Back to Insights
What Should a Company Do in the First 72 Hours After a Data Breach?

What Should a Company Do in the First 72 Hours After a Data Breach?

August 18, 2026
Alita Editorial
7 min read

A data breach rarely comes with a clear warning. It may start with an unusual login, a customer reporting a suspicious email, or a vendor discovering company data somewhere it should not be. Once a company realizes that a breach may have occurred, the clock starts ticking.

Under Indonesia’s Personal Data Protection Law (Law No. 27 of 2022 or UU PDP), data controllers and processors are required to notify the relevant supervisory authority and affected data subjects within 3 x 24 hours, or 72 hours, after becoming aware of a breach.

In those first 72 hours, companies should focus on five priorities : confirming the incident, containing the threat, preserving evidence, assessing regulatory obligations, and communicating clearly with affected stakeholders.

Hour

Business Priority

Key Actions

0 - 1 hour

Confirm the incident

Verify the alert, activate the response team, and start documenting  the incident.

1 - 6 hour

Contain without losing evidence

Cut unauthorized access, isolate affected systems, and preserve logs and forensic evidence.

6 - 24 hour

Align decision makers

Notify leadership, legal, DPO, affected business units, and insurers where applicable.

24 - 48 hour

Assess obligations and prepare communication

Determine PDP Law requirements and prepare customer, media, and internal messaging.

48 - 72 hour

Notify, communicate, and support

Complete required notifications, communicate with affected stakeholders, and activate support channels.

Hour 0-1 : Confirm the Incident Before Taking Action

When a security alert appears, the instinct may be to immediately shut down affected systems. But acting without understanding the situation can destroy evidence that investigators need later.

The first priority is to determine whether the alert represents an actual breach and activate the right people.

What to do:

  1. Escalate the alert immediately. Route it to the incident response or security team rather than leaving it in a regular ticket queue.

  2. Triage the incident. Identify the affected system, the type of data potentially involved, and how confident the team is that a breach occurred.

  3. Activate the incident response plan. Bring together IT/security, legal, corporate communications, and an executive decision-maker.

  4. Start an incident log. Record actions, decisions, and timestamps from the moment the incident is identified.

That record becomes important not only for the technical investigation, but also for regulatory reporting and the company's post-incident review.

Hour 1-6 : Cut Access Without Destroying Evidence

Once the incident is confirmed, containment becomes the priority. However, stopping the attacker should not mean destroying the evidence needed to understand how the breach happened.

What to do:

  1. Disable compromised accounts and revoke exposed credentials or API keys.

  2. Isolate affected systems from the network where necessary.

  3. Avoid wiping, reformatting, or rebooting systems before forensic evidence is preserved.

  4. Back up relevant authentication, network, and application logs.

  5. Document systems taken offline, including when and why the action was taken.

  6. Involve a digital forensics team if the incident is significant or involves sensitive data.

  7. Begin assessing what data may have been accessed and how many individuals could be affected.

The principle is simple: stop unauthorized access while preserving enough evidence to understand the scope, cause, and impact of the incident.

Hour 6-24 : Get the Right People in the Room

A data breach quickly becomes a business issue. The response may affect customers, contracts, regulatory obligations, business operations, and the company’s reputation. That is why internal notification needs to happen in a clear order.

Who to Notify

Why They Matter

Executive Leadership

Provides direction and approves critical decisions

Legal and compliance

Assesses regulatory, contractual, and legal obligations

Data Protection Officer (DPO), if appointed

Supports data protection and breach response

Affected business units

Coordinates the response with teams dealing with affected customers or partners

Cyber insurance provider, if applicable

Some policies have specific notification requirements.

The exact structure may vary by organization, but the principle is consistent: the people who can make technical, legal, operational, and communication decisions need to be aligned early.


Hour 24-48 : Assess Your PDP Obligations

By this stage, the company should have enough initial information to assess its regulatory responsibilities, even if the investigation is still ongoing.

