Summary. The first three days of a security incident set the terms for everything that follows. They determine whether the forensic investigation is privileged, whether the evidence needed to scope the incident still exists, whether the insurer will pay, and whether the notification clocks that run from discovery can be met. Most of these decisions must be made before anyone knows what happened, which is why they should be made in advance and written down. This guide runs the response hour by hour through the first seventy-two hours and the two weeks that follow, covering the sequencing of containment against preservation, the engagement structure that protects the forensic report, the ransom and law enforcement decisions, the scoping work that drives every notification obligation, and the communications that will be read by regulators and plaintiffs' counsel.
The defining feature of breach response is that the legal deadlines run from discovery, not from understanding. A company that learns something happened on Monday has, in several regimes, seventy-two hours to notify a regulator and thirty days to notify the FTC, and it will not know what was taken for weeks.
That mismatch is why the response is a sequence rather than an investigation. Each step has to be taken before the previous one is finished.
Hour zero to hour four
Activate, and get the right people in one room
The incident response team: security, IT, legal, communications, privacy, HR, and the business owner of the affected system. Designate one decision-maker. Response fails on diffusion of authority far more often than on technical capability.
Move the conversation off the potentially compromised network. If the intruder is in the email system, the incident response thread is being read. Use an out-of-band channel — a separate messaging platform, personal devices, or a conference bridge with a code word — established in advance.
Engage outside counsel before the forensic firm
This ordering is the single most consequential decision in the first hours, and it is routinely reversed.
Outside counsel retains the forensic firm, under an engagement letter stating that the work is at counsel's direction, for the purpose of providing legal advice, in anticipation of litigation. The forensic firm reports to counsel. The report is addressed to counsel and distributed narrowly.
The pattern that failed: In re Capital One Consumer Data Security Breach Litigation, 2020 WL 2731238 (E.D. Va. 2020), ordered production of a forensic report where the company had a pre-existing contract with the firm, the work substantially duplicated the firm's ordinary services, the cost was paid from the business budget, and the report was widely distributed. In re Rutter's Inc. Data Security Breach Litigation, 2021 WL 3733137 (M.D. Pa. 2021), reached the same result.
The structure that works: a new engagement letter for this incident, not a statement of work under an existing master agreement; two workstreams where possible, with one firm doing unprivileged business remediation and a separate firm doing the litigation-purpose investigation; payment from the legal budget; and severely restricted distribution.
And assume it may be produced anyway. Write nothing in it you would not want read aloud.
Tender to the insurer
Cyber policies carry short notice provisions and most require the insurer's consent to counsel and to the forensic vendor, frequently from a panel list. Engaging your own firm before tendering can forfeit coverage for those costs.
Tender within the first day. Notice is cheap; a coverage denial is not.
Preserve before you remediate
The instinct is to wipe and rebuild. Resist it long enough to preserve:
- Memory images of affected systems. Volatile data — running processes, network connections, injected code — is lost on reboot, and it is frequently the only way to determine what an attacker did.
- Disk images of affected hosts.
- Logs: firewall, VPN, authentication, endpoint, DNS, email, cloud provider, and application. Most organizations retain these for a limited period, and the retention window is often shorter than the intruder's dwell time. A company that discovers a six-month compromise with ninety days of logs cannot determine what happened — which affects the notification analysis directly and adversely.
- Suspend automatic deletion immediately: log rotation, backup expiry, email retention policies, chat message expiry, and device recycling.
Issue a litigation hold.
Where containment requires action that destroys evidence — isolating a host, resetting credentials, restoring from backup — image first where time permits, and document the decision and its reasons where it does not. An investigator asked later why the evidence is gone needs a contemporaneous answer.
Contain
Isolate affected systems from the network without powering them down where possible. Reset credentials, starting with privileged accounts and any account the attacker touched. Revoke tokens and sessions. Disable external access paths — VPN, remote desktop, third-party connections.
Watch for the attacker reacting to containment. Partial containment frequently triggers destruction.
Hour four to hour twenty-four
Begin scoping
Every notification obligation depends on what data was accessed or acquired, and whose. That question drives everything and it is answered slowly.
The scoping questions: what systems were reached, what data those systems hold, whether there is evidence of exfiltration as opposed to access, and how many individuals are affected and in which jurisdictions.
