Executive Playbook

The 72-Hour IR Executive Playbook

The first 72 hours of a cyber incident decide the cost, the liability, and how your organization is remembered. This is what to do, hour by hour, who owns it, the clocks that are running, and the record that holds up afterward.

For CISOs, executives, legal, and communications leaders. Grounded in NIST SP 800-61 and the SANS incident handling model (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned). Built by the IR-OS team.

$4.45M
Average cost of a data breach. Source: IBM Cost of a Data Breach 2023.
277 days
Average time to identify and contain a breach. Source: IBM, 2023.
10 days
Global median attacker dwell time. Source: Mandiant M-Trends 2024.

Why the first 72 hours

Most teams do not fail an incident because of the malware. They fail the first 72 hours. Roles are unclear. Decisions stall. Nobody can reconstruct who did what and when. When it is over, no one remembers the alert. They remember the damage and your response.

Three things decide the outcome in that window. Speed of coordination. Quality of decisions under pressure. And a defensible record of every action. This playbook covers all three, by time block.

The one rule that changes everything
Open an append-only record at minute one. Every action, decision, and handoff, with a timestamp and an owner. Reconstructing it later from a chat thread is where good responses become expensive ones.

Phase 0. Before the incident

The 72 hours are won or lost here. If these are not true today, fix them before you need them.

Pro tip
Print the call tree and the first-hour checklist and keep a physical copy off the network. In a ransomware event, the document you need most is often on the system you can least reach.
Hour 0 to 1

Detect and declare

Goal. Turn a signal into a coordinated response with a single owner.

Watch out
Do not power off compromised machines by reflex. Pulling the plug can destroy memory-resident evidence and the very artifacts your forensics firm and your insurer will need. Isolate at the network layer instead.
Hour 1 to 6

Mobilize and contain

Goal. Stop the spread, preserve evidence, and get the right people on the right tasks.

If ransomware, decide the payment question early
Do not improvise it at hour 40. Pre-agree the decision authority and the inputs: are backups viable, is data exfiltrated, what does the insurer require, and does the payee touch a sanctioned entity. Paying a sanctioned group can itself carry legal exposure. Legal and the insurer should be in this decision from the start.
Hour 6 to 24

Investigate and communicate

Goal. Understand what happened, meet your legal clocks, and control the narrative.

The notification clocks that may be running

Deadlines and triggers vary by jurisdiction, sector, and the facts. Confirm what applies to you. This is a starting map, not legal advice.

RegimeClockTrigger
GDPR (EU)72 hoursNotify the supervisory authority after becoming aware of a personal data breach (Article 33).
SEC (US public companies)4 business daysDisclose a material cybersecurity incident on Form 8-K, Item 1.05, after determining materiality.
HIPAA (US health)Up to 60 daysNotify affected individuals without unreasonable delay; notify HHS (immediately for 500 or more).
NIS2 (EU essential/important entities)24h / 72h / 1 monthEarly warning within 24 hours, incident notification within 72 hours, final report within one month.
CIRCIA (US critical infrastructure)72h / 24hReport covered incidents within 72 hours; report ransom payments within 24 hours.
US state breach lawsVariesMany require notice without unreasonable delay; several set fixed day limits. Check every state where affected individuals live.
Watch out
The SEC clock starts when you decide the incident is material, not when you discover it, and you cannot delay the materiality decision unreasonably. Document when and how that determination is made.
Hour 24 to 72

Eradicate, recover, and report

Goal. Remove the threat, restore safely, and close the loop with proof.

Pro tip
Rebuild identity, not just endpoints. In modern intrusions the attacker's real prize is credentials and tokens. Reset privileged accounts, rotate secrets and certificates, and revoke active sessions, or you will hand the keys back.

The record. What, where, when, and by whom

Every item above depends on one thing most teams do last and regret. An append-only record of every action, decision, and handoff, with a timestamp and an owner. Captured as it happens, not reconstructed after the fact. That record satisfies regulators, supports your insurance claim, protects individuals from personal liability, and lets the board see the response was sound. If you take one thing from this playbook, make it this.

Five mistakes that turn an incident into a crisis

The executive one-page

See where your team stands. Take the 2-minute IR-readiness assessment

IR-OS is an AI-native incident command platform built by the IR-OS team. It runs this playbook for you during a live incident. Clear roles, fast decisions, running regulatory clocks, and an append-only record of every action.