It usually starts small. An employee mentions that a file will not open, then another one says the same thing. A strange note appears on a screen, or a customer emails to ask why they got a password reset they never requested. Within a few minutes you realize this is not a glitch. Someone is inside your systems, and the clock has already started.
What you do in the next day matters more than almost anything else. Handled well, the first 24 hours contain the damage, protect your evidence, and keep your insurance claim on solid ground. Handled in a panic, those same hours can quietly wreck a claim you paid years of premiums for. This data breach response checklist walks you through exactly what to do, and in what order, so you stay calm and protected instead of guessing.
The short version is simple. Contain the problem without destroying proof, call your insurer before you call anyone else, and write down everything as you go. The rest of this guide fills in the details.

Why the first 24 hours decide your claim
A breach is not just a technical event. It is also a legal and insurance event, and the choices you make early can lock in your outcome. Most cyber policies require you to report an incident quickly, often within 24 to 72 hours of discovering it, and to let the insurer help direct the response. Miss that window, or bring in your own vendors before anyone approves them, and you can hand the carrier a reason to reduce or deny what it pays.
Time also drives cost. The average paid cyber claim ran around $116,000 in 2025, with smaller businesses closer to $79,000. A fast, orderly response keeps you at the lower end of that range, because a slow one lets attackers spread, evidence disappear, and regulators start counting the days you waited.
So the goal of your first day is not to fix everything. It is to stop the bleeding, protect the proof, and get the right professionals steering. Every step in the data breach response checklist below serves one of those three jobs.
Your first 24 hours: the data breach response checklist
Work through these steps roughly in order, though a few will overlap. If you have an incident response plan already, this is the moment to open it. If you do not, this list is a solid stand in.
1. Contain the problem, but do not wipe anything
Your first instinct will be to make it stop. That instinct is right, with one big caution. Disconnect affected devices from the network instead of powering them off or reformatting them. Unplug the network cable, disable Wi Fi, or isolate the machine, so the attacker loses their grip while the evidence on the drive stays intact.
Reset passwords for any account that may be exposed, revoke access tokens, and turn off remote access paths the intruder could be using. What you must not do is delete files, rebuild servers, or “clean up” to feel productive. Those actions destroy the forensic trail your insurer and investigators need, and they are a common reason claims fall apart.
2. Call your cyber insurer first, on the hotline
Before you hire an IT firm, before you email customers, before you post anything, call your cyber insurance carrier. Most policies list a 24/7 breach hotline on the declarations page or in your welcome packet. That one call opens your claim, starts the clock in your favor, and connects you to the people who run this playbook for a living.
This ordering trips up a lot of owners, because it feels natural to call your usual computer person first. But many policies require you to use vendors the insurer has approved in advance, and hiring your own forensics or legal help without a green light can leave those bills unpaid. If you are unsure what your policy covers here, our guide to what cyber insurance covers breaks it down.

3. Let the breach coach take the wheel
When you report the claim, the insurer usually assigns a breach coach, an outside lawyer who specializes in incident response. This is one of the most valuable things your policy buys. The coach coordinates the forensics team, advises on legal duties, and keeps much of the investigation under attorney client privilege, which can protect you later.
Follow the coach’s lead on who does what. They will bring in an approved forensics firm to find out how the attacker got in, what they touched, and whether any data actually left the building. Resist the urge to run your own parallel investigation, and give the coach the honest, complete picture. They cannot protect you from a fact they do not know about.
4. Preserve evidence and start a written log
From the first moment, keep a running record. Note the time you noticed the problem, who you called, what each person said, and every action you took. A simple document or notebook is fine. This log matters for two reasons: it proves to your insurer that you acted quickly and reasonably, and it helps investigators and, if needed, regulators reconstruct the timeline.
Preserve the technical evidence too. Save system logs, screenshots of any ransom note or suspicious message, and copies of odd emails. Do not let anyone reboot or reimage a machine until the forensics team says it is safe, because a lot of proof lives only in a system’s memory and vanishes on restart.
5. Loop in leadership, not the whole company
Pull together a small response group: the owner or a senior manager who can make decisions, your point person for IT, and whoever handles communication. Keep the circle tight in the early hours. Broad internal announcements can cause panic, tip off an attacker who is watching, or lead a well meaning employee to say something public that you will regret.
If employee records were exposed, plan to involve HR. If the breach touches a vendor or a client, note it too, since you may have contract duties to notify them. Your breach coach will help sort out which obligations apply and when.
6. Hold off on public statements and customer notices
You will feel pressure to tell customers right away. Pause. In the first 24 hours you often do not yet know what really happened, and a rushed statement can be wrong, which erodes trust and creates legal exposure. Every state has its own breach notification law, and most give you a defined window to notify affected people once a breach is confirmed, not the instant you suspect one.
Let your breach coach guide the timing and wording of any notice. There are also reporting duties beyond customers. Businesses in regulated fields, and companies in states that follow the insurance data security model law, may need to notify a regulator, sometimes within 72 hours of confirming an event.
Who to call, and who to wait on
Having the right numbers ready before anything happens is half the battle. Here is the short list for day one.
| Contact | When | Why |
|---|---|---|
| Cyber insurance hotline | Right away, first call | Opens the claim, assigns your breach coach, approves vendors |
| Breach coach (assigned) | Within the first hours | Runs the legal and forensic response, protects privilege |
| Approved forensics firm | After the coach engages them | Finds the cause and scope without wrecking your claim |
| Leadership and IT lead | Immediately, small group | Makes decisions and handles containment |
| FBI via IC3 (ic3.gov) | Within 24 to 48 hours | Reports the crime; can aid recovery and satisfies some duties |
| Customers and regulators | Later, once confirmed | Notify on the timeline the law and your coach set, not before |
Reporting the incident to the FBI through its Internet Crime Complaint Center at ic3.gov, or your local field office, is worth doing early. It is free, it creates an official record, and it can help trace funds after wire fraud or a ransom demand.

