Protection / Incident response

Preserve facts before drawing conclusions.

The first decisions can determine whether the institution contains harm, preserves usable evidence, treats people fairly, and meets legal obligations.

Response sequence

  1. 00–04 hours

    Stabilize without signaling

    Engage counsel and the minimum necessary response leads. Prevent further high-risk access using ordinary security mechanisms where possible. Avoid confronting a subject before evidence and safety implications are assessed.

  2. 00–24 hours

    Preserve first

    Place defensible holds on relevant logs, email, cloud records, devices, repositories, badge data, visitor records, samples, contracts, disclosures, and backups. Record who did what and when.

  3. Day 1

    Frame competing hypotheses

    Write the observed facts, the suspected transfer path, innocent explanations, critical unknowns, and the evidence that would distinguish them. Keep allegations out of the facts column.

  4. Day 1–3

    Assess duties and scope

    With counsel, evaluate employment, privacy, export, sanctions, sponsor, grant, contractual, insurance, law-enforcement, regulatory, and cross-border obligations. Set a documented, proportionate collection scope.

  5. Day 2–7

    Contain and investigate

    Rotate credentials, close unnecessary access, protect continuing operations, collect forensically, interview in an appropriate order, verify outside interests, and compare provenance without altering originals.

  6. Before external statements

    Separate proof levels

    State what is observed, what is alleged, what is attributed, what is disputed, and what remains unknown. Do not name a person or institution publicly without a reviewed evidentiary and legal basis.

  7. After action

    Fix the path

    Remediate the access chain, preserve lessons without exposing private data, support affected teams, review whether controls were applied fairly, and schedule a retest.

Urgent caveat

This is a preparation card, not a substitute for counsel or incident professionals.

Suspected theft, espionage, export violations, employment actions, device collection, law-enforcement contact, and cross-border evidence raise fact-specific legal and safety issues. Establish qualified contacts before an incident.