is someone in immediate physical danger, or is this an active facility emergency?Call 911 / local emergency services first. CISA's critical-infrastructure contact guidance: if a significant incident is in progress, call local law enforcement and emergency responders. Then come back to this tree.Continue. Do not skip the internal roster because the incident 'only' looks digital.
Do we have a named incident commander on an out-of-band channel, with a UTC log started?That person owns the rest of the call order. Do not start a second command thread on the possibly compromised identity plane.Name one now. Use the first-15-minutes checklist on this site: declare, name a commander, open a clean bridge, start the log, isolate, preserve volatile evidence. Do not reimage or power down yet.
Do we have in-house legal, or a retained breach counsel?Page them before you retain outside vendors when you can. Common practice: counsel directs DFIR so the investigation can sit under privilege. That is practice, not a ruling that privilege attaches. Confirm with counsel.Page the executive owner and get counsel. Do not wait for a complete picture. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
Do we have a cyber insurance policy?Read the notice clause. Many policies want prompt notice, and some require you to use a panel DFIR firm. Notice the carrier before you pick a non-panel vendor if that is what the policy says. This page does not interpret the contract.Still consider DFIR if you cannot image hosts. Do not invent a panel. The contact-cyber-insurance page on this site is the notice-and-panel checklist.
Can we capture memory and disk ourselves, forensically?Do that. The first-15-minutes and first-24-hours pages on this site are the capture-and-hold checklists. You can still bring DFIR later for analysis.After counsel and the insurer, page the retained or panel DFIR firm in the first 24 hours, not after you have rebuilt. Hand them the timeline and the hold list. This page does not rank firms.
Might a reporting duty apply (personal data, product security, critical infrastructure, sector, US state)?Counsel maps the duty. Mapping is not filing. The first-24-hours and first-72-hours pages on this site list clocks that MAY apply (including CRA Article 14 and GDPR Article 33) as questions for counsel. This page does not start a clock.You can still share operationally: CISA asks organizations to report incidents voluntarily; FBI IC3 accepts internet-crime complaints from victims and third parties. Sharing with CISA or IC3 is not a determination that a legal notification duty has started.
Should we notify law enforcement?The FTC guide: consider notifying law enforcement; call local police; if they are not equipped, contact the local FBI or U.S. Secret Service. FBI IC3 is the complaint intake (use the words 'data breach' in the description when that is the incident type). One designated point of contact, per NIST SP 800-61r2.Document the decision not to, with counsel. Do not treat 'we have not finished scoping' as a standing reason never to call. Whether you must call is still counsel's question on your facts.

Mandatory reporting versus advisory sharing

Mixing these is how a contact page turns into fake legal advice. A legal requirement applies only if the instrument applies to you. Regulator guidance tells you what a regulator currently recommends. Industry practice is what CISA, NIST, and SANS publish as operational handling. Last verified 7 September 2026. Not legal advice.

Where each contact claim on this page comes from (described as published; not legal advice)
KindWhat it is on this pageSource
Legal requirement (only if it applies)US state (and territory) breach-notification statutes; sector rules such as HIPAA or the FTC Health Breach Notification Rule; GDPR Article 33; CRA Article 14. CIRCIA reporting, once the final rule is in effect, for covered entities.The statute or regulation itself. Confirm applicability with counsel. This page does not apply them to you. Last verified 7 September 2026: the CIRCIA final rule is not in effect.
Regulator guidance (advisory unless a statute it points at applies)Assemble a team (legal, forensics, communications, management); consider notifying law enforcement; call local police, then FBI or Secret Service if needed; notify affected parties when the facts require it.FTC, Data Breach Response: A Guide for Business. CISA incident-reporting pages (written as an ask to organizations; CISA playbooks are operational procedures written for US federal civilian executive branch systems). FBI IC3 is a complaint intake, not a statute.
Industry / operational practiceOne commander; out-of-band bridge; designated law-enforcement point of contact; legal, public affairs, and management on the internal roster; counsel often retains DFIR.NIST SP 800-61r2 (guidance, not a statute). SANS Incident Handler's Handbook (practitioner checklist). Counsel-first-for-privilege is common practice, not a NIST or FTC legal rule, and not a guarantee of privilege.

Counsel-first and privilege — common practice, not a ruling

Many organizations have counsel retain the DFIR firm and direct the investigation so attorney-client privilege and work-product can cover the working papers. That sequence is common practice among incident lawyers. It is not a statement that privilege will attach on your facts, not a reason to hide facts from people who must act (isolation, evidence hold, insurer notice), and not legal advice.