Access versus acquisition matters legally. Many state statutes trigger on acquisition; some trigger on access, which is broader. Where the forensic evidence shows an intruder in a system but no evidence of data movement, the analysis differs by state.
Decide about law enforcement
FBI and Secret Service involvement can produce intelligence, may support a delay in notification where a statute permits it for law enforcement purposes, and is viewed favorably by regulators. It also means loss of control over timing and the possibility of equipment seizure.
For ransomware, contact is strongly recommended, and CISA and the FBI maintain reporting channels.
The ransom decision, if it is ransomware
Not straightforwardly illegal, but OFAC's advisory makes clear that a payment to a sanctioned person or jurisdiction violates the sanctions regulations on a strict liability basis, and that the company, its counsel, its insurer, and its incident response vendor may all face exposure.
Requirements before any payment: documented sanctions diligence on the threat actor by a vendor that does this work, and a record of the analysis. Most negotiation firms and insurers require it.
The other considerations: whether backups permit recovery; whether the decryptor works, which it frequently does poorly; whether payment prevents publication of exfiltrated data, which it frequently does not; and whether payment marks the company as a repeat target.
Payment does not affect the notification obligation. Data that was exfiltrated was acquired, and a promise to delete it is worth nothing.
CIRCIA requires covered critical infrastructure entities to report a ransom payment to CISA within twenty-four hours — confirm the current effective date and covered-entity definition of the implementing rule before assuming the obligation applies.
Hour twenty-four to hour seventy-two
The short-clock notifications
Identify, immediately, which of these apply — because the controlling deadline is the shortest one that attaches, and it may be seventy-two hours rather than the thirty or sixty days the state statutes allow.
- GDPR Article 33: notification to the supervisory authority within seventy-two hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. Where the full facts are unknown, notify within the deadline and supplement.
- NYDFS, 23 N.Y.C.R.R. § 500.17: seventy-two hours for a covered entity.
- Banking agencies, 12 C.F.R. Parts 53, 225, and 304: thirty-six hours to notify the primary federal regulator of a notification incident.
- State insurance data security laws following the NAIC model: seventy-two hours to the commissioner.
- DFARS 252.204-7012: seventy-two hours to the Department of Defense for a covered contractor.
- CIRCIA: seventy-two hours to CISA for a substantial cyber incident by a covered entity, subject to the implementing rule's effective date.
- FTC Safeguards Rule, 16 C.F.R. § 314.4(j): thirty days where unencrypted customer information of five hundred or more consumers is involved.
Assign an owner to each applicable clock on day one, with the deadline computed and calendared.
The materiality determination for public companies
Form 8-K Item 1.05 requires disclosure of a material cybersecurity incident within four business days of determining materiality — not of discovery. The determination must be made without unreasonable delay.
Two points that regulators focus on: the timing of the determination, and whether the process was documented. A company that discovers an incident on day one and determines materiality on day forty will be asked why. Document the assessment and its basis contemporaneously, including where the conclusion is that the incident is not material.
A limited delay is available where the Attorney General determines that disclosure poses a substantial risk to national security or public safety.
Begin the notification analysis
Run the affected data elements against each jurisdiction's covered-information definition and trigger. This is where a pre-built fifty-state matrix pays for itself; building one during an incident consumes the week.
For each state: the covered data elements, acquisition versus access, whether a risk-of-harm assessment is permitted, the outer deadline, required content, attorney general notification thresholds, consumer reporting agency thresholds, and credit monitoring mandates.
For each federal or sectoral regime that applies: HIPAA's four-factor presumption at 45 C.F.R. § 164.402 and the sixty-day individual notification requirement; GLBA; the SEC; and any contractual notification obligations to customers, which are frequently shorter than any statute.
Communications
Prepare a holding statement before it is needed. Something will leak, a customer will ask, or a reporter will call.
Say what is known, what is being done, and where to find updates. Do not say "no information was misused" or "no evidence of harm" unless it is true and will remain true — a statement that later proves wrong converts a security failure into a misrepresentation, which is the FTC's preferred theory and a much worse claim.
Prepare internal talking points as well. Employees will be asked and will answer, and an employee's speculation becomes the company's statement.
Coordinate: customers, employees, regulators, the board, insurers, auditors, lenders under any covenant requiring notice, and material contract counterparties.
