Data Breach Response: The First 72 Hours Decide Everything

DECLASSIFIED Data breach response is the disciplined first-hours sequence after discovering unauthorised access (containing the intrusion, preserving forensic evidence, assessing scope honestly and meeting India's CERT-In and DPDP notification duties) because the first 72 hours largely determine the total damage.

Why Do the First Hours Dominate the Outcome?

Three clocks start at discovery: the attacker's, exfiltration and lateral movement continue until real containment; the evidence clock, logs rotate and volatile traces vanish, taking attribution with them; and the regulatory clock, CERT-In's six-hour reporting window for covered incidents and DPDP breach duties do not wait for convenient facts. Panic actions, mass shutdowns, quiet clean-ups, premature denials, routinely destroy more value than the intrusion did.

What Is the 72-Hour Sequence?

The order that experienced responders enforce:

  • Contain without destroying: isolate affected segments; do not wipe and rebuild the evidence
  • Preserve forensically: images and logs under chain of custody before anything is 'fixed'
  • Assess honestly: what data, what systems, how long, scope creep is normal; plan for it
  • Notify correctly: CERT-In, DPDP duties, contracts and insurers, with counsel, on the clock
  • Communicate once, truthfully: the walked-back denial is the reputational kill-shot

Where Does Investigation Extend Response?

Beyond the technical rebuild: insider-involvement inquiry where access patterns suggest it; dark-web monitoring for the stolen data surfacing; threat-actor engagement assessment in extortion cases; and litigation-grade documentation for the disputes that follow. Garuda pairs its cyber team with forensic investigators for exactly this joint response.

Tabletop truth: organisations that rehearsed a breach respond in hours; those that didn't spend day one deciding who is in charge, schedule the drill before you need it.
Explore Our Cyber Intelligence Services Request a Confidential Consultation
Quick Answers

Frequently Asked Questions

Specified incident categories require reporting within six hours of notice under CERT-In directions, scope and format are defined; counsel and response partners keep templates ready.

The DPDP framework contemplates notification of the Board and affected data principals for personal-data breaches, obligations turn on rules in force; build the process now rather than during an incident.

A decision for leadership with legal and specialist advice, engagement assessment, sanctions exposure and recovery odds differ case by case. Never improvise it alone.

Chat with us on WhatsApp