What to Do in the First 24 Hours After a Data Breach
Written By
Sarwat Iftikhar
The first 24 hours after a data breach determine more about the outcome than any other period in the incident response lifecycle. Decisions made in this window, specifically how quickly systems are isolated, how accurately the scope is assessed, and how early the right people are notified, directly determine breach cost, regulatory exposure, and the speed of recovery.
The global average cost of a data breach reached $4.44 million in 2025. Organizations that contained their breaches in under 200 days paid an average of $3.87 million. Those that took longer paid $5.01 million, a 24% premium for every additional day the incident ran unaddressed. That gap does not close on its own. It is closed by disciplined, fast action in exactly the window this guide covers.
This post is a practical, sequential playbook. It covers what to do first, who to call, what your legal obligations are, and the most common mistakes that turn a containable incident into a prolonged disaster.
Key Takeaways
- The first two hours are about containment, not investigation. Stopping ongoing damage takes priority over understanding how the breach happened.
- Breaches contained within 200 days cost $1.14 million less than those that run longer, making every hour of response speed directly measurable in financial terms.
- GDPR requires notifying your supervisory authority within 72 hours. NIS2 requires a 24-hour early warning. CIRCIA mandates reporting to CISA within 72 hours for critical infrastructure, and 24 hours for ransomware payments.
- Internal detection saves roughly $900,000 compared to learning about a breach from an attacker or third party.
- Organizations with a tested incident response plan contain breaches significantly faster than those improvising under pressure.
Why Do the First 24 Hours Matter So Much After a Data Breach?
The first 24 hours matter because every hour of uncontrolled attacker access is an hour of additional data exfiltration, lateral movement, and evidence destruction. The average breach takes 181 days to identify and 60 additional days to contain, a total lifecycle of 241 days. Organizations that compress that window dramatically reduce both the cost and the regulatory exposure they face.
The 24-hour window is also when the most consequential decisions happen: which systems to isolate and in what order, who inside the organization is notified and when, whether law enforcement is engaged, and whether external forensic support is needed. These decisions are harder to make under pressure without a documented plan, and easier to make correctly when they have been thought through before an incident forces them.
The economics are stark. Organizations with a tested incident response plan and dedicated response team identified and contained breaches faster than those without one. Internal detection of a breach, where the organization finds it rather than learning from an attacker or a third party, saves roughly $900,000 in average breach costs. That saving comes directly from the speed advantage of knowing something happened before it is fully out of control.
The 24 hours covered in this guide break into four phases: immediate containment in the first two hours, internal notification and initial assessment in hours two to six, legal and regulatory review in hours six to twelve, and external communications and recovery planning in hours twelve to twenty-four.
What Should You Do in the First Two Hours?
The first two hours after discovering a potential breach are entirely about containment. The priority is stopping ongoing damage before conducting any investigation. This order of operations is counterintuitive to many teams, who want to understand what happened before acting. Still, an investigation conducted on a still-compromised environment is both slower and less reliable than an investigation conducted after containment.
The specific actions to take in the first two hours:
Isolate affected systems immediately. Any system confirmed or suspected to be compromised should be isolated from the network. This means removing network access, not just deactivating user accounts. The goal is to stop an attacker who still has active access from moving further. Isolation decisions should be made quickly even without complete information, because partial containment in the first hour beats complete understanding two hours later.
Revoke and rotate compromised credentials. If the breach involved credential theft, phishing, or any access via legitimate accounts, those credentials need to be revoked immediately across every connected system. Credentials compromised in 53% of all breaches are the attacker’s most durable foothold. A credential that persists after initial containment is an open door that survives the rest of your response.
Preserve evidence before remediation. Before systems are wiped, reimaged, or restored, forensic images and logs need to be captured. Evidence lost in the early hours of a response cannot be recovered. Logs showing attacker activity, files accessed, and lateral movement paths are the foundation of both the investigation and the regulatory documentation that follows.
Block identified attack pathways. If the initial access vector is identified, whether a phishing link, an exploited vulnerability, a misconfigured API, or an exposed credential, blocking that pathway takes priority alongside system isolation. An active attack using an identified vector should be cut off before the investigation expands.
Start a documented timeline. From the moment of discovery, every action taken should be timestamped and recorded. This documentation serves both the internal investigation and the regulatory notifications that may be required within 72 hours of discovery. An undocumented response is nearly impossible to reconstruct accurately.
Who Needs to Be Notified in Hours Two to Six?
