AI for Nonprofits
Visionary · M24 · lesson 24 of 49 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Incident Response Planning: What to Do When You Get Breached

15 min

Overview

An incident is the moment when the abstract risk discussed at every board meeting becomes a concrete crisis with a clock. A staff member opens a phishing email and clicks the link. A donor calls because their card was charged at a store they have never visited. A ransomware note appears on a workstation, then on a second, then on the file server. A vendor notifies you that they were breached and your data was among the records taken. In each scenario, the next twenty-four hours determine whether the incident becomes a manageable disruption or a multi-month crisis with regulatory penalties, donor flight, and lasting reputational damage.

The single most consequential variable in incident outcomes is preparation. Organizations with a written incident response plan, named team roles, pre-engaged outside counsel and forensic providers, tested communication templates, and one tabletop exercise on the books recover faster, spend less, retain more donors, and produce regulatory filings that survive scrutiny. Organizations operating without a plan make decisions under stress that they later regret: investigating internally and destroying evidence, notifying affected individuals before counsel reviews the message, paying ransoms in violation of OFAC sanctions, missing statutory notification deadlines, and losing the records they need to file an insurance claim.

This lesson translates incident response planning into the specific, time-sequenced actions a nonprofit takes from before a breach occurs through the year-long aftermath. It covers the pre-incident preparation that makes everything afterward possible, the first-hour and first-day actions that contain damage and preserve evidence, the multi-week notification and communication work that satisfies legal obligations and rebuilds trust, the long-tail remediation that prevents recurrence, the standard breach notification message structure, the financial cost categories that make insurance worthwhile, and the recurring questions about ransom payment, late discovery, vendor breaches, and evidence handling. By the end you should be able to draft a one-page response plan for your organization and identify the small set of investments needed to make the plan executable when an incident arrives.

Why You Need a Plan Before a Breach

The case for advance planning is not theoretical. Incidents arrive in patterns that the planning process anticipates. The first phone call after discovery is not the moment to research breach counsel; the firms with breach experience are deluged after a major incident and may not be available within the hours that matter. The first email to staff is not the moment to draft messaging from scratch; the wrong message produces panic, premature disclosure, and evidence loss. The first notification to a regulator is not the moment to read the statute; the timing windows are short and the format requirements specific.

Plans solve these problems by moving decisions out of the crisis. The incident response plan names the response team in advance, identifies the outside counsel relationship in advance, holds template communications in a known location, documents the regulatory notification matrix for the jurisdictions where affected individuals reside, and specifies the chain of authority for decisions that must be made quickly. When the incident arrives, the team executes from the plan rather than improvising under stress.

The plan also produces evidence of the organization's care. Cyber liability insurers ask for the plan during underwriting. Regulators ask whether the organization had a plan during post-incident inquiry. Donors and journalists ask how the organization was prepared. A documented plan, exercised at least once, demonstrates due care that a panicked memo written during the incident cannot.

Finally, the plan exists because the alternative, improvisation, has predictable failure modes. Internal investigation destroys evidence that forensic providers would have used to scope the incident. Premature individual notification triggers state attorney general inquiries before the organization can answer questions. Ransom decisions made under time pressure violate sanctions law and fund criminal enterprises without restoring the data. The plan is the structured alternative to each of these failure modes.

The Incident Response Checklist

Before a Breach Happens

Before any incident occurs, the planning work makes everything afterward possible. Complete each item on a calendar with named owners and revisit annually.

Document the response team. Identify the executive sponsor (typically the executive director or COO), the technical lead (IT director or external partner), the communications lead (development director or marketing manager), the legal lead (general counsel or outside breach attorney on retainer), the privacy or compliance lead, and the human resources lead. List home phone numbers, personal emails, and at least one alternate contact for each. Distribute the contact sheet to every team member and to one alternate per role.

