Incident Response

The First 72 Hours: An Incident Response Playbook for Law Firms

Most firms lose the case in the first three hours. A practical, hour-by-hour playbook for the moments after detection.

Attorney Armor Security Team April 16, 2026 10 min read
The First 72 Hours: An Incident Response Playbook for Law Firms

Hour 0-1: Contain, do not investigate

The instinct is to figure out what happened. The correct first move is to isolate. Pull the affected segment from the network, revoke active sessions, rotate service-account credentials. Forensics can be done on images later.

Hour 1-6: Engage counsel and the carrier

Notify outside breach counsel before IT writes anything in a ticketing system that will later be discoverable. Open the carrier claim — most policies have a notification window measured in hours, not days.

Hour 6-24: Scope and preserve

Take forensic images. Preserve logs. Inventory every system the attacker touched. Decide whether you have a regulatory notification obligation — most state bars now require client notification within 30-60 days.

Hour 24-72: Communicate

Clients hear about breaches from the news if you don't tell them first. Draft a factual, lawyer-reviewed notice. Brief the managing partner. Brief affected matter teams. Do not speculate about attribution.

What separates firms that survive

Documented decision rights, a pre-engaged breach counsel relationship, and a tabletop exercise within the last six months. Everything else is execution.

Free Assessment

See what an attacker sees.

Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.

Start the assessment

Continue reading