Report to the board
Early, factually, and in writing. Boards now face oversight exposure for cybersecurity as a Caremark risk, and SEC disclosure requirements make board oversight a public matter. A record of prompt, substantive board engagement is both good governance and the defense to the derivative suit.
Days four through fourteen
Complete the scoping. For a compromised mailbox, this frequently means a data mining review of the mailbox contents by a specialist vendor, extracting covered data elements and mapping them to individuals. It is expensive, slow, and usually unavoidable, because "we cannot determine what was in the mailbox" is not a defensible basis for declining to notify.
Build the notification list, deduplicated, with addresses, and run against the National Change of Address database.
Engage the notification and call center vendor. Print and mail capacity, a website posting, and a staffed call center with a reviewed script — because a representative who improvises is making statements on behalf of the company.
Draft the notice. Say what happened plainly. Include the superset of state-required content with state-specific addenda where mandated. Offer credit monitoring and identity restoration where Social Security numbers or financial account information were involved, and where it is customary regardless. Give people something concrete to do.
Coordinate the timing so individual notices, regulator notices, the consumer reporting agency notice, any 8-K, the website posting, and the press statement land together. A regulator who reads about the breach in the press before receiving notice remembers it.
Remediate. Patch the vulnerability, rotate credentials, deploy multi-factor authentication where it was missing, segment the network, and improve logging. Regulators and plaintiffs both ask what changed, and "nothing yet" is the worst available answer.
Preserve the record of the response itself. The timeline of what was learned when and what was done in response is the document that demonstrates reasonableness, and it should be maintained contemporaneously rather than reconstructed.
The decisions that cannot be made in the moment
Each of these should be resolved in advance, in writing, because there is no time to resolve them during an incident.
Who decides. Name the person, and the alternate. Not a committee.
Who may authorize a ransom payment, and up to what amount. A board resolution delegating authority within a cap, with a required sanctions diligence step, prevents a three-day argument during a live extortion.
Which forensic firm, retained how. Pre-negotiated, on the insurer's panel, with an engagement letter template ready.
Which outside counsel, likewise, with contact information that is current and reachable at 2 a.m.
Whether to contact law enforcement, and who makes the call.
The out-of-band communication channel, established and tested.
The fifty-state notification matrix, current and reviewed annually.
The data map. What personal information the company holds, where it lives, which systems process it, who has access, and what the retention period is. A company that cannot answer these in an incident spends two weeks answering them under pressure, and every day of that delay is visible to regulators. The corollary is that data minimization is the most effective breach mitigation available — information deleted on schedule cannot be exfiltrated.
The incident response plan itself, with roles rather than names, contact information that is current, and a copy that exists outside the network — printed, or in a system the incident cannot reach.
Tabletop exercises, annually, with the executive team present. The purpose is not to test the technology. It is to discover that nobody knows who decides about the ransom, that the general counsel's mobile number is three years old, and that the communications lead assumed legal would draft the notice.
Common failures
Remediating before preserving. The evidence needed to scope the incident, and therefore to determine who must be notified, is destroyed in the first hours by an IT team doing exactly what it was trained to do.
Engaging the forensic firm directly. Privilege lost at hour one.
Discussing the incident on the compromised system. The attacker reads the response plan.
Missing the short clock. A company focused on the thirty-day state deadlines while a seventy-two-hour regulator obligation runs.
Over-stating in the notice. "No information was misused" before anyone could know.
Waiting for certainty. Deadlines run from discovery. Notify on what is known, and supplement.
Ignoring the vendor. Where the incident originated with a service provider, the company's own clock runs from its discovery, and "our vendor has not finished investigating" is not a recognized excuse.
No board reporting. The derivative complaint writes itself.
Failing to fix the finding that was already documented. The most damaging document in breach litigation is an internal assessment identifying the exact weakness that was exploited, dated before the incident, with no record of remediation.
Primary authority
- State breach notification statutes in all fifty states, the District of Columbia, and the territories — differing in covered data elements, acquisition versus access triggers, risk-of-harm exceptions, outer deadlines, required content, regulator notification, and credit monitoring mandates.
- GDPR Articles 33 and 34 — seventy-two-hour supervisory authority notification and data subject notification.
- 23 N.Y.C.R.R. Part 500, including § 500.17 — NYDFS seventy-two-hour notification; NAIC Insurance Data Security Model Law as adopted by state.
