A cybersecurity investigation should preserve reliable evidence, verify the incident's full scope, and map notice duties before deadlines expire. Evidence shows what happened, verification tests whether the finding holds up, and notices tell the right people what they need to know. These tracks overlap but answer different questions. Strong evidence does not automatically establish who must receive notice, while a notification deadline may arrive before every technical detail is known.
Table of Contents
- Preserve evidence without losing its context
- How do investigators verify integrity and scope?
- Match each notice duty to its trigger
- Health and financial data require separate checks
- What can a notice prove?
Preserve evidence without losing its context
Start an evidence log as soon as the investigation begins. Record who collected each item, when and where it was collected, what action was taken, and where the item is stored. Restrict access to people authorized to handle the material. Preserve both content and context.
Relevant material may include system logs, alerts, account records, messages, files, device images, timestamps, and metadata. NIST says investigators should record their actions while protecting each record's integrity and provenance, meaning its origin and handling history. It also treats incident data and metadata as evidence even without a formal chain of custody. NIST's incident-response guidance A practical collection record should capture: Keep originals separate from working copies when possible. Retention decisions should account for possible prosecution, internal policy, and the cost and feasibility of accessing the evidence later.
- A unique evidence identifier
- The source system, account, or device
- Collection date, time, and time zone
- The collector and collection method
- Original storage location and working-copy location
How do investigators verify integrity and scope?
Use a hash value—a numerical fingerprint calculated from digital data—to check integrity. If an evidence file's hash changes unexpectedly, investigators should determine whether the file was altered, corrupted, or processed differently. Record the hash algorithm and value alongside the evidence record. Hashing verifies whether data remained unchanged; it does not prove the data is truthful, complete, or tied to the correct person. A preserved log can still contain a wrong timestamp, incomplete coverage, or activity generated by a shared account.
Investigators must compare evidence across independent sources. Scope verification asks whether the incident extends beyond the first affected device or account. Search for the same indicators of compromise, attacker behavior, and persistence mechanisms on known targets and other plausible targets. Test alternate explanations rather than treating the first theory as settled. For example, resetting one compromised account may stop visible misuse without removing a malicious mailbox rule or another active session. NIST warns that superficial scoping can underestimate an incident and leave related activity running elsewhere.
Match each notice duty to its trigger
Do not treat "a breach occurred" as a universal notification trigger. Duties may depend on the organization, sector, geography, customer location, contract terms, data involved, number of affected people, and when a legally defined determination occurs. Build a notice matrix with separate columns for: For SEC-reporting public companies, the four-business-day period begins after the company determines that a cyber incident is material, not when it first discovers the incident.
The filing must describe the incident's material nature, scope, timing, and actual or likely impact. Technical response details that would impede remediation are not required, and a written Attorney General determination involving national security or public safety can support delay. The SEC's cybersecurity disclosure explanation The investigation team should document both discovery and later decisions. A clear timeline helps show which event started a particular clock and why.
- Recipient or regulator
- Legal or contractual trigger
- Event that starts the clock
- Maximum deadline
- Required content
Health and financial data require separate checks
For breaches of unsecured protected health information, HIPAA covered entities must notify affected people without unreasonable delay and no later than 60 days after discovery. The notice must address what happened, the information involved, protective steps, mitigation, and contact details. An impermissible use or disclosure is presumed to be a breach unless a risk assessment finds a low probability of compromise, subject to the rule's scope and defined exceptions. HHS's Breach Notification Rule guidance That framework does not apply to every health-related record or every organization.
Investigators must confirm whether the organization is covered, whether the information is protected health information, and whether it was unsecured before relying on the HIPAA timeline. Under the FTC Safeguards Rule, a financial institution within FTC jurisdiction must report a covered event involving at least 500 consumers as soon as possible and no later than 30 days after discovery. That report does not replace other federal or state obligations. The FTC's notification requirement One incident may therefore produce several deadlines and different recipients. Track each obligation independently instead of assuming the shortest or most familiar rule resolves the others.
What can a notice prove?
A notice can establish what an organization has formally disclosed. It may identify the incident period, affected data categories, likely consequences, protective measures, and contact channels. Save the notice, envelope or email headers, attachments, and the date received. A notice does not necessarily prove that every listed data element was taken, misused, or viewed.
Phrases such as "may have involved" often describe the investigated exposure boundary rather than confirmed misuse. Compare the notice with account activity, provider messages, and other records before drawing a narrower conclusion. If you receive a notice: Do not send passwords, authentication codes, or sensitive identity documents through an unverified link. A legitimate-looking notice can still be copied and repurposed for phishing.
- Confirm it through a contact channel obtained independently from the notice.
- Preserve the complete notice and delivery details.
- Note the dates of the incident, discovery, and notification separately.
- Identify exactly which data categories the notice associates with you.
- Follow protective steps that match those categories.
