08/07/2026
The first 24 hours after a suspected breach decide whether the next six months are manageable or catastrophic.
Most of the damage in those hours comes from actions that feel productive but cost you later. The order that works:
1.Stop. Don't touch infected machines or systems. The forensic evidence on them is what determines whether your insurer covers you and whether you can prosecute later.
2.Call your cyber insurance broker. They will assign you an incident response firm and a breach attorney, often within the hour. Both fees are usually covered by your policy.
3.Call your breach attorney before you call your IT person. The attorney creates legal privilege over everything that follows, which protects you if the incident ends up in court.
4.Let the incident response firm lead. They contain the attack, collect evidence, and advise on ransom decisions. Your job is to authorize the work, not perform it.
5.Notify law enforcement. FBI IC3 at ic3.gov, or your state's cyber unit. Required in some states, helpful in all of them.
6.Don't tell your team, customers, or social media anything until your attorney clears the message.
The first call you make matters more than every action that follows.