The 72-Hour IR Executive Playbook
The first 72 hours of a cyber incident decide the cost, the liability, and how your organization is remembered. This is what to do, hour by hour, who owns it, the clocks that are running, and the record that holds up afterward.
For CISOs, executives, legal, and communications leaders. Grounded in NIST SP 800-61 and the SANS incident handling model (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned). Built by the IR-OS team.
Why the first 72 hours
Most teams do not fail an incident because of the malware. They fail the first 72 hours. Roles are unclear. Decisions stall. Nobody can reconstruct who did what and when. When it is over, no one remembers the alert. They remember the damage and your response.
Three things decide the outcome in that window. Speed of coordination. Quality of decisions under pressure. And a defensible record of every action. This playbook covers all three, by time block.
Phase 0. Before the incident
The 72 hours are won or lost here. If these are not true today, fix them before you need them.
- A current IR plan that names roles, not just tasks. One owner per role, with a named backup.
- An out-of-band way to communicate that does not depend on the network under attack. Assume email, chat, and single sign-on may be down or watched.
- A single call tree for legal, cyber insurance, executive, comms, and your external IR and forensics firm. Retainers signed in advance, so you are not negotiating a contract mid-breach.
- Tested, offline or immutable backups. A backup you have never restored is a hope, not a plan.
- A known trigger and threshold for declaring an incident, so declaring is a decision, not a debate.
- At least one tabletop in the last 12 months that put executives, not just the SOC, under pressure.
Goal. Turn a signal into a coordinated response with a single owner.
- Declare the incident. Assign an Incident Commander. This is a coordination role, not the most technical person on the response team. Their job is to run the response, not to fix the firewall.
- Open the record. Every action, decision, and time gets logged from now on. What, where, when, and by whom.
- Stand up the bridge on the out-of-band channel. Confirm who is on point for security, IT, legal, comms, and executive.
- Preserve before you change. Capture volatile evidence first. Memory, active connections, and logs disappear when a machine is rebooted or reimaged.
- Start the clock on notification obligations. You do not have to notify yet, but you must know which clocks are now running.
Goal. Stop the spread, preserve evidence, and get the right people on the right tasks.
- Confirm scope as far as you can. What is affected, what is not, and what you do not yet know. Write down the unknowns and revisit them.
- Contain in a way that preserves forensic evidence. Snapshot and image before you wipe. Maintain chain of custody so evidence holds up later.
- Engage external IR and forensics if the incident is beyond your team. The retainer you signed in Phase 0 pays off here.
- Notify your cyber insurer early. Many policies require prompt notice, and the carrier often controls which forensic and legal vendors are approved. Using an unapproved vendor can jeopardize coverage.
- Brief the executive team once, clearly. Facts known, facts unknown, next decision point, and time of next update.
- Assign a single owner to each workstream. Containment, forensics, comms, legal, and executive liaison. No shared ownership.
Goal. Understand what happened, meet your legal clocks, and control the narrative.
- Establish the attack timeline. Initial access, lateral movement, and impact. This drives both remediation and what you must disclose.
- Map the incident to your obligations. The clocks below run on different triggers. Some start from awareness, some from a materiality determination.
- Prepare holding statements for employees, customers, partners, and, if needed, the public. Say what is true, avoid speculation, and never promise what you cannot confirm.
- Decide the disclosure path with legal. What must be reported, to whom, and by when. Record the decision and the basis for it.
- Keep executive updates on a fixed cadence. A predictable rhythm reduces panic and keeps leadership from pulling responders off the work.
The notification clocks that may be running
Deadlines and triggers vary by jurisdiction, sector, and the facts. Confirm what applies to you. This is a starting map, not legal advice.
| Regime | Clock | Trigger |
|---|---|---|
| GDPR (EU) | 72 hours | Notify the supervisory authority after becoming aware of a personal data breach (Article 33). |
| SEC (US public companies) | 4 business days | Disclose a material cybersecurity incident on Form 8-K, Item 1.05, after determining materiality. |
| HIPAA (US health) | Up to 60 days | Notify affected individuals without unreasonable delay; notify HHS (immediately for 500 or more). |
| NIS2 (EU essential/important entities) | 24h / 72h / 1 month | Early warning within 24 hours, incident notification within 72 hours, final report within one month. |
| CIRCIA (US critical infrastructure) | 72h / 24h | Report covered incidents within 72 hours; report ransom payments within 24 hours. |
| US state breach laws | Varies | Many require notice without unreasonable delay; several set fixed day limits. Check every state where affected individuals live. |
Goal. Remove the threat, restore safely, and close the loop with proof.
- Eradicate the root cause, not just the symptom. Removing the malware without closing the entry point invites a second incident, often within days.
- Recover in a controlled order. Restore validated, clean systems first, guided by your recovery priorities and RTO and RPO targets. Confirm the attacker is out before you reconnect.
- Meet the notifications that are due. File what regulators require, on time, with the facts you have recorded.
- Give the board and executives a defensible account. What happened, what you did, what it cost, and what changes now.
- Preserve the full record for insurers, regulators, and potential litigation. This is the difference between a defensible response and a costly one.
The record. What, where, when, and by whom
Every item above depends on one thing most teams do last and regret. An append-only record of every action, decision, and handoff, with a timestamp and an owner. Captured as it happens, not reconstructed after the fact. That record satisfies regulators, supports your insurance claim, protects individuals from personal liability, and lets the board see the response was sound. If you take one thing from this playbook, make it this.
Five mistakes that turn an incident into a crisis
- Making the best engineer the Incident Commander, so no one is actually coordinating.
- Wiping machines before capturing evidence, then being unable to prove scope to regulators or insurers.
- Communicating on the compromised network, so the attacker reads your response plan.
- Speculating in public before the facts are in, then having to walk it back.
- Declaring victory after removing the malware, without closing the entry point or rotating credentials.
The executive one-page
- Declare fast. Assign one Incident Commander whose only job is coordination.
- Open the record at minute one. Timestamp everything.
- Communicate out of band. Do not trust the compromised network.
- Preserve before you change. Capture memory and logs before reimaging. Isolate, do not power off.
- Call legal, insurance, and your IR firm early. Use insurer-approved vendors.
- Know which notification clocks are running from the moment you are aware.
- Pre-agree the ransom decision authority and inputs.
- One owner per workstream. No shared ownership.
- Update executives on a fixed cadence. Facts known, facts unknown, next decision.
- Eradicate the root cause. Rotate credentials. Recover clean systems first.
- Keep a defensible record. What, where, when, and by whom.
IR-OS is an AI-native incident command platform built by the IR-OS team. It runs this playbook for you during a live incident. Clear roles, fast decisions, running regulatory clocks, and an append-only record of every action.