- 12 C.F.R. Parts 53, 225, and 304 — the banking agencies' thirty-six-hour computer-security incident notification rule.
- 16 C.F.R. Part 314, including § 314.4(j) — the FTC Safeguards Rule and the thirty-day FTC notification.
- 45 C.F.R. §§ 164.400–164.414 — the HIPAA Breach Notification Rule and the four-factor risk assessment.
- 17 C.F.R. § 229.106 and Form 8-K Item 1.05 — SEC cybersecurity disclosure and the materiality determination.
- 6 U.S.C. §§ 681–681g (CIRCIA) — CISA reporting, including the twenty-four-hour ransom payment report, subject to the implementing rule.
- DFARS 252.204-7012 and NIST SP 800-171 — defense contractor reporting and safeguarding.
- OFAC, Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments; 31 C.F.R. Chapter V.
- Fed. R. Civ. P. 26(b)(3) and Fed. R. Evid. 502(d) — work product and non-waiver orders.
- In re Capital One Consumer Data Security Breach Litigation, 2020 WL 2731238 (E.D. Va. 2020) and In re Rutter's Inc. Data Security Breach Litigation, 2021 WL 3733137 (M.D. Pa. 2021) — privilege over forensic reports.
- 15 U.S.C. § 45 — the FTC Act unfairness and deception authority underlying most federal data security enforcement.
A worked seventy-two hours
Tuesday, 6:15 a.m. The security operations vendor pages the CISO: anomalous authentication from an unfamiliar ASN, followed by creation of a privileged account, on a server hosting a customer database.
6:40 a.m. CISO calls the general counsel, who calls outside breach counsel from a personal mobile. The incident channel is established on a platform separate from corporate email, because the intrusion path is not yet known.
7:30 a.m. Counsel engages a forensic firm from the cyber insurer's panel, under a new engagement letter naming counsel as the client and stating the litigation purpose. Billing is coded to legal.
8:00 a.m. Tender to the insurer. Broker notified. Consent to counsel and vendor confirmed.
8:15 a.m. Instruction to IT: do not reboot, do not reimage, do not restore. Isolate the host at the network layer, leave it powered on. Preserve memory before anything else. Suspend log rotation, backup expiry, and mailbox retention policies. Confirm in writing from the infrastructure lead.
10:00 a.m. Litigation hold issued. Privileged accounts rotated. External remote access disabled pending review.
Tuesday afternoon. Log inventory: the firewall keeps ninety days, endpoint telemetry thirty days, authentication logs one year. The dwell time is unknown and the thirty-day endpoint window may not cover it. This limitation is documented now, because it will shape what can ever be concluded.
Wednesday. Forensics confirms initial access through a vendor-managed jump host with a credential that had no multi-factor authentication, twenty-three days earlier. Evidence of database queries; evidence of a compressed archive staged and transferred out.
Wednesday afternoon. The short-clock inventory is run. The company holds a NYDFS license: seventy-two hours from a determination that a cybersecurity event occurred. EU customers exist: GDPR seventy-two hours. Neither deadline waits for scoping. Both notifications are prepared on what is known, expressly stating that the investigation continues and that supplemental information will follow.
Thursday morning. The SEC materiality assessment convenes: the affected database, the customer count, the anticipated cost, and the reputational and contractual exposure. The conclusion and its basis are documented contemporaneously, with the date and the participants.
Thursday. Regulator notifications filed within the seventy-two-hour windows. Holding statement approved and held. Board briefed in writing. Key customers with contractual notice obligations — several shorter than any statute — identified and notified.
By day ten, the exfiltrated archive is characterized: 118,000 individuals, names and email addresses, and for 9,400 of them driver's license numbers. The fifty-state analysis runs against those elements, notification vendors are engaged, and the notice is drafted.
Nothing about the first three days depended on knowing the answer. Everything depended on preserving the ability to find it and on meeting deadlines that ran regardless.
Containment without destroying the case
The tension between stopping the intrusion and preserving the evidence is real, and the resolution is sequencing rather than choosing.
Preserve first where it costs minutes, contain first where it costs hours. Memory capture on a host takes ten to thirty minutes. Isolating that host at the network layer while the capture runs stops the attacker's lateral movement without losing volatile data. Powering it down loses everything in memory and is almost never necessary.
