Attorney Incident Response: Your First 72-Hour Playbook
A 72-hour attorney incident response playbook for law firms. Contain the incident, preserve privilege, map notice deadlines, and document every step the right way.
Blog post - By Securing Your Law Firm
Get your free review | See pricing | Contact us
Attorney incident response is not a formality. When a client email disappears, a login fails, or a ransom note appears, the first 72 hours decide most of the outcome.
This playbook gives your team a clear order of operations. It is built for legal standards, not generic IT cleanup.
In this article:
- How to contain an incident in the first 0–6 hours without destroying evidence
- Why breach counsel should come before vendors and insurers
- How to protect privilege while keeping operations moving
- What to map during the 24–72 hour notification window
- Why documentation and exposure reviews matter before the next incident
Hours 0–6: Contain the Incident Before It Spreads
Isolate without destroying evidence
The first job is simple: stop the bleed without destroying evidence. Disconnect compromised endpoints, revoke active sessions, suspend suspicious accounts, and block known malicious traffic. Timestamp each move and name the person who made it.
Most teams want to reimage immediately. Do not do that before forensic images are captured. Reimaging wipes volatile memory, log artifacts, and filesystem evidence that your forensic team, insurer, and regulator may need later.
Stop outbound communication from the affected environment
Business email compromise often hides in forwarding rules. Before you cut access, check inbox rules and forwarding settings, then document what you find. That record shows what left the environment and when.
Use an out-of-band channel from here on. Assume firm email is compromised. Coordinate by phone or a secure personal-device platform instead.
Engaging Breach Counsel and Your Insurer in the Right Order
Why outside breach counsel should be your first call
Most firms get the order wrong. They call IT, then leadership, then insurance, and only loop in legal counsel after the paper trail already exists. Retain outside breach counsel before any vendor, forensic firm, or IT consultant starts work.
When counsel retains the forensic vendor, the work can fit under attorney work product and the Kovel doctrine. Retaining the same vendor through operations or IT makes privilege much harder to defend. For smaller firms, outside breach counsel also adds independence and a clear legal-purpose record.
Notifying your cyber insurer without jeopardizing coverage
Prompt insurer notice is a coverage requirement, not a courtesy. Most policies require notice within a set window after discovery, and carriers do dispute delayed notice. Engage counsel first, then notify the insurer through counsel.
Keep insurer updates factual. Do not guess about cause, attribution, or scope before the facts are established. Let counsel review the message before it goes out.
Protecting Attorney-Client Privilege During Incident Response
Structuring the forensic vendor engagement to protect work product
The Kovel doctrine only helps when the engagement is set up correctly. The forensic vendor's letter should say the vendor is retained by outside counsel to help provide legal advice and defend anticipated litigation. If it reads like a general IT contract, the protection is weaker.
The cleanest structure is two-track. One report covers remediation and technical facts for operations. A separate privileged report goes only to counsel and covers legal strategy, causation, and privilege-sensitive findings.
Keeping legal and operational response tracks separate
Privileged material is waived when it is broadly shared. Do not paste forensic conclusions into Slack, a status deck, or a wide email thread. Forensic findings, legal analysis, and strategy go to counsel only.
Operational updates should stay separate. Use them for affected systems, restoration timelines, and staff access. Discipline here is legal protection.
Mapping Notification Obligations in the 24–72 Hour Window
State breach-notification deadlines counsel must identify immediately
Notification deadlines run on multiple tracks and they are not uniform. Within 24 hours, identify every state affected and map the most restrictive deadline. In 2026, many states cluster around 30-, 45-, and 60-day windows. Counsel should verify current requirements against a current 50-state matrix.
Two points matter immediately: some states start the clock at "discovery," others at "determination," and attorney general notice thresholds vary by state. Multi-state firms need counsel to map the spread before sending anything.
Bar ethics and client confidentiality duties specific to law firms
For attorneys, state breach-notification law is only part of the job. ABA Model Rule 1.4 requires prompt client communication when material client confidential information may be involved. Model Rule 1.6 limits those disclosures to what is strictly necessary. State bars have also made clear that client-file incidents trigger separate professional duties.
Client notification is a professional conduct obligation, not just a regulatory one. Counsel should review every notice before it goes out. Keep the language factual. "We are investigating unauthorized access that may have affected your matter files" is defensible. "We have no indication your data was compromised" is not, if you do not yet know.
Documentation That Holds Up to Insurers, Regulators, and Bar Complaints
What to record and how to timestamp it correctly
Every incident action needs a contemporaneous record: who acted, when, on what system, and who authorized it. Capture containment steps, vendor engagements, insurer notices, client communications, and leadership briefings as they happen. Reconstructed timelines carry less weight than real-time records.
Use a dedicated incident log separate from your normal ticketing system and route it through counsel. Labels alone do not control privilege, but the content, purpose, and distribution matter. The timestamp is what regulators will scrutinize for timeliness and reasonableness.
Communication templates that create a defensible record without creating liability
Casual language in status emails and chat threads can become exhibit material. Before any incident, template five messages: an internal holding statement, a business-continuity update, an HR notice if needed, a client notice, and a counsel-only legal and forensic memo. Each template should use confirmed facts only, with an approval workflow and version control.
This is not bureaucracy. It keeps external communications counsel-reviewed, defensible, and less likely to create new liability. Build the templates now.
Catch Exposures Before a Breach Forces This Playbook
What a pre-breach exposure review actually catches
Many law firm incidents start with the same preconditions: weak email authentication, lookalike domains, noisy public DNS records, and Microsoft 365 settings that allow forwarding or external sharing. These are public-facing exposures. They are visible to anyone who knows where to look.
How firms reduce breach likelihood before an incident occurs
Securing Your Law Firm conducts pre-breach exposure reviews that scan public DNS, certificate, and web records without needing internal access or passwords. The result is a before-and-after evidence file for insurer review. It does not eliminate risk, but it can turn the 72-hour playbook from crisis mode into contingency planning.
These reviews also produce insurer-ready documentation. Showing that your firm found and fixed public exposures matters in underwriting and claim review. The firms least likely to need this playbook urgently are the ones that already know their exposure and have closed it.
The First 72 Hours Are a Legal Discipline, Not Just a Technical One
These steps are practical, not theoretical. They separate firms that manage breaches well from firms that face regulatory penalties, malpractice exposure, and long reputational damage. Privilege is preserved or lost early. Notification deadlines start at discovery. Insurers review the sequence of decisions before the claim.
The takeaway is direct: retain outside breach counsel before vendors, run separate forensic and operational tracks, map deadlines on day one, and document everything in real time through a privileged channel. That is defensible attorney incident response. The best firms practice it before they need it.
If you have not yet assessed what your firm looks like from the outside, start there. A Zero-Access Exposure Review from Securing Your Law Firm requires no passwords and no internal access, only a clear look at your public-facing risk profile. Make attorney incident response planning part of your firm's risk program before a breach forces the issue.
This article is informational and does not constitute legal or compliance advice. State breach-notification deadlines, bar rules, and insurer requirements can change, so counsel should verify current obligations before acting.
