Activate the firm’s incident process as soon as a possible breach is discovered. Notify the designated security contact and firm leadership. Contact counsel and the insurer promptly to ask about legal duties, policy notice, and any required incident response process. Do not wait for a complete investigation before making those calls, since deadlines or policy conditions may apply.
Record what is known: when the issue was found, who found it, which systems or accounts may be affected, what information may have been exposed, and what actions have been taken. Preserve relevant emails, access logs, device details, and vendor communications. Do not delete files or reset systems in a way that could destroy evidence. Qualified technical responders can help contain access and investigate what occurred. Ask them to document their work and coordinate with counsel and the insurer where appropriate.
Limit further access in a controlled way. For example, a compromised account may need to be disabled and credentials changed, but the firm should preserve logs and follow the incident lead’s instructions. Avoid making public statements or telling clients what happened until the facts and notification obligations have been reviewed. That does not mean staying silent when a notice is required. Ask counsel to identify relevant privacy laws, contract terms, regulator rules, and client commitments, including who must be told, by whom, and by what deadline.
Name one spokesperson to communicate with clients, employees, regulators, and vendors. Keep messages accurate and limited to verified facts. Record when each communication was sent and what was said. Ask the insurer whether it requires use of specified response providers or approval before certain costs are incurred. Confirm who can authorize system shutdowns, restoration, outside support, and client notices.
After containment, restore systems from known clean sources and verify access controls before returning them to normal use. Review the cause with the technical team and identify specific changes, such as disabling a vulnerable account, improving multifactor authentication, or changing vendor access. A vendor’s involvement does not automatically resolve the firm’s contractual or legal responsibilities, so clarify duties with counsel.
This is general education, not legal, cybersecurity, or engineering advice; applicable law, contracts, licensed PE judgment, and local codes govern.