Engage outside counsel with breach experience now, even if only for a brief introductory meeting. Most breach attorneys offer pre-incident retainer arrangements at modest cost; the relationship dramatically accelerates the response when an incident arrives. Identify a forensic provider similarly: a brief introductory engagement, a master service agreement on file, and an understanding of their availability. Confirm cyber liability insurance with adequate limits, review the policy for breach response panel inclusion, and document the claims hotline.

Maintain template communications: the staff notification, the donor notification, the regulator notification, the press statement, and the internal status update. Have counsel review them before any incident occurs. Maintain the regulatory notification matrix mapping the states where your supporters reside to the relevant breach statutes, notification deadlines, attorney general thresholds, and credit monitoring obligations. Update the matrix annually as state laws change.

Conduct a tabletop exercise once a year. A two-hour facilitated walkthrough of a realistic scenario reveals every gap in the plan, the missing phone number, the unclear authority, the assumption that someone else was monitoring email. Update the plan based on what the exercise teaches. The exercise itself is the most underused, most valuable preparation activity available.

When You Discover a Breach (Hour 0)

Hour zero is the moment of discovery. The actions in the first sixty minutes set the tone for everything that follows.

Notify the response team. The discoverer, often a staff member or external alert, calls or messages the executive sponsor and the technical lead. Document the time of discovery to the minute; this timestamp drives notification clocks and insurance coverage. Activate the response team's communication channel, typically a dedicated Slack channel or a conference bridge with all members.

Preserve evidence. Do not log into the affected system to investigate. Do not let staff begin clicking around. Do not delete suspicious emails or files. Forensic providers reconstruct what happened from the artifacts remaining on systems; deletion or login activity overwrites evidence that may be the difference between a contained scope and an unknowable scope. If the affected system is actively damaging the network, ransomware encrypting other machines, malware spreading, isolation is appropriate, but isolation should be done by someone trained to preserve evidence, ideally the forensic provider's first responder.

Engage outside counsel. The lawyer's first task is to take privileged control of the investigation. Communications during the response that pass through counsel are typically privileged; communications that do not may be discoverable in subsequent litigation. Routing the response through counsel from the start preserves attorney-client privilege over the most sensitive deliberations.

Activate the cyber liability insurer. The hotline call within the first hours opens the claim, deploys the breach response panel, and may pay for the forensic engagement and counsel directly. Many insurers have preferred providers; using their panel is generally the right path because it accelerates response and aligns coverage.

Within 24 Hours

Within twenty-four hours of discovery, the team executes a rapid cycle of containment, scope assessment, internal communication, and documentation.

Containment is the technical work of stopping ongoing damage. Forensic providers and IT lead the containment, typically isolating affected systems from the network, disabling compromised credentials, blocking attacker command-and-control channels, and segmenting the environment. Containment must balance stopping damage against preserving evidence; the forensic provider directs the balance.

Scope assessment begins to identify what was accessed, when, and how. The first twenty-four hours rarely produce a complete answer; they produce an initial estimate and the analytical plan that produces the answer over days. Scope drives every downstream decision: notification obligations, insurance claim sizing, communication strategy, and remediation priorities.

Internal communication informs staff at the right level of detail. The standard message tells staff that the organization is responding to a security incident, identifies one designated spokesperson for any external inquiries, instructs staff not to discuss the incident outside the organization, and explains that more information will follow. Avoid speculative content; staff repeating an inaccurate early assessment to donors becomes its own problem.

Documentation begins immediately. The response team logs every action with time, owner, and outcome. The log becomes the record for the insurance claim, the regulatory inquiry, and the post-incident review. Treat documentation as a serious deliverable, not a secondary task. Most regulators ask for the contemporaneous timeline as their first piece of evidence.

Days 3-7: Investigation and Notification Prep

Days three through seven are the period of deeper investigation and notification preparation. Forensic analysis matures: the team can typically identify the entry vector, the duration of attacker access, the systems and data that were touched, and the likelihood that data was exfiltrated rather than merely accessed. Each of these findings sharpens the notification message and the insurance claim.

Counsel translates the forensic findings into a notification analysis. The matrix prepared in advance identifies the states whose residents are affected, the statutes that apply, the deadlines that begin running from discovery, the thresholds that trigger attorney general notification, and the credit monitoring obligations. For organizations operating across many states, the analysis can identify several dozen distinct notification obligations with overlapping but distinct requirements. Vendors are sometimes engaged to manage the notification logistics: large mailings, call centers, credit monitoring enrollment, and tracking of acknowledgments.

The communication strategy crystallizes. Counsel and communications lead draft the donor notification, the public statement (if any), the FAQ for staff handling inquiries, and the briefings for major donors and key partners. Major donors should hear from leadership directly before reading any public statement. The board chair should be briefed on the incident, the planned response, and any decision points requiring board input.

If law enforcement involvement is appropriate, commonly with ransomware, with theft of significant volumes of personal data, or with suspected insider threat, counsel manages the engagement. Law enforcement involvement does not pause notification obligations except where statute provides for delay during active investigation, and even those delays are time-limited. Consult counsel before publicly disclosing law enforcement involvement, because disclosure can disrupt active investigations.

Days 7-30: Notification and Communication

Between roughly days seven and thirty, the formal notifications occur and external communication peaks. Statutory windows for notification of affected individuals range from thirty to ninety days in most states; many organizations target notification by day thirty to leave margin and to communicate before the news becomes public through other channels.

Send individual notifications using the template the lesson section on notification messages describes. Notifications must be sent in the manner the statute requires, first-class mail, electronic mail (only if certain conditions are met), or substitute notice for very large incidents. Track delivery and respond to inquiries through a dedicated response channel staffed by trained personnel; a hotline number, an email address, or both. Provide credit monitoring enrollment instructions where required by statute or where the type of data accessed warrants it.

Notify regulators on the schedule the matrix specifies. Many states require simultaneous attorney general notification when incidents exceed thresholds. Federal notifications, HHS for protected health information, the IRS for tax records, FTC for certain consumer data, follow their own schedules. Counsel manages the regulatory notification process; the documentation prepared in advance dramatically simplifies the work.

Manage external communications proactively. A press statement, posted on the organization's website and shared with key media contacts, prevents speculation. Brief key sponsors and major donors directly before they hear from other sources. Update the public statement as new information emerges. Resist the temptation to minimize: every breach communication that proves later to be incomplete or inaccurate causes a second wave of damage worse than the first.

After 30 Days: Fix and Prevent

After day thirty, the work shifts from notification to remediation, learning, and prevention. The forensic report identifies the root cause and recommends remediation; the team implements the recommendations on a documented schedule.

Conduct a post-incident review with the response team and key stakeholders. What worked, what did not, what gaps did the incident reveal in the plan, what investments would prevent or mitigate the next incident. Document the review and present a summary to the board. Update the incident response plan based on the lessons.

Implement the security improvements the incident motivated. If the incident exploited weak password practices, deploy a password manager and require MFA. If the incident exploited a missing patch, implement a patching cadence. If the incident exploited a vendor compromise, strengthen the vendor security review process. The post-incident period is when board and donor support for security investment is highest; capture the support while it is available.

Manage the long tail of inquiry and litigation. Notifications continue to produce inquiries for months. Regulator follow-up letters arrive on extended timelines. Class action attorneys may file suit; coverage and defense are usually the insurance company's concern, but the organization remains the named defendant. Maintain the documentation, respond to inquiries through counsel, and continue to update affected individuals as new information emerges. The first anniversary of the incident is also a meaningful milestone for many board reviews and external reporting cycles.

What to Tell People When You Notify

Breach notifications to affected individuals are governed by statute in detail and reviewed by regulators after the fact. The standard structure includes: a clear statement that an incident occurred and that the recipient's information was affected; a description of what happened in plain language without technical jargon; the date the incident was discovered and, where reliably known, the dates of attacker activity; the categories of personal information involved (names, addresses, Social Security numbers, financial account numbers, health information, dates of birth); the steps the organization is taking to investigate and remediate; the steps the recipient should take to protect themselves; the offer of credit monitoring or identity theft protection if applicable; and contact information for questions, including a dedicated phone number and email address.

Tone matters. The notification should be direct, respectful of the recipient's time and concern, and honest about uncertainty where it exists. Avoid corporate boilerplate that sounds defensive. Avoid speculation that may turn out to be wrong. Acknowledge that the experience is upsetting. Provide concrete, actionable steps the recipient can take, placing a fraud alert, freezing credit, monitoring statements, enrolling in credit monitoring, rather than vague reassurances. Counsel reviews every notification before it leaves the organization; the cost of a poorly drafted notification is higher than the cost of one extra day of legal review.

Cost of a Breach

Breach costs accumulate across multiple categories that collectively account for the total impact. Forensic investigation runs from twenty thousand dollars for a small incident to several hundred thousand for a complex one; the meter starts immediately on engagement and continues until the analysis is complete. Outside counsel costs scale similarly: privileged investigation, notification analysis, regulatory engagement, and litigation defense each add to the bill, and the bill grows over months not weeks.

Notification logistics, mailing, call center, credit monitoring enrollment, run two to ten dollars per affected individual depending on volume, statute, and contract terms with the vendor. For an incident affecting ten thousand donors, the notification cost alone can reach a hundred thousand dollars. Credit monitoring offered for one or two years is often required by statute or by best practice for sensitive data.

Regulatory penalties and settlements depend on jurisdiction and incident specifics. State attorneys general may impose civil penalties; federal regulators (HHS, FTC) may impose fines. Class action settlements are common for incidents affecting many residents; the per-affected-individual settlement value typically runs from a few dollars to a few hundred dollars depending on the data exposed and the jurisdiction.

Indirect costs often exceed the direct ones. Donor flight following a breach has been documented at meaningful percentages in nonprofit-specific studies; the lifetime value of lost donors compounds over years. Staff time during the response, frequently three to six months of meaningful executive engagement, displaces other organizational priorities. Reputation rebuilding after a public breach is a years-long effort. Cyber liability insurance covers most direct categories; policies with limits in the one to five million dollar range are typical for mid-sized nonprofits and offset most direct costs at premiums of a few thousand dollars per year. The economic case for the policy is overwhelming once the cost categories are understood.

Key Takeaway

Incident response is a discipline of preparation. The decisions that matter most are made in calm offices in advance: who is on the team, who is on retainer, what templates exist, what insurance is in place, what the matrix looks like, what the tabletop exercise revealed. The execution of those decisions during a real incident becomes a sequence of practiced steps rather than a series of frightened improvisations.

Every nonprofit will eventually face an incident. Phishing, ransomware, vendor compromise, lost laptop, accidental disclosure, the categories vary; the eventual occurrence does not. The investment that distinguishes a manageable incident from a catastrophic one is fundamentally a planning investment made before the incident occurs. A two-hour tabletop exercise once a year, a three-thousand-dollar cyber liability policy, a brief introductory call with a breach attorney, and a one-page plan in a known location are not exotic preparations. They are the difference between an organization that survives an incident and one that does not.

Frequently Asked Questions

Should we pay ransom if hackers encrypt our files?

The strong consensus across law enforcement, cyber liability insurers, and security professionals is that nonprofits should not pay ransom unless every alternative has been exhausted and counsel has cleared the payment under sanctions law. The Office of Foreign Assets Control has issued advisories warning that ransom payments to sanctioned entities can produce strict-liability sanctions exposure for the paying organization, even when the recipient's identity is not known with certainty. Many ransomware groups have been linked to sanctioned jurisdictions. Even where sanctions risk is manageable, payment funds future criminal activity, marks the organization as willing to pay (increasing the probability of future targeting), and provides no guarantee of decryption: roughly thirty to forty percent of victims who pay receive nonworking decryption keys, partial decryption, or follow-up extortion attempts. The right alternative is offline backups: organizations with tested, segregated backups recover without payment. If your organization faces ransomware without backups, the decision becomes a triage exercise managed by counsel, the forensic provider, and the insurer; document every step and every consultation. The lesson's preventive direction is to invest in backups, MFA, and training before the incident so that the ransom question never reaches the table.

