Protection / Incident response
Preserve facts before drawing conclusions.
The first decisions can determine whether the institution contains harm, preserves usable evidence, treats people fairly, and meets legal obligations.
Response sequence
- 00–04 hours
Stabilize without signaling
Engage counsel and the minimum necessary response leads. Prevent further high-risk access using ordinary security mechanisms where possible. Avoid confronting a subject before evidence and safety implications are assessed.
- 00–24 hours
Preserve first
Place defensible holds on relevant logs, email, cloud records, devices, repositories, badge data, visitor records, samples, contracts, disclosures, and backups. Record who did what and when.
- Day 1
Frame competing hypotheses
Write the observed facts, the suspected transfer path, innocent explanations, critical unknowns, and the evidence that would distinguish them. Keep allegations out of the facts column.
- Day 1–3
Assess duties and scope
With counsel, evaluate employment, privacy, export, sanctions, sponsor, grant, contractual, insurance, law-enforcement, regulatory, and cross-border obligations. Set a documented, proportionate collection scope.
- Day 2–7
Contain and investigate
Rotate credentials, close unnecessary access, protect continuing operations, collect forensically, interview in an appropriate order, verify outside interests, and compare provenance without altering originals.
- Before external statements
Separate proof levels
State what is observed, what is alleged, what is attributed, what is disputed, and what remains unknown. Do not name a person or institution publicly without a reviewed evidentiary and legal basis.
- After action
Fix the path
Remediate the access chain, preserve lessons without exposing private data, support affected teams, review whether controls were applied fairly, and schedule a retest.
Urgent caveat
This is a preparation card, not a substitute for counsel or incident professionals.
Suspected theft, espionage, export violations, employment actions, device collection, law-enforcement contact, and cross-border evidence raise fact-specific legal and safety issues. Establish qualified contacts before an incident.