Containing without destroying evidence
The first technical goal is to stop the spread while keeping the evidence intact. That usually means isolating affected systems from the network rather than shutting them down, since powering off can erase memory that forensic investigators need. Preserve logs, disk images, and the ransom note or other attacker communications, and avoid wiping and rebuilding systems before they have been captured. Reset or disable compromised credentials promptly, and do not leave a compromised account active in the hope of gathering evidence. Notify your cyber insurer early, since many policies require prompt notice and the use of approved vendors.
Privilege and the investigation
Many companies have outside counsel retain and direct the forensic firm so that the analysis supports legal advice. Whether a forensic report stays privileged depends on who engaged the firm, why, and how the report was used, and courts have ordered production where the work looked like ordinary business remediation. Keep written communications about the investigation limited and factual, and avoid speculating in email or chat about fault or scope. Law enforcement, such as the FBI, can be contacted, and doing so does not usually stop the company from continuing its own response. If a ransom payment is under consideration, sanctions rules and reporting obligations must be reviewed first.
Notification clocks start early
Notification duties under state breach laws, sector rules, and contracts can start running before the investigation is finished. New York has its own breach notification law, and companies regulated by the Department of Financial Services face a very short deadline to notify that agency of certain cybersecurity events. Public companies may need to assess materiality for securities disclosure quickly. Customer and vendor contracts often carry their own notice terms. In the first conversation we establish what is known, which laws and contracts likely apply based on where affected people live, and which deadline comes first, then plan notifications around that date.