What if we discover a breach weeks after it happens?

Late discovery is common and not fatal to the response, but it tightens timelines and expands scope. State notification statutes generally start the clock at discovery rather than at the original incident date, so the day-one response begins when the organization knew or should have known. The insurance policy may have a notification window from the date of the original incident; check the policy with counsel because some policies require notification within a fixed window of the underlying event regardless of when the organization discovered it. The forensic investigation will be harder because evidence has aged: logs may have rolled over, attacker artifacts may have been overwritten, and the timeline reconstruction is less complete. The notification message may need to acknowledge the gap between incident and discovery; regulators ask why the discovery took as long as it did and expect a credible explanation. The remediation plan will be larger because the attacker had longer access and the scope of accessed data is typically broader. The lesson is preventive: monitoring practices that detect incidents within days rather than months are among the highest-return investments the organization can make.

Do we need cyber insurance?

Cyber liability insurance has moved from optional to essentially required for any nonprofit handling personal data. The policy structure is reasonably standardized: first-party coverage for forensic investigation, notification logistics, credit monitoring, business interruption, and ransom expenses where lawful; third-party coverage for litigation defense and settlements arising from the incident; pre-breach services such as incident response planning, tabletop exercises, and security assessments; and access to a panel of pre-vetted counsel, forensics, and notification vendors. Premiums for mid-sized nonprofits with reasonable security hygiene typically run from a few thousand dollars to fifteen thousand dollars per year for limits between one million and five million dollars. The application process itself produces value: insurers now require evidence of MFA, password practices, backups, and patching, and the review process surfaces gaps the organization can address. For small organizations the policy may be the most consequential single investment in incident readiness, because it brings the breach response panel relationships that the organization could not maintain on its own. Work with a broker familiar with nonprofit cyber risk; the policy language varies significantly across carriers, and the wrong policy is sometimes worse than no policy.

Can we just delete evidence after the incident?

Evidence destruction is among the worst possible decisions during incident response. Statutes in many jurisdictions impose record retention obligations triggered by the incident itself; deletion can constitute spoliation in subsequent litigation; forensic investigators rely on the artifacts that remain on systems to reconstruct what happened; and insurance claims and regulatory filings depend on the contemporaneous record. The normal expectation is that the organization preserves the affected systems, the access logs, the email records, the network traffic captures (where they exist), and the contemporaneous response notes for the duration of any investigation, litigation, or audit, which often runs years. Counsel and the forensic provider will direct preservation; their direction supersedes any internal impulse to clean up after the incident. The exception is data that cannot lawfully be retained, certain categories of regulated information that must be deleted at the end of stated retention periods, but deletion of those records continues on the original schedule rather than being either accelerated or frozen by the incident; consult counsel before deviating. As a practical matter, the impulse to delete usually arises from embarrassment about what the evidence will show; managing that impulse is part of what counsel and the response team do.

What if the breach involves a vendor, not us?

Vendor breaches have become the most common incident category for nonprofits because they exploit the trust relationship without requiring the attacker to compromise the nonprofit's own systems. The response is structurally similar to a direct breach but with key differences. The vendor's notification triggers your own analysis: counsel reviews whether your organization has independent notification obligations under state law (yes, in most cases, because the affected individuals are your supporters even if the breach occurred on the vendor's systems), whether your contracts assign costs of notification to the vendor (often yes for credit monitoring and notification logistics, but sometimes contested), and whether your insurance covers the incident or whether the vendor's insurance is primary (typically the vendor's, with your policy as a backup). Maintain documentation of every interaction with the vendor: their notifications, their forensic reports if shared, their commitments on remediation, and their responses to your contractual demands. Reassess the vendor relationship: the breach may justify replacing the vendor, requiring additional contractual safeguards, or accepting the risk depending on the cause and the vendor's response. The post-incident period is the right moment to revisit the broader vendor security review process so future relationships are scoped with this scenario in mind.