Contain without erasing
Containment and preservation pull against each other, so a data breach response checklist has to put them in order. Pulling an affected machine off the network is usually fine; wiping it, reimaging it, or handing it back to the user so they can keep working is not, because the state of that machine is the investigation. The same applies to terminating and rebuilding cloud instances or rotating credentials away before anyone has captured what those accounts were actually doing. Have memory and disk images taken by someone qualified first, and restore service from clean media afterward. If the real choice is between staying online and preserving a machine, write down who made that call and on what basis. That note tends to matter later, when the sequence of events is reconstructed by people who were not there.
Logs run out faster than people assume
Much of the record you will want lives in logs that rotate, and retention is often far shorter than anyone in the room believes. Endpoint, firewall, VPN, authentication, email, and cloud administrative logs should be exported and set aside as soon as an incident is recognized rather than left in place to overwrite themselves. Ask your providers to extend retention and to preserve what sits on their side, since a good deal of it is not yours to hold and some of it is discarded on a schedule you do not control. Collect the unglamorous items too: ticket histories, physical access records, and the configuration as it stood before anyone began changing things. This is the step most often skipped, and it is the one least likely to be recoverable once it is gone.
Keep the internal record clean
Maintain a single running timeline of who learned what and when, who was told, and what was done in response, because that record tends to be read closely afterward. Move the discussion out of open channels into a defined group, and ask people to stop speculating in writing about cause, scope, or fault while the facts are still moving. Early guesses typed into a chat window have a way of outliving the facts that replaced them. Bring counsel in at the beginning rather than once the technical work is finished, so the investigation is directed and documented properly from the first hour. It is safest to assume that anything written during this period may eventually be read by someone outside the company.