Network isolation beats shutdown. Disable the switch port, apply an access control list, or move the host to a quarantine VLAN. The system stays running, the attacker loses access, and the evidence survives.
Credential rotation is urgent and disruptive. Rotating privileged credentials, service accounts, and any credential the attacker touched is essential — and it will break integrations, lock out legitimate users, and generate help desk volume. Sequence it: privileged and administrative accounts first, then service accounts with a rollback plan, then the general population.
Watch for retaliation. Attackers monitor the response and frequently accelerate destruction or encryption when they detect containment. Where the intrusion is active and destruction is a risk, containment may have to be simultaneous and comprehensive rather than staged — a judgment call that belongs to the incident commander with forensic input.
Do not restore from backup until the entry vector is closed. Restoring a system into an environment where the attacker retains access reinfects it, and the second incident is worse because the response is now on record as having failed.
Preserve the backups themselves. They are evidence of what the data looked like before, and in a ransomware case they are the recovery path. Take them offline immediately; attackers target backup infrastructure specifically.
Document every containment action — what was done, when, by whom, and why. The timeline is the artifact regulators and plaintiffs examine, and reconstructing it from memory three months later produces a record that looks worse than the response actually was.
Where evidence must be sacrificed, say so contemporaneously in writing: the business need, the alternative considered, and who decided. An investigator asked why a system was reimaged on day two needs an answer that was written on day two.
The people problem
Incident response is described technically and experienced humanly, and the human failures are as costly as the technical ones.
The team will be exhausted by day four. Twenty-hour days produce errors, and the errors compound. Build shifts from the start, even when it feels premature — an incident commander who works seventy-two hours straight makes the decision that becomes the case study.
Someone will be blamed. Frequently the person who clicked the link, or the administrator who did not enable multi-factor authentication on the jump host. Resist it during the response: a team afraid of blame stops volunteering information, and the information they stop volunteering is what scopes the incident. Separate the after-action review from the response.
The employee whose credentials were used is a witness, not a suspect — usually. Where the facts suggest insider involvement, the analysis changes entirely: the person should not be part of the response team, HR and counsel should be involved before any interview, and the interview should be conducted with an Upjohn warning.
Employees are affected too. In many incidents the compromised data includes the workforce's own information — Social Security numbers on payroll systems, health information in benefits files. Employees learn from the news, or from a notice sent to their home, that their own data was taken while they were working the response. Tell them first, and offer them the same protections offered to customers.
Executives will ask for certainty that does not exist. The honest answers on day two are "we do not know yet" and "here is what we are doing to find out." A team that manufactures confidence to satisfy an anxious executive produces statements that end up in an 8-K.
The communications team needs the truth, including the parts that are unflattering. A spokesperson who learns from a reporter that the vulnerability had been flagged internally will not recover.
Customers respond to competence and candor, not to reassurance. The companies that emerge with their relationships intact are the ones that said what happened, what they were doing, and what they did not yet know — and then did what they said.
Schedule the after-action review for two to four weeks after closure, conducted under privilege, focused on what to change rather than on who erred. Its output — the findings, the remediation plan, and the tracking to closure — is both the improvement and the evidence of reasonableness.
Variations by incident type
The seventy-two-hour framework is general. Four common incident types have their own first moves.
Ransomware. Isolate aggressively, because encryption spreads. Take backups offline immediately — attackers target backup infrastructure first. Engage a negotiation specialist and begin sanctions diligence in parallel with recovery assessment, because the decision window is short and the diligence takes days. Assume exfiltration occurred even if the extortion note does not mention it; double extortion is now standard, and the notification analysis proceeds regardless of whether the ransom is paid. Report the payment to CISA within twenty-four hours where CIRCIA applies.
Business email compromise. The mailbox is the incident. Preserve the mailbox and the audit logs before anything else, because message-level audit retention is short and frequently disabled by default. Check for forwarding rules and delegate permissions the attacker created, which persist after a password reset. Report wire fraud to the FBI's Internet Crime Complaint Center immediately — the Financial Fraud Kill Chain can sometimes recover funds transferred within seventy-two hours. Then the hard part: a mailbox review to determine what covered data the messages contained.
