Blog
What to Do After a Data Breach at a Small Business
If you suspect a data breach, the first hour matters more than the first day. Here's the exact sequence to follow, plus what Pennsylvania law actually requires.
The First 24 Hours
If you suspect a data breach, do three things immediately: isolate the affected systems from your network, preserve evidence rather than deleting or reimaging anything, and call your IT provider or an incident response firm before you call anyone else. In Pennsylvania, businesses are also required to notify affected residents 'without unreasonable delay,' and businesses affected by breaches involving 500 or more Pennsylvania residents must notify the Attorney General's office as well.
Most small business owners have never been through this before, so the instinct is either to panic or to freeze. Neither helps. What helps is a clear sequence of steps, taken in order, without skipping ahead to notification before containment is actually confirmed.
- Contain, don't clean up. Disconnect affected devices from the network (unplug the ethernet cable or disable Wi-Fi, don't power them down). Powering off can destroy forensic evidence that's needed later to determine what happened and what data was actually accessed.
- Call your IT provider or a forensic firm before your insurance carrier. Your carrier will want documentation, and your incident response team is what produces it. Most cyber insurance policies also require you to use an approved incident response vendor to remain covered, so check your policy before you start remediation work on your own.
- Preserve, don't delete. Logs, emails, and system images related to the incident should be preserved as-is. Deleting anything, even something that looks like malware, can compromise the investigation and your legal position later.
- Loop in legal counsel early. Notification obligations, what counts as 'personal information,' and how you communicate with affected individuals all carry legal weight. This isn't a step to handle informally over email with your ops team.
- Document everything as you go. When the breach was discovered, what systems were affected, what actions were taken and when. This record becomes the backbone of your regulatory notifications and, if it comes to it, your defense.
Pennsylvania's Notification Requirements
Pennsylvania businesses are covered by the Breach of Personal Information Notification Act (BPINA), amended in 2024 under Act 33. A few specifics worth knowing before you're in the middle of one:
- Timing: The law requires notification 'without unreasonable delay.' There's no fixed number of days, but delay is only justified for two reasons: an active law enforcement investigation, or the time genuinely needed to determine the scope of the breach and restore system integrity.
- Attorney General notification: If the breach affects 500 or more Pennsylvania residents, the state Attorney General's office must be notified as well, not just the affected individuals.
- Credit monitoring: Under the 2024 amendment, businesses may be required to provide affected individuals with 12 months of credit monitoring, depending on the type of information exposed.
- Enforcement: BPINA violations are treated as unfair trade practices under Pennsylvania's Unfair Trade Practices and Consumer Protection Law, enforced by the Attorney General. There's no private right of action under BPINA itself, but that doesn't mean there's no legal exposure. It just means it comes through a different door.
This is general information, not legal advice. Every breach is different, and an attorney familiar with Pennsylvania notification law should review your specific situation before you send anything to affected individuals or regulators.
What Not to Do
- Don't power down affected devices. It feels like the responsible move. It usually isn't.
- Don't notify customers before you know what actually happened. An inaccurate early notification can create more legal exposure than a slightly delayed accurate one.
- Don't assume a ransom payment guarantees data return or deletion. Law enforcement and most incident response firms advise against paying without exhausting other options first, and payment doesn't obligate the attacker to do anything.
- Don't handle it entirely in-house if you don't have a security team. A well-meaning internal fix can destroy the evidence needed to determine what was actually accessed, which affects both your legal notification obligations and your insurance claim.
"The businesses that come out of a breach in the best shape aren't the ones with the fanciest security stack. They're the ones who had a plan before it happened and didn't have to improvise while the clock was running," says Anthony Purich, CIO at 3rd Element Consulting. "By the time you're calling us in the middle of an incident, the decisions that matter most were already made, or not made, months earlier."
Reducing the Odds of a Repeat
A breach response plan matters, but it's a second line of defense. The businesses that recover fastest are usually the ones who had basic controls in place already: multi-factor authentication on every account, a tested backup that isn't connected to the same network as production systems, and a documented incident response plan that doesn't get written for the first time during an actual incident. This is the kind of groundwork a standards-led IT partner builds in from the start rather than bolting on after something goes wrong.
If you're not confident your current environment could withstand this kind of scrutiny, an IT Environment Review is a reasonable place to start, before there's an incident to respond to.
Common questions
Questions leadership usually asks first.
Continue reading
Related reading.
Cybersecurity Services
The controls that decide how bad an incident gets before anyone notices it.
Read more: Cybersecurity ServicesGovernance, Risk & Compliance
Documented policies and notification obligations handled before you need them.
Read more: Governance, Risk & ComplianceBuilding a Business Continuity Plan That Works
The plan that keeps a breach from turning into an improvised week.
Read more: Building a Business Continuity Plan That WorksNext step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