Mistakes that can sink a good claim
Most denied claims are not denied because the policy was bad. They are denied because of avoidable missteps in the first day. Watch for these.

Waiting too long to report is the big one. If your policy says notify within 72 hours and you sit on it for a week while you try to fix things yourself, you have handed the insurer a clean reason to push back. Hiring your own forensics or lawyer without approval is a close second, because those costs may not be reimbursed. And wiping or rebuilding systems before evidence is preserved can leave everyone unable to prove what happened, which stalls the whole claim.
One more quiet trap: paying a ransom on your own before talking to your carrier and coach. Beyond the sanctions risk, an unapproved payment can fall outside coverage. If ransomware is involved, our guide to ransomware insurance explains what is and is not covered. And if you are still shopping for a policy, it is worth checking that your security controls meet insurer requirements so a future claim is not denied over a missing safeguard.
Key takeaways
- Contain without destroying evidence. Disconnect affected devices from the network, but do not power them off, wipe them, or rebuild them.
- Call your cyber insurer’s hotline first, before hiring anyone. Most policies want notice within 24 to 72 hours and may require approved vendors.
- Let the assigned breach coach direct the forensics and legal steps, and give them the full, honest picture.
- Keep a written log from minute one, and preserve system logs, screenshots, and suspicious emails.
- Hold public and customer statements until the facts are clear and your coach sets the timing. Report to the FBI at ic3.gov early.
A breach is stressful, but it is survivable when you move in the right order. Keep this checklist and your insurer’s hotline number somewhere you can grab in a hurry, and the worst day of your business year becomes a problem you manage rather than one that manages you. If you do not have coverage yet, you can check what a policy would cost and get a free quote before you ever need this list.
Frequently asked questions
What is the very first thing to do after a data breach?
Contain it without destroying evidence, then call your cyber insurer’s hotline. Disconnect affected devices from the network so the attacker loses access, but leave them powered on and untouched so investigators can see what happened. Your insurer’s call opens the claim and brings in the experts who guide the rest.
How fast do I have to report a breach to my insurer?
Check your policy, but most require notice quickly, commonly within 24 to 72 hours of discovering the incident, and many offer a 24/7 hotline for exactly this. Reporting late is one of the most common reasons a claim gets reduced or denied, so when in doubt, call sooner rather than later.
Should I tell my customers right away?
Usually not in the first 24 hours. You often do not yet know the true scope, and a wrong or premature statement can create legal problems. State breach notification laws give you a defined window once a breach is confirmed. Let your breach coach guide what you say and when.
Can I use my own IT company for the investigation?
Only if your insurer approves it. Many policies require you to use vendors they have vetted, or to get sign off before you hire your own. Using an unapproved firm can leave those bills unpaid. Your regular IT team can still help with containment while the approved forensics firm handles the formal investigation.
Do I need to report the breach to the police?
It is a good idea. Reporting to the FBI at ic3.gov, or a local field office, is free, creates an official record, and can help trace stolen funds. It does not replace your other duties, such as notifying customers or regulators when the law requires it. If you want the plain meaning of any term here, our cyber insurance glossary spells it out.

