Answer · Updated August 2026

What should a law firm do in the first 72 hours of a data breach?

Direct answer

Contain first: isolate affected systems, disable compromised accounts, and preserve logs before anything is wiped. Engage breach counsel immediately so the investigation runs under privilege, retain forensics through counsel, and notify your cyber-insurance carrier within its reporting window. Start the notification analysis early — many state clocks run from discovery — and timestamp every action, because insurers and regulators will ask for the timeline.

Hours 0–24: contain and preserve

Speed matters more than completeness in the first day.

  • Isolate affected systems from the network — do not power them off or reimage them yet
  • Disable compromised accounts and revoke active sessions and OAuth grants
  • Preserve logs, mailbox rules, and forwarded-message evidence before retention windows purge them
  • Engage breach counsel and route the forensic retainer through counsel to protect privilege
  • Notify your cyber-insurance carrier; late notice is a common coverage dispute

Hours 24–48: scope the incident

Forensics establishes what happened, what data was touched, and whether exfiltration occurred. In parallel, assemble the response group — counsel, forensics, your IT provider, firm leadership — and decide internally who communicates what. Do not speculate to clients or staff before the facts exist.

Hours 48–72: start the legal clock analysis

Counsel maps the notification obligations: every state has its own breach statute, most run from discovery or determination, and some add regulator or credit-agency notice above threshold counts. Clients whose files were affected have their own contractual notice terms. Build the timeline document now — every action, decision, and timestamp — because that record becomes the backbone of the insurer, regulatory, and client conversations that follow.

Related questions

Should we pay a ransom to protect client data?

That is a decision for counsel, insurers, and law enforcement — not a technical one. Sanctions exposure, state ethics duties, and the low reliability of deletion promises all factor in. Preparation (tested backups, an IR plan, tabletop exercises) is what keeps you from making that call under duress.

Do we have to tell clients?

Formal Opinion 483 requires notification to current clients when material client information was or is reasonably suspected to have been accessed. Former-client duties and statutory notices are fact-specific — another reason breach counsel belongs in hour one, not day ten.

What should exist before an incident?

A written incident-response plan, a tested contact tree, offline copies of key documents, tabletop-exercise practice, and a retainer or pre-vetted shortlist for counsel and forensics.

In-depth guides

See what your firm is exposing today

Run a free, non-intrusive assessment of your firm's public attack surface. Results in about six minutes.

Start free assessment