In hours two to six, the priority shifts from technical containment to internal notification. The right people need to know what happened quickly enough to make decisions, but with enough verified information that those decisions are sound. Notifying too broadly or too early without verified facts creates confusion. Notifying too slowly delays decisions that have real cost consequences.
The internal notification sequence that matters most:
Your incident response team or equivalent. If your organization has a documented incident response plan, the IR team is activated at this point. If it does not, this is when an ad-hoc response group is assembled. This group should include whoever owns the technical response, legal counsel, the most senior security decision-maker available, and communications ownership.
Legal counsel. Legal needs to be in the room from this point forward, not brought in after decisions are already made. Regulatory notification deadlines begin running from the time the organization knew or should have known about the breach, not from when legal is eventually briefed. Getting legal involved early shapes every subsequent decision in a way that reduces regulatory exposure rather than creating it.
Senior leadership. The CEO, CFO, and Board-level security contacts need to be briefed on what is known at this point, including confirmed facts, suspected scope, and what is still unknown. Leadership cannot make resourcing and communication decisions without this briefing, and delayed leadership notification is consistently cited as a factor that extends breach response timelines.
External forensic support, if needed. Most organizations do not have the internal capability to conduct a thorough forensic investigation under incident conditions while simultaneously managing containment and notifications. Engaging an external forensic partner or security firm early, before the investigation is underway, produces better results than calling for support after the internal team has already been working in the environment without forensic discipline.
What Are Your Legal Notification Deadlines After a Breach?
Legal notification deadlines begin running from the moment of discovery, and in 2026 those deadlines are shorter, more specific, and more consequential than they were five years ago. Missing a regulatory notification window is not a minor procedural failure. It is a separate regulatory violation that stacks on top of the breach itself.
GDPR requires notification to the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals’ rights and freedoms. Where that risk is high, affected individuals must also be notified without undue delay. The 72-hour clock runs from awareness, not from the completion of any investigation.
NIS2, in force across EU member states since October 2024, requires an initial early warning to the national CSIRT or competent authority within 24 hours of becoming aware of a significant incident. A full report with a detailed assessment must follow within 72 hours, and a final report is expected within one month. NIS2 applies to a broader set of organizations than its predecessor, covering essential entities across critical sectors including healthcare, energy, transport, and digital infrastructure.
HIPAA requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured protected health information. If the breach affects 500 or more residents of a state or jurisdiction, prominent media notice in that state is also required within 60 days. HHS must be notified, with breaches affecting 500 or more individuals reported without unreasonable delay and all others reportable in the annual log submission.
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) requires covered critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and to report ransomware payments within 24 hours of payment. This obligation applies to a wide range of sectors including water, energy, healthcare, financial services, transportation, and communications.
SEC requirements mandate that public companies disclose material cybersecurity incidents in an 8-K filing within four business days of determining the incident is material. Materiality assessment is now expected to happen quickly, not after months of investigation.
US state laws create an additional layer of notification obligation. All 50 states plus DC, Puerto Rico, and the US Virgin Islands maintain independent breach notification requirements with varying deadlines, definitions of personal information, and exemptions. Most require notification within 30 to 60 days. Your legal counsel needs to map which state laws apply based on where affected individuals reside.
Breach notification costs averaged $390,000 in the most recent measurement period. Late or incomplete notification triggers additional regulatory fines and litigation that can multiply that figure significantly.
How Do You Assess the Full Scope of What Was Compromised?
Scoping the breach accurately in hours six to twelve requires forensic discipline rather than guesswork. The initial containment phase establishes what you think happened. The assessment phase establishes what actually happened: which systems were accessed, what data was exfiltrated, when the attacker first gained access, and whether any backdoors or persistent access mechanisms were installed.
The key assessment activities for this phase:
Review authentication and access logs. Every system in the suspected scope needs its authentication logs reviewed for anomalous access patterns: logins from unexpected geographic locations, unusual hours, service accounts accessing resources they do not typically touch, or access from credentials that should not have been active. These patterns establish the timeline and the lateral movement path.
Identify data exposure. The core question regulators and affected individuals will ask is what data was accessed or exfiltrated. Answering this requires mapping what data each compromised system contained, what queries or file accesses were performed during the attacker’s presence, and what, if anything, left the environment. Data loss prevention logs, database query logs, and network egress monitoring are the primary evidence sources for this question.
