A database appears for sale on a forum. Ransomware locks your servers. A departing employee has taken the customer list. An email account is compromised and invoices are altered mid-thread.

What you do in the first three days determines the cost of all of it.

Hour one to twelve: contain

Do not turn everything off and wipe it. The instinct to rebuild immediately destroys the evidence you will need — for the investigation, for the insurer, and for the clients who will ask what happened.

  • Isolate affected systems from the network rather than wiping them
  • Preserve logs before they rotate — server, firewall, VPN, email, access logs. This is the single most common irrecoverable loss
  • Take images of affected machines where practical
  • Revoke credentials, reset passwords, and revoke active sessions and tokens
  • Enable or force multi-factor authentication
  • Remove access for anyone who has left
  • Assemble a small response team and record every decision with a timestamp

Do not pay a ransom before taking advice. Payment does not guarantee decryption or deletion, funds a criminal enterprise, and carries its own legal exposure including under AML and sanctions frameworks where the recipient is a designated entity.

Day one to three: establish scope and notify

What was actually taken? Not what you fear, and not the reassuring version. Categories of data, number of records, and whether it includes CNIC numbers, financial details, health information, or credentials.

Who has to be told, and by when?

Contractual obligations come first and are the tightest. If you process data for clients — particularly EU, UK or US clients — your contract almost certainly requires notification within a short fixed period, commonly measured in hours. Read the data processing addendum. Missing that deadline is a breach in itself, and it is the exposure Pakistani IT firms most often overlook. See software development and SaaS agreements and setting up a software house.

Regulators. Sectoral regulators — State Bank for banks and payment institutions, PTA for licensees, SECP for regulated entities — have their own incident reporting requirements. Pakistan's general data protection framework has been in development, so confirm the current position; regardless, sectoral obligations bite now.

Law enforcement. Unauthorised access, data theft and ransomware are offences under PECA, and the FIA Cyber Crime Wing is the reporting route. See reporting online fraud and cybercrime and an FIA notice and how the agency works.

Affected individuals. Even where no statute compels it, telling people whose data has been exposed is usually right and is increasingly expected — particularly where they can protect themselves by changing a password or watching an account.

Your insurer, within the policy's notification period. Late notification is a standard ground for declining cover. See a rejected insurance claim.

Your bank, immediately, if payment details or banking credentials are involved. See card and account fraud.

What to say, and what not to

Say what you know, when you know it. The greatest reputational damage comes from statements that later prove wrong — "no customer data was affected" issued before anyone had checked.

Do not speculate about the cause, and do not blame a named employee or vendor in public. That statement will be read back to you in litigation.

Give people something to do — change a password, watch for phishing, verify payment details by phone.

Keep one channel and one spokesperson. Multiple staff answering customers individually produces contradictions.

Business email compromise

Worth separate mention because it is the most common incident affecting Pakistani businesses and the most preventable.

An email account is compromised, the attacker watches the thread, and at the moment of payment sends amended bank details. The money goes and the two businesses argue about who bears it — a question that turns on whose system was compromised and whether either was negligent.

The control that defeats it: never change payment details on the strength of an email. Verify by phone, on a number you already held. Say so in your invoices and your terms.

If it has happened, act within hours — report to both banks immediately, because a recall has a chance only before funds are moved on.

Insider incidents

Where an employee or contractor has taken data, the response is different: preserve access logs and device records before anything is reset, do not confront before you have the evidence, and consider both the criminal route and urgent civil relief — an injunction restraining use and requiring delivery up.

See protecting your business when an employee leaves and stay orders and injunctions.

After: what determines your liability

Whether you are liable to customers, clients and regulators turns less on the fact of the breach than on what you did before and after:

  • Did you have reasonable security measures proportionate to the data held?
  • Did you comply with your contractual commitments on security and notification?
  • Did you notify on time?
  • Did you act reasonably on discovery, or delay and conceal?
  • Did you have a plan, or improvise?

Concealment is what turns a manageable incident into an existential one.

Preparing before it happens

  • Know what personal data you hold, where, and who can reach it — most Pakistani businesses cannot answer this
  • Minimise: delete what you no longer need, especially CNIC copies and payment details
  • Multi-factor authentication everywhere, and an offline backup you have actually tested restoring
  • A written incident response plan naming who does what, with contact details for counsel, forensics and your insurer
  • Vendor terms that give you the security commitments and notification you owe your own clients
  • Staff training on phishing, and a policy on what may be put into external tools including AI. See using AI in your business
  • Cyber insurance, read properly — check the ransomware and business interruption terms
  • Contractual caps on liability with your customers, agreed before an incident, not during one

See data protection and privacy for Pakistani businesses.

How the firm can help

We advise through live incidents — containment and evidence preservation, contractual and regulatory notification deadlines, what to tell customers, dealing with FIA reporting, and ransom demands. Afterwards we handle claims from customers and clients, insurance recovery, and action against insiders.

Before an incident, we review your contracts and prepare the response plan, which is considerably cheaper.

See regulatory and compliance, or contact the firm. If a breach is live, today.