Respond guides

Incident response, breach reporting, and CRA Article 14 reporting ladders — first moves through regulatory notification.

We've been breached — what do we do now?

Stop, isolate, and preserve. Do not reimage, power down, or delete logs. Name a commander, start a contemporaneous log, and keep the actor in the dark. Then work the timeboxes: first 15 minutes, first hour, first 24 hours, first 72 hours, first week.

First 15 minutes after a cybersecurity incident

In the first 15 minutes: declare an incident, name a commander, open a comms bridge the actor cannot see, start a contemporaneous log, and preserve volatile evidence. Do not power down or reimage yet.

First hour after a breach

In the first hour after a breach: finish isolate-and-preserve, then scope affected systems and accounts, decide contain-versus-observe, engage leadership, counsel, and the insurer, and begin a UTC timeline. Do not eradicate or reimage yet.

First 24 hours after a breach

In the first 24 hours after a breach: continue the UTC timeline, put an evidence hold on logs and hosts, finish short-term containment, decide who is informed, and map which reporting clocks may have started. This page does not start a clock and is not legal advice.

First 72 hours after a breach

In the first 72 hours after a breach: keep the timeline and evidence hold, finish containment, decide with counsel whether a 72-hour notification clock applies (GDPR Article 33, CRA Article 14), and document the facts. This page does not start a clock and is not legal advice.

First week after a breach

In the first week after a breach: validate recovery, keep the evidence package, plan individual notice with counsel, start the CRA 14-day final-report clock if it applies, and hand off to post-incident review. Not legal advice.

Who should you call after a cybersecurity breach?

Name a commander, then page legal, an executive owner, and comms on an out-of-band channel. Next: the cyber insurer and, if you cannot image hosts, DFIR. Law enforcement and regulators are duty questions for counsel. Decision tree, not a vendor list. Not legal advice.

When should you contact cyber insurance?

Notify the cyber insurer as soon as the incident is a possible claim — often before you pick DFIR or outside counsel. Read YOUR policy's notice and panel-vendor clauses. This page is not legal advice and not coverage advice.

When should you contact outside breach counsel?

Contact outside breach counsel as soon as legal exposure, privilege, or a notification question is on the table, often in the first hour, before you retain DFIR. Counsel-first is common practice, not a ruling that privilege will attach. This page is not legal advice.

What is digital forensics and incident response?

DFIR is digital forensics plus incident response: identify potential evidence, preserve it in a forensically sound way, analyze a working copy, and report what the evidence supports. It sits inside IR; it does not replace it. This page is not legal advice.

When do you need a DFIR firm?

Bring in a DFIR firm when you cannot preserve evidence forensically in-house, when regulated data, theft, litigation, or an insurer panel is in play, or when in-house capability is not enough. This is a decision tree, not a ranking. Not legal advice.

What evidence should you preserve after a breach?

Preserve volatile evidence first: memory and live state before disk, then logs, then archives. Record chain of custody as you collect. Isolate, do not wipe. This page is not legal advice.

What should you never delete or reimage after a breach?

Do not power down a live host, reimage, rotate or delete logs, purge mailboxes or accounts, or clean up malware before imaging. Isolate, do not destroy. This page is not legal advice.

How do you determine whether data was actually stolen?

Determine theft from evidence: egress or network logs, cloud access logs, data-staging artifacts, and DLP. Access is not exfiltration. Missing egress logs do not prove no theft. Notification is counsel's legal call. This page is not legal advice.

Compromise vs access vs exfiltration vs confirmed data breach

Compromise, access, exfiltration, and a confirmed data breach are four different claims. A NIST incident is not a legal breach. GDPR Article 4(12) is an EU legal definition. Counsel maps YOUR statute. This page is not legal advice.

How to build an incident timeline

Build a defensible incident timeline in UTC: one row per event, source, evidence ID, and notes. Normalize timezones and clock skew before correlating logs. Mark first access, dwell, discovery, and containment as practitioner metrics, not SLAs. Cite evidence. This page is not legal advice.

Post-incident review checklist

After a security incident, schedule a lessons-learned review within a few days: capture what worked and what failed, log corrective actions with owners and due dates, and update controls. This page is not legal advice.

How to perform root cause analysis after a security incident

After a security incident, run a blameless root-cause analysis: separate the proximate cause from the root cause, list contributing factors, and assign corrective actions with owners. Outputs may feed audit evidence. This page is not legal advice.

How to document containment and recovery actions

Log every containment, eradication, and recovery action: who, what, when (UTC), why, and the evidence ID. Isolate, do not destroy. Eradicate before you restore. This page is not legal advice.