Search for persistence mechanisms. Experienced attackers install backdoors, create new accounts, modify scheduled tasks, or plant additional access mechanisms before detection. A containment action that closes the original access vector while leaving a persistence mechanism in place is not complete containment. The assessment phase should specifically look for indicators of persistence, not just for the original compromise.
Establish the initial access timeline. The date of the breach report is almost never the date of the initial compromise. The average time from initial compromise to discovery is 181 days in recent industry data. Establishing the actual initial access date matters for both the regulatory notification (some jurisdictions require disclosure of when the breach began) and for understanding what data was potentially accessible during the entire dwell period.
Bring in external forensic expertise if needed. An internal team conducting this assessment while simultaneously managing containment, communications, and leadership briefings is operating under conditions that reduce both speed and accuracy. External forensic support, engaged early, produces more complete assessments in less time than internal teams typically can achieve under incident conditions.
What Communications Do You Need to Send in the First 24 Hours?
External communications in the first 24 hours should be limited to what is required by law, what is strategically necessary, and what has been reviewed by legal counsel. The most common communication mistake in this window is saying too much too soon, making statements that need to be walked back as the investigation reveals more complete information.
What to communicate in the first 24 hours:
If you are under NIS2 and 24 hours have elapsed since discovery of a significant incident, the early warning to your national CSIRT is required. This early warning is intentionally brief: it acknowledges the incident, notes whether it appears to be malicious, and describes the initial impact assessment. It does not require a complete picture.
Law enforcement engagement, where relevant, should happen early. Law enforcement notification preserves the option to pursue criminal investigation and may provide resources and intelligence not otherwise available. Some regulatory frameworks specifically reference law enforcement notification as a relevant factor in assessing the organization’s response.
Key business partners, suppliers, or customers who may be affected by your containment actions, for example, if you have had to take down APIs or systems that they depend on, should receive operational communications that do not characterize the breach itself before the investigation is sufficiently advanced.
What to defer past 24 hours:
Public disclosure, media statements, and broad customer notification should generally wait until the scope is accurately established, legal has reviewed the content, and any required regulatory notifications have been filed. Making a public statement before the investigation is substantially complete creates statements of record that may turn out to be inaccurate, complicating both regulatory interactions and any subsequent litigation.
What Are the Most Common Mistakes Organizations Make in Breach Response?
The most common breach response mistakes share a pattern: they either rush actions that should be methodical (like public communications before scope is established) or delay actions that should be immediate (like containment and legal notification). Both errors extend the breach lifecycle and increase total cost.
Remediating before preserving evidence. The instinct to fix the problem immediately is understandable. Wiping and reimaging a compromised server feels like solving the problem. It does destroy the forensic record of how the attacker got in, what they did, and what they accessed. Forensic preservation should happen before any remediation action, even if it slightly delays recovery.
Not resetting all potentially compromised credentials. The credential that was directly used in a breach is not necessarily the only credential at risk. In a breach involving phishing, credential theft, or insider access, all credentials belonging to potentially affected users, and all credentials that were accessible within compromised systems, should be evaluated for reset. A partial credential reset that leaves attacker-controlled accounts active extends the compromise.
Communicating publicly before legal review. Public statements made in the heat of an incident often contain inaccuracies that become problematic when the full investigation is complete. Statements like “no financial data was accessed” that are later proven wrong in court or in regulatory proceedings create significant additional liability. Every external communication should be reviewed by legal before it goes out.
Not involving legal early enough. Legal counsel’s role in a breach response is not to draft the eventual notification letter. It is to shape every decision from the first hours onward in a way that manages regulatory exposure, preserves privilege over the investigation, and positions the organization correctly for any regulatory inquiry or litigation that follows—legal needs to be in the room from hour two, not hour forty-eight.
Underestimating the initial scope. Initial assessments almost always underestimate the scope of a breach. Systems that appeared isolated frequently turn out to have been accessible from the compromised environment. Data that appeared not to have been exfiltrated sometimes shows evidence of exfiltration once the investigation progresses. Communications and regulatory notifications should be calibrated to what is known with reasonable confidence, not to the most optimistic interpretation of incomplete evidence.
What Happens After the First 24 Hours?
The first 24 hours establish containment and initiate the formal response. What happens next is a structured recovery process that spans days to weeks, depending on the scope and complexity of the incident. The decisions made in the first 24 hours determine how difficult or straightforward that recovery process is.
The immediate priorities after the 24-hour window:
Complete the forensic investigation. The initial assessment in hours six to twelve establishes the preliminary scope. A complete forensic investigation, typically conducted by external specialists, produces the detailed incident report that regulatory submissions, insurance claims, and litigation may require. This investigation should be treated as a formal documentation process, not just an internal technical review.
