What Should a Company Do in the First 72 Hours After a Data Breach?
A data breach rarely comes with a clear warning. It may start with an unusual login, a customer reporting a suspicious email, or a vendor discovering company data somewhere it should not be. Once a company realizes that a breach may have occurred, the clock starts ticking.
Under Indonesia’s Personal Data Protection Law (Law No. 27 of 2022 or UU PDP), data controllers and processors are required to notify the relevant supervisory authority and affected data subjects within 3 x 24 hours, or 72 hours, after becoming aware of a breach.
In those first 72 hours, companies should focus on five priorities : confirming the incident, containing the threat, preserving evidence, assessing regulatory obligations, and communicating clearly with affected stakeholders.
Hour | Business Priority | Key Actions |
|---|---|---|
0 - 1 hour | Confirm the incident | Verify the alert, activate the response team, and start documenting the incident. |
1 - 6 hour | Contain without losing evidence | Cut unauthorized access, isolate affected systems, and preserve logs and forensic evidence. |
6 - 24 hour | Align decision makers | Notify leadership, legal, DPO, affected business units, and insurers where applicable. |
24 - 48 hour | Assess obligations and prepare communication | Determine PDP Law requirements and prepare customer, media, and internal messaging. |
48 - 72 hour | Notify, communicate, and support | Complete required notifications, communicate with affected stakeholders, and activate support channels. |
Hour 0-1 : Confirm the Incident Before Taking Action
When a security alert appears, the instinct may be to immediately shut down affected systems. But acting without understanding the situation can destroy evidence that investigators need later.
The first priority is to determine whether the alert represents an actual breach and activate the right people.
What to do:
Escalate the alert immediately. Route it to the incident response or security team rather than leaving it in a regular ticket queue.
Triage the incident. Identify the affected system, the type of data potentially involved, and how confident the team is that a breach occurred.
Activate the incident response plan. Bring together IT/security, legal, corporate communications, and an executive decision-maker.
Start an incident log. Record actions, decisions, and timestamps from the moment the incident is identified.
That record becomes important not only for the technical investigation, but also for regulatory reporting and the company's post-incident review.
Hour 1-6 : Cut Access Without Destroying Evidence
Once the incident is confirmed, containment becomes the priority. However, stopping the attacker should not mean destroying the evidence needed to understand how the breach happened.
What to do:
Disable compromised accounts and revoke exposed credentials or API keys.
Isolate affected systems from the network where necessary.
Avoid wiping, reformatting, or rebooting systems before forensic evidence is preserved.
Back up relevant authentication, network, and application logs.
Document systems taken offline, including when and why the action was taken.
Involve a digital forensics team if the incident is significant or involves sensitive data.
Begin assessing what data may have been accessed and how many individuals could be affected.
The principle is simple: stop unauthorized access while preserving enough evidence to understand the scope, cause, and impact of the incident.
Hour 6-24 : Get the Right People in the Room
A data breach quickly becomes a business issue. The response may affect customers, contracts, regulatory obligations, business operations, and the company’s reputation. That is why internal notification needs to happen in a clear order.
Who to Notify | Why They Matter |
|---|---|
Executive Leadership | Provides direction and approves critical decisions |
Legal and compliance | Assesses regulatory, contractual, and legal obligations |
Data Protection Officer (DPO), if appointed | Supports data protection and breach response |
Affected business units | Coordinates the response with teams dealing with affected customers or partners |
Cyber insurance provider, if applicable | Some policies have specific notification requirements. |
The exact structure may vary by organization, but the principle is consistent: the people who can make technical, legal, operational, and communication decisions need to be aligned early.
Hour 24-48 : Assess Your PDP Obligations
By this stage, the company should have enough initial information to assess its regulatory responsibilities, even if the investigation is still ongoing.
Under Article 46 of Indonesia's UU PDP, written breach notification must be submitted to the relevant data protection supervisory authority and affected data subjects within 72 hours of becoming aware of the breach.