Insider exfiltration. A departing employee taking data. Preserve the endpoint, the email, and the cloud storage logs before the person's account is disabled, because disabling it can truncate the evidence. Involve HR and employment counsel before any interview. Consider a temporary restraining order and expedited discovery, and evaluate the Defend Trade Secrets Act claim and the Computer Fraud and Abuse Act analysis after Van Buren.
Vendor breach. The company's clock runs from its own discovery, not the vendor's. Escalate to the vendor's executives in writing, assert the notification deadline as a legal obligation, and request the specific data elements and affected-individual list — which is what the notice requires. Preserve every communication. Begin the notification analysis on the facts available, because the deadline does not wait for the vendor's investigation.
Across all four, the same three actions come first: get counsel engaged before the forensic firm, preserve before remediating, and identify the shortest applicable clock. Everything else is variation.
Insurance, in more detail
Cyber coverage is where the response is funded, and the provisions that matter are ones nobody reads until they need them.
Notice provisions are short and are enforced. Most policies require notice "as soon as practicable" and many specify a period. Claims-made policies require the claim to be made and reported within the policy period or an extended reporting period. Tender on day one, even when it is unclear whether the incident will exceed the retention.
Panel requirements. Most policies require the insurer's consent to counsel, forensic vendors, notification vendors, and public relations firms, frequently from a published panel. Engaging off-panel without consent can forfeit coverage for those costs. Where the company has a strong preference, negotiate the panel at renewal, not during an incident.
What is typically covered: forensic investigation, legal services, notification costs, call center, credit monitoring and identity restoration, public relations, regulatory defense and — where insurable by law — fines and penalties, business interruption and dependent business interruption, data restoration, and cyber extortion including ransom payments.
Sublimits are where the coverage disappears. A ten-million-dollar policy may carry a two-hundred-fifty-thousand-dollar sublimit for regulatory defense, a one-million-dollar sublimit for extortion, and a waiting period of eight or twelve hours before business interruption attaches. Read the schedule, not the headline limit.
Common exclusions: war and hostile act exclusions, which insurers have narrowed and expanded repeatedly following state-sponsored attacks; failure to maintain minimum security standards, where the application's representations become conditions; prior known circumstances; and contractual liability.
The application is a warranty in substance. A representation that the company requires multi-factor authentication on all remote access, made on the application and untrue in fact, is the fact pattern insurers use to deny. Confirm what was represented before renewal and confirm it is true.
Business interruption proof requires financial records the company must assemble — revenue baseline, actual loss, extra expense, and mitigation. Start collecting on day one; reconstructing it later is where recoveries are lost.
Coordinate counsel roles. Breach counsel, coverage counsel, and defense counsel for the litigation that follows may be three different firms, and the insurer selects some of them. Where a conflict exists, independent counsel may be available depending on the state.
Related articles
- Data Breach Response and Notification: The Fifty-State Patchwork, Regulators, and Litigation — the substantive notification analysis and the litigation that follows.
- Building a Vendor and Third-Party Risk Management Program — the contracts that govern a vendor breach.
- HIPAA Privacy and Security Compliance for Covered Entities and Business Associates — the healthcare regime and its sixty-day clock.
- State Consumer Privacy Laws: The CCPA, the CPRA, and the Multi-State Patchwork — the substantive obligations underneath.
- Cybersecurity Incident Response and IP Protection: Preventing Trade Secret Loss During Data Breaches — the trade secret dimension.
- Attorney-Client Privilege and Work Product for Businesses: Upjohn, In-House Counsel, and the Common Interest Doctrine — structuring the forensic engagement.
- Business Insurance and Coverage Disputes: CGL, E&O, Cyber, and D&O — what the cyber policy pays for and the panel requirements.
- Data Minimization and Avoiding the Over-Retention of Personal Information — the mitigation that works before anything happens.
- Preparing a Business Continuity and Crisis Management Plan — the broader plan this sits inside.
- Fiduciary Duties of Directors and Officers: The Business Judgment Rule, Loyalty, and Caremark Oversight — board oversight and the derivative claim.
This guide is provided for general informational purposes and does not constitute legal advice. Breach notification deadlines run from discovery, are short, and differ by jurisdiction and sector; several federal and state regimes impose seventy-two-hour or thirty-six-hour regulator notification. CIRCIA's implementing rule has a shifting effective date. Engage outside counsel before retaining a forensic firm, and consult qualified counsel in every jurisdiction where affected individuals reside before issuing any notice.