Ransomware response checklist

Isolate ransomware hosts without wiping them. Identify the strain, assess backups, and treat payment as a counsel, insurer, and OFAC sanctions-risk question — not a recommendation. Report to CISA and law enforcement. This page is not legal advice.

Credential compromise response checklist

Revoke sessions and tokens, rotate the credential, enforce MFA, then hunt persistence before the actor moves laterally. Secrets in code or CI are a source. This page is not legal advice.

Cloud account compromise response checklist

Preserve cloud audit logs first — they can roll off. Review IAM changes and new resources, hunt cryptomining and data staging, rotate keys and roles, then evict the actor across the tenant. This page is not legal advice.

Repository compromise response checklist

Revoke repository access, tokens, and deploy keys. Diff for malicious commits and workflow changes. Rotate any secret that sat in history. Ask whether a published artifact was poisoned. This page is not legal advice.

CI/CD pipeline compromise response checklist

Freeze the pipeline. Audit runners, workflows, and secrets. Rotate every pipeline credential and signing key. Verify artifact provenance and check downstream releases. This page is not legal advice.

Supply-chain incident response checklist

Confirm whether a vendor or supply chain dependency breach reached you. Map the blast radius. Walk contractual and possible DORA or CRA flow-down duties with counsel. This page does not start a clock and is not legal advice.

What are the best incident response firms?

What are the best incident response firms? This page is an inclusion-criteria checklist, not a ranking. Inclusion is not endorsement. Verify current public IR offerings, retainers, and accreditation class. Not legal advice.

Best digital forensics firms — criteria, not a ranking

Evaluate digital-forensics firms by stated criteria — accreditation class (PFI, CREST, ISO/IEC 17025), jurisdiction, and media/cloud/mobile scope — not a ranking. Verify the current public roster. Not legal advice.

How to select a DFIR provider

Select a DFIR provider with a decision tree and stated criteria — accreditation class, insurer-panel constraint, jurisdiction, and scope — not a ranking. Red flags are listed. Not legal advice.

How do DFIR firms preserve chain of custody?

A chain of custody is the chronological record of digital evidence: who collected it, hashes, every transfer, and the working copy examiners use. DFIR firms keep that record so another examiner can reconstruct handling. This page is not legal advice.

What is an incident response retainer?

An incident-response retainer is a pre-breach contract: prepaid hours, a named SLA, and often a panel or notice clause. It is not the same as on-demand engagement after an incident. Typical terms are generic, not YOUR policy. Not legal advice.

Should you have an incident response retainer before a breach?

Buy a retainer when surge, panel, or a notification clock will outrun a new procurement. Use on-demand when the estate is small, in-house capture is sound, and YOUR policy does not require a panel. This is a decision tree, not a ranking. Not legal advice.

Questions to ask an incident response provider

Ask an IR provider about accreditation class (PFI, CREST, FedRAMP CSO), SLA, data handling, jurisdiction, tooling, deliverables, and cost model — then score the answers against good-answer and red-flag signals. Not a ranking. Not legal advice.

What does a breach investigation cost?

A breach investigation (DFIR) is one bill, not the IBM total-breach average and not a GDPR or CRA fine. Cost drivers set the range; this page is not a quote. Not legal advice. Not financial advice.

What information should you give a DFIR firm?

Hand over assets, logs, access, a UTC timeline, and architecture so DFIR intake can start. Do not wipe, rebuild, or alter hosts first. This page is not legal advice.

How do major incident response providers compare?

Compare major IR providers by stated criteria — parent, accreditation class, public scope, and retainer as they describe it. This is not a ranking. Inclusion is not endorsement. Not legal advice.

Do I have to report a cybersecurity breach?

Maybe. Reporting is mandatory only when a named regime applies to your facts — personal-data notification, sector or incident reporting, or product-vulnerability reporting. This page maps those classes. It is not legal advice and does not start a clock.

Which reporting obligations might this incident trigger?

Walk this tree top to bottom. Each yes adds a regime that may apply; a yes on an earlier row does not skip later rows. This tool is not legal advice and does not start a clock.

Which cybersecurity reporting deadline fires first?

Statutory clocks differ by regime. GDPR Article 33 is 72 hours from awareness; CRA Article 14 is a 24-hour, 72-hour, and 14-day ladder. This table is not legal advice, does not start a clock, and does not average those times.

Who must be notified after a data breach?

Supervisory authorities, CSIRTs, affected individuals, customers, law enforcement, payment brands, and insurers are different recipient classes. Each is a legal requirement, a contractual obligation, or best practice only when it applies. This map is not legal advice and does not start a clock.

How do regulator, customer, and individual notices differ?

Regulator, customer (controller or processor), and individual (data subject) notices are three different streams. Each has its own who, threshold, clock, content, and channel. This comparison is not legal advice and does not start a clock.

