A pre-written checklist matters because breach response decisions made under pressure, without a plan, are where the most costly mistakes happen — both technically and legally.
The checklist
- Contain: revoke compromised credentials, patch the entry point, isolate affected systems
- Assess scope: exactly what data and how many records were exposed
- Check legal obligations: notification deadlines vary by jurisdiction and data type — confirm requirements early, not after the deadline has passed
- Notify affected individuals with specific, actionable guidance
- Notify relevant regulators if required
- Rotate all potentially affected credentials, including any shared/service account credentials
- Document the incident and root cause for a post-mortem
- Implement the specific fix that prevents recurrence, not just a general "we’ll be more careful"
FAQ
Should a small business have a written breach response plan in advance?
Yes — even a one-page plan drastically speeds up the first, most critical hours of response compared to figuring out the process from scratch during an active incident.