Summary. An incident response plan is tested exactly once, under conditions where nobody has time to read it. This toolkit is built for that moment and for the preparation that makes it survivable: what must exist before an incident, the first hours, containment and evidence preservation, the privileged forensic investigation and the case law governing whether the report stays privileged, the jurisdiction-by-jurisdiction notification analysis, and the notification mechanics. Later stages cover ransomware and sanctions, business email compromise, vendor breaches, regulatory response, the litigation that follows, and the post-incident work.
What this toolkit is for, and who should use it
Every organization holding personal data will have an incident. The variable is not whether but how expensive, and the cost is determined less by the attacker's sophistication than by three things the organization controlled in advance: whether the logs needed to scope the incident exist, whether counsel was engaged before the forensic firm, and whether anyone had ever read the notification statutes that would apply.
This toolkit is for general counsel, privacy officers, CISOs, and outside counsel. It assumes a US-centric organization with some multistate and possibly international exposure. It is written to be usable at 11 p.m. on a Friday, which is when these calls come.
Roadmap at a glance
- Before anything happens — plan, team, retainers, insurance, logging.
- Hour zero — detection, triage, and who gets called first.
- Containment and preservation.
- The privileged investigation.
- Scoping — what data, whose data, which jurisdictions.
- The notification decision — statute by statute.
- Notifying — individuals, regulators, agencies, and customers.
- Ransomware and the sanctions problem.
- Business email compromise and vendor incidents.
- Regulators and litigation.
- After — remediation, lessons, and the next tabletop.
Stage 1 — Before anything happens
The plan. A written incident response plan with roles by title, not by name; a call tree that works when corporate email is compromised; severity definitions; decision authority at each level; and a one-page quick-reference card. Store it offline. A plan that lives only on the network you just lost is not a plan.
The team. Name the incident commander, legal lead, technical lead, communications lead, and executive sponsor. Add outside counsel, a forensic firm, a notification vendor, a credit monitoring provider, and a public relations firm — all retained in advance, because negotiating an engagement letter during an incident wastes the hours that matter most.
Insurance. Read the cyber policy before you need it: what triggers coverage, the notice requirements and their deadlines, whether the carrier's panel counsel and panel forensics must be used, consent-to-incur requirements for expenses, sublimits for notification and regulatory defense, and any exclusion for unencrypted devices or for failure to maintain stated controls. Confirm the notice provision and the contact, and put both in the plan.
Logging. Confirm the logs that scoping will require actually exist and are retained long enough: authentication, VPN, endpoint, email access, file access, DNS, and cloud audit logs. An investigation that cannot determine what was accessed usually ends in notifying everyone, which is the most expensive outcome available.
Exercises. Run a tabletop at least annually, with the executives who will actually make the decisions in the room, and with a scenario that includes a hard call — a ransom demand, a regulator's inquiry, a reporter's email.
Illustration. A company discovers unauthorized access to a mailbox. Its email logs retain 30 days. The intrusion began 90 days earlier. Because it cannot show what was accessed, it must treat all 240,000 messages in the account as potentially exposed and notify accordingly. Extending log retention would have cost a few thousand dollars a year.
Resources
Stage 2 — Hour zero
Call outside counsel first, before the forensic firm. The sequence matters for privilege, and it costs nothing.
Then: convene the team; open a single incident log with timestamps and decisions; assign one person to record; and stop the informal Slack commentary immediately — every message is discoverable, and speculation in the first hour reads badly in a deposition two years later. Move incident communications to an out-of-band channel if the primary environment may be compromised.
Assess severity against the plan's definitions. Notify the executive sponsor and, for public companies, begin the materiality assessment immediately, because the SEC's rule requires disclosure on Item 1.05 of Form 8-K within four business days of determining that a cybersecurity incident is material — and the clock runs from the materiality determination, which cannot be unreasonably delayed.
Give the insurer notice now, in the manner the policy requires.
Stage 3 — Containment and preservation
Contain without destroying evidence. Isolate rather than rebuild; image before wiping; preserve memory before rebooting where feasible. Rotate credentials, revoke sessions and tokens, disable compromised accounts, and block attacker infrastructure.
Issue a litigation hold covering incident-related materials, the affected systems, logs, and the communications of the responders. Suspend routine deletion for anything in scope, including the log rotation that is about to overwrite the evidence you need.
Decide, deliberately, whether and when to involve law enforcement. The FBI and Secret Service can add capability and, in some cases, a delay-of-notification basis where a statute permits it; a law enforcement delay request must be documented.
Resources
Stage 4 — The privileged investigation
Structure the forensic work for privilege and understand its limits. Retain the forensic firm through counsel, under an engagement stating the purpose is to assist counsel in providing legal advice in anticipation of litigation. Keep the legal investigation separate from the operational remediation, ideally with different vendors or at least different work streams and separate reports.