Which countries' breach laws might apply to this incident?

Walk establishment, targeting, data-subject location, processing location, and sectoral reach. Those tests decide which regimes may attach to one incident. This applicability map is not legal advice and does not start a clock.

What must a regulatory incident report contain?

A regulator report is a field checklist, not one universal form. GDPR Art. 33(3), CRA Art. 14, NIS2 Art. 23, and the DORA RTS name different content. Partial information is permitted where the article says so. Not legal advice. The product does not file.

What evidence should support a regulatory filing?

The filing is the notice. The evidence is the record that can show how you knew, what you scoped, what you assessed, and what you fixed. GDPR Art. 33(5) documents facts, effects, and remedial action. A forensic chain of custody is a different job. Not legal advice.

How do you document your reporting decision?

Document the notify or no-notify decision even when you do not notify. GDPR Art. 33(5) records any personal data breach — facts, effects, remedial action — so a later reader can verify Article 33. This page is not legal advice.

What happens if you fail to report a cybersecurity incident?

Failure to make a required notification can attract statutory maxima under GDPR Article 83, NIS2 Article 34, HIPAA 45 CFR 160.404, and SEC civil-penalty authority. Those maxima are not typical fines. This table is not legal advice, does not start a clock, and does not compute YOUR penalty.

How do regulators determine whether you knew about an incident?

Notification clocks start from the event the cited article names — awareness, determination, or discovery — not from a product timestamp. This page is not legal advice, does not start a clock, and does not find that you became aware.

When must you notify a GDPR personal data breach?

Article 33(1) GDPR: notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware, unless unlikely to result in a risk. Article 34 is a separate high-risk individual duty. Not legal advice; does not start a clock.

When must you report a significant incident under NIS2?

Article 23 of Directive (EU) 2022/2555 (NIS2) sets a 24-hour early warning, a 72-hour incident notification, and a one-month final report after that notification. Those three marks are not one number. This page is not legal advice and does not start a clock.

When must you report a DORA major ICT-related incident?

Article 19 DORA: financial entities report major ICT-related incidents to the relevant competent authority in three distinct stages — an initial notification, an intermediate report, and a final report — under time limits in the RTS. Classification is Article 18. Not legal advice; does not start a clock.

When must you report under CRA Article 14?

Article 14 of Regulation (EU) 2024/2847 (CRA) sets a 24-hour early warning, a 72-hour notification, and a 14-day final report on the actively-exploited track. Those three marks are not one number. This page is not legal advice and does not start a clock.

When must you notify a UK GDPR personal data breach?

UK GDPR Article 33(1): notify the Commissioner without undue delay and, where feasible, not later than 72 hours after having become aware, unless unlikely to result in a risk. Article 34 is a separate high-risk duty. Not legal advice; does not start a clock.

Which US state breach-notification laws might apply?

All 50 US states now have a data-breach notification law. Individual, attorney-general, and credit-bureau notices are different recipient classes with different clocks. This representative table is not a restatement of every statute. Not legal advice; does not start a clock.

When must you file Form 8-K Item 1.05 for a cyber incident?

Form 8-K Item 1.05: if a registrant determines a cybersecurity incident is material, file within four business days of that determination — not discovery, not GDPR awareness, not four calendar days. Item 1.05 is not Item 8.01 and not Item 106. Not legal advice; does not start a clock.

When must you notify a HIPAA breach?

Covered entities notify individuals without unreasonable delay and in no case later than 60 calendar days after discovery (45 CFR 164.404). HHS OCR uses a 500+ versus <500 clock (164.408). Media notice is a separate 500-resident trigger (164.406). Not legal advice; does not start a clock.

When must you notify a PIPEDA breach of security safeguards?

PIPEDA s. 10.1: if it is reasonable to believe a breach of security safeguards creates a real risk of significant harm, report to the Commissioner and notify the individual as soon as feasible after the organization determines the breach occurred. Not legal advice; does not start a clock.

When must you notify an eligible data breach?

If Part IIIC applies, notify the Commissioner and affected individuals as soon as practicable after becoming aware of reasonable grounds to believe an eligible data breach occurred (ss 26WK–26WL). The 30-day window is assessment, not a notify clock. Not legal advice; does not start a clock.

When must you report a CERT-In incident or a DPDP breach?

Two regimes: CERT-In Directions (ii) set a 6-hour report from noticing a reportable cyber incident (in force since 27 June 2022). DPDP s.8(6) and Rule 7 intimation is not in force until 13 May 2027. Not legal advice; does not start a clock.

Which UAE, DIFC or ADGM regime applies to a breach?

