What you need to know
FTC guidance connects immediate operational security, forensic preservation, scope determination, corrective action, accurate communication, and fact-specific legal notification decisions.
Potentially affected
U.S. organizations that store or process employee, customer, patient, financial, identity, authentication, or other sensitive personal information.
DSE recommendation
Activate qualified response resources, stop additional loss without destroying evidence, determine scope, remediate safely, document facts, and have counsel evaluate notification duties.
A suspected data breach creates pressure to shut systems down, reassure customers, and announce an answer. Acting without forensic, legal, technical, and communications coordination can destroy evidence, leave the cause active, or produce statements that are incomplete or misleading.
What the FTC guide establishes
Source fact: The Federal Trade Commission organizes its business guidance around securing operations and notifying appropriate parties. It recommends mobilizing a response team that can include forensics, legal, information security, IT, operations, human resources, communications, management, and other functions appropriate to the organization.
Source fact: The FTC advises moving quickly to stop additional loss, determine the source and scope, identify affected information and people, preserve evidence, correct vulnerabilities, document the investigation, and communicate accurately. It warns organizations not to turn affected machines off before forensic experts advise because powering down can affect evidence.
Source fact: Notification duties vary. The FTC notes state and federal requirements and additional rules that may apply based on the information and organization. It advises consultation with counsel and coordination with law enforcement where appropriate.
Coordinate overlapping response workstreams
DSE recommendation: use the organization’s approved plan and activate qualified internal and external resources. Engage counsel and any insurer promptly when required by law, policy, or contract while qualified responders preserve evidence and contain harm. There is no universal sequence: legal, forensic, operational, safety, law-enforcement, insurer, vendor, and notification work can overlap, and their order depends on the facts and applicable obligations.
- Protect people and essential operations, stop additional data loss, and preserve volatile and forensic evidence under qualified direction.
- Determine the entry path, duration, systems, identities, persistence, data types, affected individuals or organizations, and remaining exposure.
- Secure physical and digital access, compromised credentials, exposed information, affected integrations, and vulnerable systems without assuming the first containment action removed the actor.
- Implement and validate corrective actions, clean restoration, monitoring, and the intended business transaction.
- Document known facts, uncertainty, evidence, decisions, timestamps, scope, communications, and unresolved risk.
- Have counsel determine required notices and timing; coordinate clear communications and practical affected-person guidance.
Communicate facts without creating more harm
DSE recommendation: designate an approved spokesperson and maintain one reviewed fact record. Explain what is known, what information was involved, what the organization has done, what affected people can do, and where updates will appear when counsel determines communication is appropriate. Do not speculate, minimize confirmed impact, disclose details that increase risk, or promise a result the investigation cannot support.
Applicability and limits
The FTC publication is general U.S. business guidance, not legal advice or a complete notification-law matrix. Requirements change and depend on jurisdiction, sector, data, contracts, insurer terms, and facts. This article intentionally provides no universal deadline or fixed response sequence. Organizations outside the United States need guidance for their applicable jurisdictions.
Official reference
Data Breach Response: A Guide for Business — FTC operational and notification considerations.
Review the official source
Federal Trade Commission: Data Breach Response — A Guide for Business · Verified July 19, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE