Pumpkin
    What to Do in the First 24 Hours After a Breach
    Security

    What to Do in the First 24 Hours After a Breach

    By Aaron WatersApril 8, 2025Updated August 15, 20265 min read

    The first 24 hours after a breach decide more than the five years of security spending that came before them. Handled fast and correctly, a breach becomes a contained, documented, insurable event. Handled slow or wrong, it compounds into something that shows up in client letters for years. So here's the playbook, in order, written for a firm without a security operations center. Print it. On the day you need it, your screens may not be available to display it.

    How firms actually find out

    Almost nobody discovers a breach from an alert, because at most small firms nothing is watching. Discovery tends to look stranger and sadder than the movies.

    Wojeski & Company, a CPA firm in New York, got its notice in 2023 when client files simply stopped opening. No warning banner. No dramatic ransom splash screen at first. Just documents that wouldn't launch, and a slow, spreading realization across the office that this wasn't a server glitch. By the time ransomware announces itself that way, the encryption has usually been running for a while, and the attackers were inside well before that.

    Two lessons hide in that story. First, "we'll notice" is not a detection plan. Continuous threat monitoring exists to compress the gap between intrusion and discovery, and that gap is where the damage compounds quietly. Second, hour zero goes very differently depending on whether there's a number to call. Firms with real IT support for accounting practices start containment in minutes. Firms without it spend the first afternoon searching for help while the clock runs.

    The first hour

    Confirm it's real. A phishing email nobody clicked is a Tuesday. Encrypted files, a confirmed account takeover, or client data surfacing where it shouldn't is a breach.

    Then contain. Disconnect affected machines from the network but leave them powered on, because memory holds forensic evidence that a shutdown destroys. Disable compromised accounts, force password resets, kill active sessions. And start a written log: times, observations, actions taken. Future-you, the insurer, and possibly a regulator will all want that timeline, and memory under stress is garbage.

    Wake up whoever your plan names as the decision-maker. If there's no plan, the most senior person available takes the job, and writing a breach response plan moves to the top of next month's list.

    Hours one through four, figuring out how bad

    Now scope it. How did they get in, and is that door still open? What could the compromised account or machine actually reach? Tax returns and bank details, or the office lunch calendar? The sensitivity of what was reachable drives everything downstream, including who legally must be told. This is the moment firms discover the value of having already mapped what data they keep and who can touch it. The ones that never did spend these hours guessing.

    Check the backups before anything else gets touched. Ransomware crews target backup systems deliberately, and whether yours survived determines your entire negotiating position.

    And unless someone at your firm does forensics for a living, engage an incident response team now. Your insurer likely has one on call, which brings up the phone calls.

    The calls you have to make

    The cyber insurer comes first, and earlier than feels natural. Policies carry notification windows, often 24 to 72 hours, and late notice is one of the classic reasons claims get denied. Calling early also buys help, not just compliance with the fine print: most carriers bring approved forensics teams, breach counsel, and notification vendors with them.

    Then breach counsel, because notification law is a fifty-state patchwork with federal and professional overlays, and the wrong communication at the wrong time creates liability that didn't exist an hour before.

    Law enforcement too. The FBI's IC3 for any breach, CISA as well for ransomware. It costs little and occasionally helps a lot.

    Hours eight through sixteen, closing and rebuilding

    Close the entry point, whatever it was: the unpatched service, the exposed remote desktop, the compromised mailbox rule. Reset credentials wider than feels necessary; if the attacker had any admin-level access, assume every password and API key is burned. Machines that were compromised get rebuilt, not cleaned, because you can't prove a negative about malware persistence. Restore data from verified-clean backups, then watch the restored systems closely, since attackers who lose one door often left a second.

    The last stretch, words and paper

    With counsel, draft the client notifications you may be obligated to send. State laws generally allow 30 to 60 days but some are tighter, and regulators may have their own expectations: the IRS for tax practices, bar associations for law firms. Don't announce before you understand scope. A correction letter is worse than a careful first letter.

    Then consolidate your notes into a clean timeline while it's fresh. That record feeds the insurance claim, any regulatory response, and the honest post-mortem about which control failed and why.

    Things people do at 2am that they regret

    Paying the ransom without advice from forensics, counsel, and the insurer. Payment is sometimes rational and sometimes illegal, since sanctions apply to certain groups, and it's never a decision for one exhausted partner alone.

    Wiping machines to "clean things up," which destroys the exact evidence the insurer and investigators need.

    Blaming the person who clicked. The click was the spark; the conditions were the firm's. Shame today buys silence during the next incident, and silence is the expensive part.

    Before you ever need this page

    This playbook works a hundred times better with three things done in advance: monitoring that shortens discovery, backups you've tested, and a response plan with names and phone numbers on it. All three, and where they fit among everything else, are laid out in our cybersecurity guide for firms. The firms that handle breaches well aren't lucky. They're rehearsed.