Incident Response: What to Do in the First 24 Hours

Discovering that your systems may have been compromised is disorienting. The instinct is either to act too fast, wiping or resetting systems before anyone knows what happened, or to freeze completely. Neither helps. Having a plan before something goes wrong is the difference between a contained, documented incident and a costly, drawn-out crisis. Here's what the first 24 hours should look like.
First: Contain, Don't Delete
The instinct to clean things up can destroy the evidence you'll need for any investigation, regulatory response, or insurance claim. Before taking corrective action, your priority is containment, stopping the spread, without eliminating forensic evidence. Don't reinstall operating systems, wipe drives, or reset devices until you have proper guidance.
Step 1: Identify and Isolate Affected Systems
As soon as you suspect a breach or unauthorized access, take these steps immediately:
Disconnect affected systems from the network (remove the ethernet cable or disable Wi-Fi), but don't power them down unless directed by a forensics professional. Powering off destroys volatile memory that may contain critical evidence.
Change passwords immediately for all accounts that may have been accessed, especially administrator accounts, email, and any system containing patient or client data
Revoke or suspend any access tokens or credentials that appear to have been involved
If the incident involves ransomware, isolate affected machines immediately. Don't pay the ransom before consulting legal counsel and a qualified incident response professional.
Step 2: Notify the Right People Internally
Before any public or regulatory communication, make sure the right people inside your organization know what's happening. At minimum, that includes:
Practice owner or managing partner
Your IT contact or managed services provider
Legal counsel, especially critical if data belonging to patients or clients may have been accessed
Your cyber liability insurance carrier. Most policies require timely notification to preserve coverage, and some provide incident response resources directly.
Don't use potentially compromised accounts or devices to communicate about the incident. Switch to an unaffected channel until you know the scope of what happened.
Step 3: Document Everything from the Start
Start an incident log immediately and keep it current throughout the response. Record the following and continue adding to it as the situation develops:
When you first noticed the activity or anomaly, and what specifically triggered the concern
Which systems, accounts, or categories of data appear to be affected
Every action taken in response, by whom, and when
All communications with vendors, insurers, or legal counsel
This documentation is essential for regulatory reporting, insurance claims, and any subsequent investigation. Regulators will ask for it, and the absence of a clear incident record can compound an already difficult situation.
Step 4: Assess Your Reporting Obligations
Many practices don't realize until it's too late that a breach triggers mandatory reporting requirements under multiple frameworks, each with different timelines. The most relevant ones for Boston-area regulated practices:
HIPAA: Covered entities must notify affected individuals within 60 days of discovering a breach involving PHI. Breaches affecting 500 or more individuals in a state also require notification to HHS within 60 days. Smaller breaches are logged and reported to HHS annually.
Massachusetts 201 CMR 17.00: If a Massachusetts resident's personal information is compromised, notification to affected individuals and the Office of Consumer Affairs and Business Regulation is required as soon as reasonably possible.
PCI-DSS: If payment cardholder data was involved, notification to your payment processor is required. Timelines and specific obligations vary by agreement and incident type.
Financial services (FINRA, SEC, or state regulators): Advisory and financial firms may have specific incident disclosure requirements under their regulatory frameworks.
Start this assessment in the first 24 hours. Some reporting windows are shorter than practices expect, and failing to report on time can create additional legal exposure beyond the original incident.
Common Mistakes That Make Things Worse
Powering down compromised machines before forensic review. This destroys the volatile memory evidence needed to understand how the intrusion occurred.
Rebuilding or reimaging systems before documenting and preserving evidence
Communicating about the incident through potentially compromised channels
Assuming the incident is resolved because visible symptoms stopped. Many intrusions persist quietly after initial detection.
When to Bring in Outside Help
Not every incident requires a forensics firm. But if PHI, financial records, or legally privileged materials may have been accessed or exfiltrated, bring in a qualified third party before you begin remediation. DataMoat helps Boston-area practices understand the scope of what happened, navigate their regulatory reporting obligations, and coordinate with forensics partners when deeper investigation is needed, so you can make decisions clearly instead of under pressure.
Read other blogs
Stay informed with our latest articles on compliance, security, and risk management.