The notification generally needs to cover:
Scope of impact: What personal data was affected or disclosed.
Timeline: When and how the breach occurred.
Response actions: What has been done or is planned to handle and mitigate the incident.
One detail matters: the 72-hour period begins when the organization becomes aware of the breach, not necessarily when the breach itself occurred. This is why the incident log created from Hour 0 matters. It provides a documented timeline of when the company became aware of the incident and how it responded.
Because regulatory requirements and submission channels may change, companies should confirm the applicable notification process with their legal or compliance team during an actual incident.
Hour 24-48: Prepare Customer and Media Communication
While security and legal teams assess the incident, communications teams should prepare for another critical challenge: what will the company tell customers, employees, partners, and the media? The guiding principle should be accuracy before speed. A strong breach communication should clearly explain:
What happened.
What information may have been affected.
What the company is doing to address the incident.
What affected individuals should do.
Where they can get further information or support.
Communication should also be prepared for different channels, including direct customer notifications, website FAQs, media statements, and talking points for customer facing teams.
A single spokesperson or communication lead should coordinate external messaging to prevent conflicting information. In a data breach, how a company communicates can influence trust just as much as how quickly it contains the technical problem.
Hour 48-72 : Notify, Communicate, and Support
The final 24 hours are about turning preparation into action. The company should coordinate regulatory requirements with communication to affected stakeholders.
What to do:
Submit the required written notification to the relevant authority and affected data subjects.
Publish customer notifications or public statements when appropriate.
Provide a dedicated support channel, such as an email address, hotline, or FAQ page.
Brief customer-facing employees so they can respond consistently.
Continue monitoring systems for signs of further compromise.
A contained incident is not necessarily a closed incident. Monitoring and investigation should continue to identify any further risks.
What Happens After 72 Hours?
The 72-hour deadline is an important milestone, but it is not the end of the response. Companies should continue the forensic investigation, address the root cause, review contractual or cross-border obligations where relevant, and conduct a post-incident review.
The objective is not simply to close the incident, but to learn from it and strengthen the organization's ability to respond to the next one.
Data Breach Readiness Checklist
The best time to prepare for a data breach is before one happens. Ask whether your company has:
A documented incident response plan with clearly assigned roles.
A designated person responsible for data protection and breach notification.
Up to date contact information for the relevant supervisory authority.
Log retention and backup processes that support forensic investigation.
Pre-approved templates for regulatory, customer, and media communication.
A trained spokesperson and backup.
A clear briefing process for customer-facing teams.
Documented cyber insurance notification requirements, if applicable.
Regular incident response simulations or tabletop exercises.
A formal post incident review process.
Don't Wait for a Breach to Build Your Response Plan
The first 72 hours after a data breach are too important to leave to improvisation.
A strong response requires more than cybersecurity technology. It requires clear processes, defined responsibilities, fast decision-making, regulatory awareness, and coordinated communication.
Organizations that respond effectively are not necessarily those that never experience an incident. They are the ones that have prepared their technology, people, processes, and communication strategy before the first alert appears.
Need help strengthening your organization's incident response readiness?
Alita's Cyber Security solutions help organizations strengthen detection, containment, and response capabilities across their digital infrastructure helping teams respond to cybersecurity incidents with greater speed, clarity, and confidence.
Sources
Law No. 27 of 2022 on Personal Data Protection (UU PDP)
Future of Privacy Forum - Indonesia's Personal Data Protection Bill
ASEAN Briefing - Indonesia's Comprehensive Personal Data Protection Law Guide.
Multilaw - Data Protection Guide: Indonesia.
Ready to Lead Your Industry?
Transform now.
Tags:
Related Articles
Private AI vs Public AI: Which Is Right for Your Enterprise?
How to decide where your AI workloads should live, based on security, compliance, cost, and what your organization can realistically operate.
Enterprise AI Strategy: How to Successfully Adopt AI Without Disrupting Your Business
Build a practical enterprise AI strategy that delivers business value while ensuring security and governance.