Suspected Data Breach: the First 24 Hours for Small Teams

A breach response has two clocks: the technical one (hours) and the legal one (days, and it starts whether or not you feel ready). The first 24 hours decide both. The checklist: confirm scope before you announce, contain without destroying evidence, preserve first, notify per your actual obligations — and write everything down with timestamps.

1. Confirm before you announce (hours 0–2)

"We think we were breached" and "we were breached" are different statements, and each one triggers different duties:

SignalWhat it meansFirst move
Creds for sale / dump postedAssume breach; verify which system the dump matchesScope: which data, which dates, which systems
Anomalous access in audit logsPossible intrusion or misconfigurationPreserve logs FIRST (see below), then investigate
Security researcher contacts youVerify researcher, then scopeRespond within their window; document everything

Scope before announcements: what data (rows and fields), when (first/last access), and how many people. You will need all three for every notification you send.

2. Contain — without destroying evidence (hours 0–4)

3. The notification clocks (hours 2–24)

Notification duties vary by jurisdiction and industry — the small-team reality is that most breaches fall under at least one of these:

When in doubt, get counsel involved early — the cost of an hour of advice is trivial next to a mis-filed notification. This checklist is operational, not legal advice.

4. Tell customers the true shape, not the comfortable shape

5. The mistakes that turn a breach into a crisis

Takeaways

---

The Ops Starter Kit ($14) includes the incident templates and evidence-log structure that make a breach response survivable, and Vol. 2 ($27) adds the full DR plan and evidence log. Launch week: 30% off any paid kit with code HIVE-LAUNCH30 at checkout.