Three UAE regimes. Federal PDPL Art. 9: immediately / as set by Executive Regulations (72h is not in the Decree-Law). DIFC Arts 41–42: as soon as practicable. ADGM Art. 32: without undue delay / 72h where feasible. Not legal advice; does not start a clock.

What does CRA Article 14 require you to report, and when?

Article 14 of Regulation (EU) 2024/2847 sets a 24-hour early warning, a 72-hour notification, and a 14-day final report on the actively-exploited track, from 11 September 2026. This CRA-cluster overview is not legal advice and does not start a clock.

What is the CRA Article 14 24-hour early warning?

The CRA 24-hour early warning is an Article 14 notification to the CSIRT designated as coordinator and to ENISA via the single reporting platform, without undue delay and in any event within 24 hours of the manufacturer becoming aware.

What is the CRA Article 14 72-hour notification?

The CRA 72-hour notification is an Article 14 vulnerability or incident notification to the CSIRT designated as coordinator and to ENISA via the single reporting platform, without undue delay and in any event within 72 hours of the manufacturer becoming aware.

Where do you submit CRA vulnerability reports?

Manufacturers submit Article 14 reports of Regulation (EU) 2024/2847 simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform established under Article 16. This page is not legal advice and does not start a clock.

How does the ENISA single reporting platform workflow work?

The ENISA Single Reporting Platform is the Article 16 channel for CRA Article 14 notifications: identity, then 24-hour, 72-hour, and final entries, then CSIRT dissemination. This page is an agency-guidance walkthrough, not the regulation, not legal advice, and does not start a clock.

What does the CSIRT designated as coordinator do after a CRA filing?

The CSIRT designated as coordinator (Article 3(51) of Regulation (EU) 2024/2847) receives Article 14 notifications via the single reporting platform and disseminates them. It may delay dissemination on cybersecurity-related grounds under Delegated Regulation (EU) 2026/881. This page is not legal advice and does not start a clock.

Do I need a penetration test?

A penetration test is needed when a contract, framework, or regulation requires one — PCI DSS 11.4, a customer exhibit, or auditor practice around SOC 2 or ISO 27001. Scanning and SAST/DAST do not substitute. This page is not legal advice.

What is the difference between a penetration test and a vulnerability scan?

A vulnerability scan is automated breadth across known checks. A penetration test is a scoped attempt to exploit, usually with a human methodology. PCI DSS treats them as different requirements (11.3 vs 11.4). A scan is not a pen test. This page is not legal advice.

What is the difference between SAST, DAST, and SCA?

SAST reads source without running it. DAST exercises a running application. SCA inventories third-party components and their known vulnerabilities. They find different classes of defect and belong in layers, not as substitutes. This page is not legal advice.

How often should you do a penetration test?

The common bar is at least annually and after significant change — that is PCI DSS 11.4 when PCI applies, and common auditor practice elsewhere. It is not a universal law. Continuous SAST/DAST and scanning cover the gaps between tests. This page is not legal advice.

What does a penetration test cost?

Pen-test price tracks days, seniority, and attack surface — not a catalog SKU. Indicative, time-sensitive observation puts a scoped web-app test from the low thousands of US dollars into five figures when more surfaces are added. Do not choose on price alone. This page is not legal advice.

How do you choose a penetration testing company?

Choose a pen-test firm with stated criteria — accreditation, methodology, scoping, retest, reporting, and references — not a logo list. This page never ranks providers. Accreditation is not endorsement. CREST, CHECK, and PCI ASV authorize different work. Not legal advice.

What should a penetration test report include?

A credible pen-test report states scope, methodology, risk-rated findings with reproduction, remediation guidance, retest status, and an executive summary. A scanner dump is not that report. Weak reports hide method and severity. This page is not legal advice.

What is a penetration test retest?

A retest is targeted validation that agreed findings were remediated — not a second full pen test. PCI DSS 11.4 expects confirmation of fixes when PCI applies. Scope the window in the statement of work. This page is not legal advice.

Does SOC 2 require a penetration test?

SOC 2 has no explicit “annual pen test” mandate in the Trust Services Criteria. Testing supports CC4.1, CC7.1, and CC7.2, and many examiners expect it as practice. A scan is not automatically that evidence. This page is not legal advice.

Does ISO 27001 require a penetration test?

ISO/IEC 27001:2022 does not say “penetration test.” It names technical vulnerability management (A.8.8), security testing in development and acceptance (A.8.29), and secure development (A.8.25). A pen test is one way to evidence those controls. This page is not legal advice.

What is continuous security testing?

Continuous security testing is automated SAST, DAST, SCA, and scanning in CI and production-adjacent environments. It covers the months between point-in-time pen tests. It complements a scoped manual test; it does not replace one. This page is not legal advice.