Begin structured remediation. Once forensic preservation is complete and the initial scope is established, remediation can proceed systematically. This includes patching the vulnerabilities or configuration gaps that enabled the breach, removing any persistence mechanisms the attacker installed, and validating that the environment is clean before bringing isolated systems back online.
Fulfill all applicable notification obligations. With accurate scope information from the forensic investigation and legal review completed, the formal regulatory notifications and, where required, individual notifications can be executed. These should follow pre-approved templates where possible to ensure accuracy and consistency.
Conduct a post-breach security assessment. Once the immediate crisis is contained, the security controls that failed need to be formally evaluated. This means understanding not just how the attacker got in, but which controls should have detected or prevented the breach and did not. A post-breach penetration test or security assessment provides an independent view of the remaining exposure and validates whether the remediation was complete. Understanding the difference between the two matters here, because the right tool depends on what question you are trying to answer. Get a free quote if this is a step your organization is planning for.
Review and update the incident response plan. Every real incident surfaces gaps in the documented response plan. The lessons from this incident, including what the plan got right, what it missed, and what decisions needed to be made that were not anticipated, should be formally documented and used to update the plan before the next incident.
Frequently Asked Questions
How do I know if I have actually had a data breach or just a security incident?
A data breach specifically involves unauthorized access to, acquisition of, or exposure of protected data. A security incident is broader, covering any event that violates security policies, not all of which involve data exposure. For regulatory notification purposes, the key question is whether personal data, protected health information, financial data, or other regulated information was potentially accessed by an unauthorized party. When in doubt, assume breach and let the investigation prove otherwise: the regulatory and legal risk of under-responding to a breach is substantially greater than the cost of over-responding to an incident that turns out not to involve data exposure.
Do I need to notify customers within 24 hours of a breach?
Not in most jurisdictions. GDPR’s 72-hour clock applies to notification of the supervisory authority, not of affected individuals. Individual notification under GDPR is required where the breach poses a high risk to those individuals, but timing is “without undue delay” rather than within a fixed window. NIS2’s 24-hour obligation is an early warning to the national CSIRT, not a customer notification. Customer notification timing should be determined by legal counsel based on the applicable regulatory frameworks, the scope of the breach, and what verified information is available to communicate accurately.
Should we pay the ransom if we are hit by ransomware?
Law enforcement agencies consistently recommend against ransomware payment because payment does not guarantee data recovery, funds criminal operations, and may not end attacker access to your environment. CIRCIA now requires reporting ransomware payments to CISA within 24 hours, which creates a regulatory obligation alongside the decision itself. The decision should involve legal counsel, cyber insurance advisors, and where applicable, law enforcement, rather than being made under pressure in the immediate aftermath of the attack.
What is the most important thing to do in the first hour after discovering a breach?
Isolate affected systems from the network. Not investigate. Not notify stakeholders. Not issue communications. The first action that limits damage is cutting off ongoing attacker access, and that means network isolation of confirmed and suspected compromised systems before any other action. Every hour of continued attacker access after discovery is an hour of additional exfiltration, lateral movement, and evidence destruction.
How long will the full breach response process take?
The immediate containment phase spans the first 24-48 hours. The forensic investigation typically runs one to four weeks depending on complexity. Regulatory notifications follow once the investigation is sufficiently advanced. Full remediation and system restoration can take weeks to months depending on the scope. The full lifecycle from initial compromise to complete containment and remediation averaged 241 days in the most recent industry data, though organizations with strong detection capabilities compress this significantly. Post-breach security assessment and plan updates extend the process further but are essential for preventing recurrence.
The First 24 Hours Are Not the End of Anything
Containing a breach in the first 24 hours is not the resolution of an incident. It is the beginning of a structured response process that will likely run for weeks. What the first 24 hours determine is whether that process starts from a position of reasonable control, with the attacker’s access cut off, the evidence preserved, and the legal clock tracked from the moment of discovery, or whether it starts from a position of ongoing damage.
The organizations that navigate breaches best are almost never the ones with the most sophisticated security stacks at the moment of the incident. They are the ones with documented, tested response plans that their teams have actually rehearsed under realistic conditions. When an incident happens, the quality of the response is determined by the decisions that were made before the incident, not by improvisation under pressure.
Contact us to discuss your incident response readiness or post-breach security assessment