The FTC guide says consult legal counsel, then you may consider hiring outside counsel with privacy and data security expertise to advise on federal and state laws that a breach may implicate. NIST SP 800-61r2 says legal experts should review incident-response plans and that responders should seek legal guidance when an incident may have legal ramifications. Neither source says 'privilege always attaches if you call a lawyer first.' Counsel tells you how to keep the papers. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.

  • Page counsel early so later vendor and regulator calls happen with advice, not as a surprise.
  • Do not wait for a complete forensic picture before that call. Completeness is a later timebox.
  • Do not use 'privilege' as a reason to skip the insurer's notice clause or a legal reporting duty. Coverage and notification are different questions.
  • One internal owner for outside counsel and DFIR (usually the commander or in-house legal). Split instructions are how two images get taken and neither is complete.

Where this shows up in ShipReady Metrics

The signed-in app does not page people, retain counsel, notice an insurer, or file with CISA, the FBI, or a regulator. It does not keep a call tree. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. It does not start a clock for you, it is not a contact list, and it is not a determination that CRA applies. A named human still submits. The cyber risk register lives under Security; the obligation map (frameworks you have marked in-scope) is under Compliance. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.

Primary sources (last verified 7 September 2026)

Every operational and regulatory claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.

CISA's reporting pages ask organizations to report cyber incidents and publish the 24/7 paths; they are not themselves a statute. CIRCIA will impose reporting duties on covered entities when the final rule is in effect — last verified 7 September 2026, it is not. NIST SP 800-61 Revision 2 remains the current final Computer Security Incident Handling Guide (August 2012) — guidance, not a statute. The SANS Incident Handler's Handbook is a practitioner checklist. The FTC Data Breach Response guide is business guidance from a US regulator; the legal notification duties are in the statutes it points at, not in the guide itself. FBI IC3 is the Bureau's internet-crime complaint intake; the FBI is the lead US federal agency for investigating cyberattacks and intrusions. Regulation (EU) 2016/679 Article 33 and Regulation (EU) 2024/2847 Article 14 are legal requirements only when they apply.

Frequently asked questions

Who should we call first after a cybersecurity breach?

Name one incident commander, then page in-house legal, an executive owner, and comms on an out-of-band channel. Next, with counsel: the cyber insurer (read YOUR notice clause) and, if you cannot capture memory and disk, a DFIR firm — retained or the insurer's panel. Law enforcement and regulators are duty questions for counsel, not the first ring. NIST SP 800-61r2, the FTC guide, CISA, and SANS are the operational sources. Not legal advice.

Should we call counsel before the insurer and DFIR?

Common practice is counsel first, so counsel can direct DFIR and the working papers can sit under attorney-client privilege and work-product. That is practice, not a ruling that privilege will attach on your facts, and not a reason to miss a policy notice clause. Many cyber policies want prompt notice, sometimes before you pick a panel firm. Read YOUR policy; this page does not interpret it. The contact-cyber-insurance page on this site is the notice-and-panel checklist. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. Not legal advice.

Do we have to report this to CISA, the FBI, or a regulator?

This page cannot tell you. CISA asks every organization to report cyber incidents (cisa.gov/report); that is voluntary sharing today for most operators. Last verified 7 September 2026, CIRCIA mandatory reporting is not in effect until the final rule's effective date. FBI IC3 is a complaint intake. Regulator filings (US state statutes, HIPAA, GDPR Article 33, CRA Article 14, and others) are legal requirements only when they apply. Counsel maps YOUR facts. Mapping is not filing. Not legal advice.

When should we call law enforcement?

The FTC Data Breach Response guide tells businesses to consider notifying law enforcement, to call local police, and if local police are not equipped for an information compromise, to contact the local FBI or U.S. Secret Service. FBI IC3 accepts the internet-crime complaint. NIST SP 800-61r2: one designated point of contact, consistent with law and your procedures. Whether you must call is jurisdiction- and sector-specific. Ask counsel. If there is immediate physical danger, call 911 first. Not legal advice.

Is this legal advice?

No. It is a contact map and decision tree distilled from CISA incident-reporting guidance, NIST SP 800-61r2, the FTC Data Breach Response guide, the SANS Incident Handler's Handbook, and FBI IC3. Who you must call, whether privilege attaches, whether a policy notice clause is satisfied, and whether a regulator filing is due are legal questions for counsel on your facts. This page does not start a reporting clock and does not rank vendors.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.