Know the case law. In In re Capital One Consumer Data Security Breach Litigation, 2020 WL 2731238 (E.D. Va. May 26, 2020), a forensic report was held not protected where the same firm had performed the same work under a pre-existing business agreement and the report was distributed broadly. In re Rutter's Inc. Data Security Breach Litigation, 2021 WL 3733137 (M.D. Pa. July 22, 2021), reached a similar result. The lessons are consistent: a separate statement of work, a different scope than the ordinary-course engagement, payment from the legal budget, restricted distribution, and a report addressed to counsel.
Do not paper a privilege claim over an investigation the company would have run anyway. Courts look at the substance, and an overreaching privilege claim that fails is worse than a candid report handled carefully.
Resources
- Attorney-Client Privilege and Work Product for Businesses
- Internal Investigation and Upjohn Warning Checklist
Stage 5 — Scoping
Determine what happened (unauthorized access, acquisition, exfiltration, encryption, or misconfiguration), what data was involved, whose data it was, and where those people live.
The data-element question drives everything, because notification statutes are element-specific: name plus Social Security number, driver's license number, financial account number with access credential, medical information, health insurance information, biometric data, username-and-password combinations, and in some states passport numbers, tax identification numbers, and genetic data.
Build the notification list by jurisdiction of residence, not by where the company sits. A single incident routinely implicates forty or more state statutes plus sectoral rules.
Resources
- State Consumer Privacy Laws
- Data Minimization and Avoiding the Over-Retention of Personal Information
Stage 6 — The notification decision
For each jurisdiction and each regime, answer four questions: Is this a "breach" as defined? Does a risk-of-harm exception apply? What is the deadline? Who must be told?
- State statutes. All fifty states, plus the District of Columbia and the territories, have notification laws. Most require notice "in the most expedient time possible and without unreasonable delay," and a growing number impose an outer limit of 30, 45, or 60 days. Many require notice to the state attorney general, some at any size and others above a threshold. Most require notice to the three nationwide consumer reporting agencies above a threshold, commonly 1,000 residents. Content requirements differ, and several states mandate specific language or prohibit certain content.
- Encryption safe harbors. Most statutes exempt encrypted data — but only if the key was not also compromised. Confirm both facts before relying on it.
- Risk-of-harm exceptions. Many states permit no notice where the entity determines, after investigation, that harm is not reasonably likely. The determination usually must be documented and, in several states, submitted to the attorney general.
- HIPAA. For protected health information, the Breach Notification Rule, 45 C.F.R. §§ 164.400-414, presumes a breach unless a four-factor risk assessment shows a low probability of compromise. Individuals within 60 days; HHS within 60 days for breaches of 500 or more, annually otherwise; and media notice for 500 or more residents of a state.
- GLBA. The Safeguards Rule requires financial institutions to notify the FTC of unauthorized acquisition affecting 500 or more consumers, within 30 days of discovery.
- SEC. Public companies disclose material incidents on Form 8-K Item 1.05 within four business days of the materiality determination, and describe risk management and governance annually.
- GDPR. Notice to the supervisory authority within 72 hours of becoming aware, unless unlikely to result in risk; notice to data subjects without undue delay where high risk. Arts. 33-34.
- Contracts. Customer agreements and DPAs frequently impose shorter deadlines than any statute — 24 or 48 hours is common. Check them early; the contractual clock is usually the first to expire.
Stage 7 — Notifying
Write the individual notice to be understood: what happened, when, what information was involved, what the company is doing, what the person should do, and a real contact. Include the state-mandated elements for each recipient's state, which may require a hybrid template or state-specific versions. Avoid minimizing language — "we have no evidence of misuse" is accurate and acceptable; "there is nothing to worry about" is neither.
Decide on credit monitoring or identity protection, which some states require for certain data elements and which is otherwise a judgment call. Stand up a call center with a script and enough capacity, because a busy signal generates complaints to the attorney general.
Prepare regulator notices in each required form — several states require a specific online submission — and file them on time. Prepare media notice where required. Prepare customer and partner notice under contractual obligations, and coordinate the sequence so that no group learns from the press first.
Prepare for inbound: employees, customers, press, and plaintiffs' firms that monitor attorney general breach portals and file within days. Brief the frontline before the letters land.
Illustration. A company mails notices on a Friday and issues a press statement the same afternoon. Its 40-person support team receives 6,000 calls on Monday, its notice omitted the Massachusetts-required statement about security freezes, and a class action is filed Tuesday citing the press statement. Each of the three was foreseeable and preventable in the drafting week.
Stage 8 — Ransomware and the sanctions problem
Ransomware adds decisions the ordinary playbook does not cover.