Under Article 46 of Indonesia's UU PDP, written breach notification must be submitted to the relevant data protection supervisory authority and affected data subjects within 72 hours of becoming aware of the breach.

The notification generally needs to cover:

  1. Scope of impact: What personal data was affected or disclosed.

  2. Timeline: When and how the breach occurred.

  3. Response actions: What has been done or is planned to handle and mitigate the incident.

One detail matters: the 72-hour period begins when the organization becomes aware of the breach, not necessarily when the breach itself occurred. This is why the incident log created from Hour 0 matters. It provides a documented timeline of when the company became aware of the incident and how it responded.

Because regulatory requirements and submission channels may change, companies should confirm the applicable notification process with their legal or compliance team during an actual incident.

Hour 24-48: Prepare Customer and Media Communication

While security and legal teams assess the incident, communications teams should prepare for another critical challenge: what will the company tell customers, employees, partners, and the media? The guiding principle should be accuracy before speed. A strong breach communication should clearly explain:

  1. What happened.

  2. What information may have been affected.

  3. What the company is doing to address the incident.

  4. What affected individuals should do.

  5. Where they can get further information or support.

Communication should also be prepared for different channels, including direct customer notifications, website FAQs, media statements, and talking points for customer facing teams.

A single spokesperson or communication lead should coordinate external messaging to prevent conflicting information. In a data breach, how a company communicates can influence trust just as much as how quickly it contains the technical problem.

Hour 48-72 : Notify, Communicate, and Support

The final 24 hours are about turning preparation into action. The company should coordinate regulatory requirements with communication to affected stakeholders.

What to do:

  1. Submit the required written notification to the relevant authority and affected data subjects.

  2. Publish customer notifications or public statements when appropriate.

  3. Provide a dedicated support channel, such as an email address, hotline, or FAQ page.

  4. Brief customer-facing employees so they can respond consistently.

  5. Continue monitoring systems for signs of further compromise.

A contained incident is not necessarily a closed incident. Monitoring and investigation should continue to identify any further risks.

What Happens After 72 Hours?

The 72-hour deadline is an important milestone, but it is not the end of the response. Companies should continue the forensic investigation, address the root cause, review contractual or cross-border obligations where relevant, and conduct a post-incident review.

The objective is not simply to close the incident, but to learn from it and strengthen the organization's ability to respond to the next one.

Data Breach Readiness Checklist

The best time to prepare for a data breach is before one happens. Ask whether your company has:

  1. A documented incident response plan with clearly assigned roles.

  2. A designated person responsible for data protection and breach notification.

  3. Up to date contact information for the relevant supervisory authority.

  4. Log retention and backup processes that support forensic investigation.

  5. Pre-approved templates for regulatory, customer, and media communication.

  6. A trained spokesperson and backup.

  7. A clear briefing process for customer-facing teams.

  8. Documented cyber insurance notification requirements, if applicable.

  9. Regular incident response simulations or tabletop exercises.

  10. A formal post incident review process.

Don't Wait for a Breach to Build Your Response Plan

The first 72 hours after a data breach are too important to leave to improvisation.

A strong response requires more than cybersecurity technology. It requires clear processes, defined responsibilities, fast decision-making, regulatory awareness, and coordinated communication.

Organizations that respond effectively are not necessarily those that never experience an incident. They are the ones that have prepared their technology, people, processes, and communication strategy before the first alert appears.

Need help strengthening your organization's incident response readiness?

Alita's Cyber Security solutions help organizations strengthen detection, containment, and response capabilities across their digital infrastructure helping teams respond to cybersecurity incidents with greater speed, clarity, and confidence.

Sources

  1. Law No. 27 of 2022 on Personal Data Protection (UU PDP)

  2. Future of Privacy Forum - Indonesia's Personal Data Protection Bill

  3. ASEAN Briefing - Indonesia's Comprehensive Personal Data Protection Law Guide.

  4. Multilaw - Data Protection Guide: Indonesia.

Ready to Lead Your Industry?

Transform now.

Tags:

Alita Insights Data Breach Indonesia's PDP Law

Share this article: