Situation & Goals
I would present a repeatable incident response plan to contain the breach, preserve evidence for cross-border regulation and litigation, minimize customer harm, and meet legal/notification timelines while protecting business reputation.
Immediate technical containment (0–4 hours)
- Triage: validate breach indicators, scope systems/users/data affected.
- Isolate: segment or air-gap affected subnets/VMs; revoke compromised creds and tokens; block attacker C2 IPs at edge; disable impacted services if needed.
- Short-lived mitigations: deploy WAF rules, IPS signatures, endpoint containment (kill-process/quarantine).
Forensic preservation (0–24 hours)
- Immutability: snapshot affected hosts, network captures (pcap), and endpoint images; store in WORM storage with cryptographic hashes.
- Log preservation: preserve SIEM, cloud audit logs, identity provider logs, and backups. Export hashes and chain-of-custody metadata.
- Use read-only forensic workspaces and dedicated forensic team to avoid contamination.
Legal & compliance engagement timeline
- 0–4 hours: Notify GC and privacy/compliance leads; assemble IR, legal, PR, and business owners.
- 4–24 hours: Map affected records to jurisdictions (data residency, PII/regulated types). Legal assesses notification obligations and evidence rules per region.
- 24–72 hours: Prepare regulator/customer notification drafts; decide on expedited notifications where mandated.
Regulator & customer notification considerations
- Jurisdiction mapping: apply strictest timelines (e.g., GDPR 72-hour rule) and local breach laws (state/sector-specific).
- Content: nature of breach, data classes affected, mitigation steps, recommended customer actions, contact for further information.
- Coordination: use central legal to avoid inconsistent statements; schedule notifications per regulator deadlines and coordinate with law enforcement if requested.
Evidence preservation for audits/litigation
- Chain of custody: document who accessed artifacts, when, and why; preserve original media and forensic copies.
- Retention policy: retain artifacts for periods required by regulators/litigation holds; restrict access via least privilege.
- Expert validation: engage external forensics counsel to attest methodology and findings.
Decision points for public disclosure
- Thresholds: disclose publicly if customer-impacting data confirmed, regulator notification required, or material business impact exists.
- Timing: align public statement after legal clears wording and regulator notifications are scheduled; prefer transparent, factual messaging.
- Escalation: CISO + CEO + GC to approve public release; prepare Q&A and monitoring plan for follow-up.
Post-incident
- Root-cause remediation, patching, credential rotation, compensating controls.
- Lessons learned, updated runbooks, tabletop exercises, and targeted audit to validate fixes.
This plan balances rapid technical containment and rigorous forensic preservation with legal/compliance timelines for multi-jurisdictional regulated data.