What to Do After a Data Breach: A Small Business Checklist
After a data breach, a small business has five jobs, roughly in this order: contain the incident and hand technical response to professionals, preserve evidence (don’t wipe anything), notify your cyber-insurance carrier before spending money on recovery, meet your legal notification obligations — in Tennessee that clock is short — and communicate honestly with the customers affected.
Most breach advice focuses on the technical scramble — we’ve covered that side in our guide to the first hour of a breach. This post is about what comes after: the business, legal, and insurance decisions in the following days that determine whether the incident stays a bad week or becomes a lawsuit. One caveat up front: none of this is legal advice. Breach law is genuinely complicated, and one of the first calls below gets you an actual attorney.
1. Contain, then hand off — and stop touching things
Isolate affected machines from the network, disable compromised accounts, and then resist the natural urge to "clean everything up." Reimaging computers, deleting suspicious files, and rotating every log feels productive, but it destroys the record investigators need to answer the one question everything else depends on: what data was actually accessed? The scope of your legal duties, your insurance claim, and your customer communication all hinge on that answer. If you can’t prove the breach was limited, you may have to treat it as if it wasn’t.
2. Preserve evidence like it’s going to court
Because it might. Concretely:
- Leave affected systems isolated but intact. Disconnected from the network, not wiped, ideally still powered on so memory evidence survives.
- Export and save logs now — firewall, Microsoft 365 audit, VPN, backups — many of these overwrite themselves within days or weeks by default.
- Start a written timeline immediately. Who noticed what, when, and every action taken since. Memory fades fast, and this document is the backbone of the insurance claim and any legal defense.
- Preserve the phishing email or entry point if you know it, headers and all.
3. Call your cyber insurer before you spend a dime
This step is out of order on most people’s instinct list, and getting it wrong is expensive. Nearly every cyber policy requires prompt notice and consent before incurring costs. Hire your own forensics firm or attorney without the carrier’s approval and those bills may not be covered — some policies let the carrier deny parts of a claim over it. Your policy has a breach hotline; call it. The carrier will typically assign breach counsel (an attorney who quarterbacks the response and, importantly, wraps the investigation in privilege) and approved forensics vendors. If you don’t have cyber insurance, call a breach attorney directly — yes, really, before the PR firm and before the new firewall.
4. Know your notification obligations
Tennessee’s breach-notification law is Tenn. Code Ann. § 47-18-2107. In broad strokes: if an unauthorized person acquires unencrypted personal information of Tennessee residents — a name combined with something like a Social Security number, driver’s license number, or financial account credentials — you must notify the affected residents immediately, and no later than 45 days from discovery of the breach. If more than 1,000 Tennessee residents are notified, you must also notify the consumer reporting agencies. Properly encrypted data (where the key wasn’t also taken) generally falls outside the notice requirement — one more reason encryption pays for itself.
Two complications: other states’ laws follow your customers, not your office. If your customer list includes Georgia, Alabama, or North Carolina residents, each of those states’ rules applies to its residents, and deadlines and thresholds vary. And industry rules stack on top — HIPAA for health information, the FTC Safeguards Rule for financial data, PCI DSS for card data. This is exactly why breach counsel exists; determining who must be told what by when is their job, not a judgment call for you or your IT provider.
5. Communicate with customers like a business worth trusting
- Don’t speculate. Say what you know, what you’re doing, and what affected people should do (change passwords, watch statements, freeze credit if warranted). Early guesses that turn out wrong do more damage than the breach.
- One voice. Pick a single point of contact and brief your employees on what to say — and what not to — before customers start calling the front desk.
- Follow through. If credit monitoring is appropriate, offer it. If you promised an update, send it. Businesses mostly survive breaches; they rarely survive looking evasive about them.
6. After the dust settles
Fix the actual root cause — not just the symptom — and document what changed. Your insurance renewal will ask, your customers may ask, and a second breach through the same door is far harder to explain than the first. A short lessons-learned review with everyone involved, while it’s fresh, is the cheapest security improvement you’ll ever make.
Equal Tech Solutions helps small businesses across Cleveland, Chattanooga, and the Southeast US both before these calls happen and during them — from managed cybersecurity and incident response that limits the blast radius, to working alongside your carrier and counsel when something gets through. If you’re reading this mid-incident, contact us — and if you’re reading it beforehand, even better.