Assess whether data was exfiltrated, not merely encrypted — an encryption-only event may or may not trigger notification depending on the state, while exfiltration almost always does. Modern actors exfiltrate first and publish later, so absence of evidence of exfiltration is not evidence of absence.
If payment is contemplated, run the sanctions analysis. OFAC has advised that facilitating a ransom payment to a sanctioned person or jurisdiction may violate US sanctions law, and liability is strict. Screen the actor and the wallet, engage counsel and a firm experienced in the analysis, document the diligence, and consider voluntary reporting to law enforcement, which OFAC treats as a mitigating factor.
Confirm the insurer's consent before paying; paying without it can void coverage. Confirm the decryptor works on a test set before relying on it. And recognize that payment does not resolve the notification obligations — a promise to delete stolen data is not evidence that it was deleted.
Resources
Stage 9 — Business email compromise and vendor incidents
Business email compromise is the most common incident by volume and the one most often mishandled, because it looks small. A single compromised mailbox can contain years of attachments with personal data of thousands of people. Scope the mailbox contents, not just the intrusion; determine whether forwarding rules exfiltrated mail; and check for fraudulent payment instructions, which raise a separate set of recovery steps — immediate bank notification, an FBI IC3 complaint, and a request for a financial fraud kill chain recall, all of which are time-critical within the first 72 hours.
Vendor incidents are your problem when the data is yours. Confirm your contractual rights: notification timing, cooperation, audit, indemnity, and who controls notification to affected individuals. Insist on facts rather than reassurance, and remember that under most state statutes the data owner, not the vendor, owes the notice. Under HIPAA, a business associate notifies the covered entity, and the covered entity notifies individuals.
Stage 10 — Regulators and litigation
Expect attorney general inquiries in the states with the most residents affected, and prepare a consistent factual narrative that matches every notice already sent. Expect FTC interest where security representations were made, under Section 5, and state UDAP claims on the same theory. Sector regulators — HHS OCR, state insurance and banking departments, and the SEC — bring their own processes.
Expect class litigation within days. The battleground is standing and damages: TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), requires concrete injury, and circuits differ on whether increased risk of identity theft suffices absent misuse. Common claims include negligence, breach of implied contract, state UDAP, and statutory claims under CCPA's private right of action for certain data elements, which provides statutory damages without proof of harm.
Preserve everything, coordinate the regulatory and civil narratives, and involve coverage counsel early on defense cost allocation.
Resources
Stage 11 — After
Complete remediation and verify it. Conduct a lessons-learned review that is honest enough to be useful and structured enough to be privileged where appropriate. Update the plan, the call tree, the retainers, and the log retention settings based on what actually failed.
Then close the loop on the things the incident exposed: data the company was holding and did not need, accounts that should have been disabled, a vendor whose contract lacked a notification clause, and the multifactor authentication gap that made the whole thing possible. The most valuable output of an incident is the list of things that will not be true next time.
Resources
- Data Subject Rights Request Handling Checklist
- Data Minimization and Avoiding the Over-Retention of Personal Information
Master resource index
Articles
- Developing a Privacy Compliance Program
- State Consumer Privacy Laws
- Data Minimization and Avoiding the Over-Retention of Personal Information
- Attorney-Client Privilege and Work Product for Businesses
- Business Insurance and Coverage Disputes
- Class Actions Under Rule 23
Checklists
- Privacy Compliance Program Checklist
- Litigation Hold and Evidence Preservation Checklist
- Internal Investigation and Upjohn Warning Checklist
- Data Subject Rights Request Handling Checklist
- Software License Agreement Review Checklist
Related toolkits
- Privacy and Data Protection Toolkit
- AI Governance Toolkit
- Insurance Coverage Toolkit
- Class Action Defense Toolkit
External and primary sources
- State breach notification statutes (all 50 states, D.C., and territories) and state attorney general reporting portals
- HIPAA Breach Notification Rule, 45 C.F.R. §§ 164.400-414; Security Rule, 45 C.F.R. pt. 164 subpt. C
- GLBA Safeguards Rule, 16 C.F.R. pt. 314; FTC Act § 5, 15 U.S.C. § 45
- SEC cybersecurity disclosure rules, Item 1.05 of Form 8-K and Item 106 of Regulation S-K
- GDPR arts. 32-34; Cal. Civ. Code § 1798.150
- OFAC advisories on potential sanctions risks for facilitating ransomware payments
- TransUnion LLC v. Ramirez, 594 U.S. 413 (2021); In re Capital One Consumer Data Security Breach Litigation, 2020 WL 2731238 (E.D. Va. May 26, 2020); In re Rutter's Inc. Data Security Breach Litigation, 2021 WL 3733137 (M.D. Pa. July 22, 2021)
This toolkit is educational and not legal advice. Notification obligations are jurisdiction-specific, deadline-driven, and change frequently. Engage qualified breach counsel at the start of an incident, not after.