WEB CHECKLIST

Data Breach Response Checklist

Use this page to record facts, coordinate containment and evidence work, plan recovery, and identify who must assess notification duties. Adapt it to your environment before an incident.

Open the checklist

You can use the checklist without submitting contact details. This web page is the current version; the earlier PDF has been retired.

Working checklist

The order will change with the incident. The incident commander should assign owners, record decisions, and adapt each item to system safety and business impact.

Prepare before an incident

Review this section during planning and tabletop exercises.

Open and triage the incident

Start a reliable record before the team loses track of events.

Contain and preserve

Coordinate risk reduction with evidence work. A single rigid sequence can cause harm.

Scope and remove access

Base remediation on tested evidence, not on a single indicator.

Recover and watch for recurrence

Use documented criteria to return services to normal operation.

Assess notifications and communications

Qualified advisers should apply current rules and contracts to the facts.

Close and improve

Do this after owners agree that active response work has ended.

Ransomware and extortion

Use the approved ransomware plan and current government guidance.

Evidence and containment belong in the same decision log. CISA advises ransomware victims to isolate affected systems promptly. NIST frames incident response as coordinated preparation, detection, response, and recovery. Your responders should choose actions that fit the threat, the system, and the consequences of delay.

Questions before you use it

Is this checklist a substitute for an incident-response plan or professional advice?

No. Use it as a working prompt and adapt it to your systems, contracts, insurance, jurisdiction, and approved incident-response plan. Your technical responders and legal advisers should make decisions for the incident in front of them.

Does containment have to wait until evidence collection is complete?

No fixed rule works for every incident. The response lead should balance system safety, business impact, evidence needs, and the risk of further harm with technical and legal advisers. CISA's ransomware guidance tells organizations to isolate affected systems promptly, while NIST treats response and recovery as coordinated risk-management work. Record each action and its reason.

Can this checklist set our breach-notification deadlines?

No. Notification duties depend on the organization, affected people, data, location, regulator, contracts, and facts of the incident. Record awareness and discovery times, identify the rules that may apply, and ask qualified counsel to assess them against current official sources.

Does the checklist tell us whether to pay a ransomware demand?

No. A payment decision can involve sanctions, law enforcement, insurance, technical recovery, and business continuity. Bring qualified counsel, the incident lead, the insurer when applicable, and the appropriate authorities into the decision. Use current CISA and OFAC guidance rather than a generic rule.

This checklist provides general operational prompts. It is not legal advice, a certification, or a guarantee that the listed actions fit a specific incident.