The First 72 Hours: An Incident Response Playbook for Law Firms
Most firms lose the case in the first three hours. A practical, hour-by-hour playbook for the moments after detection.

Hour 0-1: Contain, do not investigate
The instinct is to figure out what happened. The correct first move is to isolate. Pull the affected segment from the network, revoke active sessions, rotate service-account credentials. Forensics can be done on images later.
Hour 1-6: Engage counsel and the carrier
Notify outside breach counsel before IT writes anything in a ticketing system that will later be discoverable. Open the carrier claim — most policies have a notification window measured in hours, not days.
Hour 6-24: Scope and preserve
Take forensic images. Preserve logs. Inventory every system the attacker touched. Decide whether you have a regulatory notification obligation — most state bars now require client notification within 30-60 days.
Hour 24-72: Communicate
Clients hear about breaches from the news if you don't tell them first. Draft a factual, lawyer-reviewed notice. Brief the managing partner. Brief affected matter teams. Do not speculate about attribution.
What separates firms that survive
Documented decision rights, a pre-engaged breach counsel relationship, and a tabletop exercise within the last six months. Everything else is execution.
Free Assessment
See what an attacker sees.
Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.
Start the assessment


