WARTIME

When Something Goes Wrong

The decisions made in the first hours of a cyber incident shape everything that follows. Select an incident type below for immediate priorities, common early errors, and interactive response tools.

Active incident?

Contact PierFerd CPT Immediately

Call 833-737-7444

Email cyber@pierferd.com

Active incident? • Contact PierFerd CPT Immediately • Call 833-737-7444 • Email cyber@pierferd.com •

01

Business Email Compromise

Time Critical | Preserve Evidence

Business email compromise is a social-engineering fraud that uses compromised, spoofed, or impersonated email communications to redirect payments or obtain sensitive information. When an actual mailbox is compromised, the incident may also create separate forensic, privacy, and notification issues.

02

Wire Fraud / Fraudulent Transfer

Time Critical

A fraudulent payment instruction succeeds and funds leave the account. From that moment, the recovery window narrows by the hour. Banks, law enforcement, and counsel each control a different lever, and the sequence in which an organization pulls them often determines whether the money comes back.

Engage Legal Counsel Early

Engage legal counsel promptly while time-sensitive recovery, containment, and evidence-preservation efforts proceed. Counsel can help coordinate the response, assess legal obligations, and structure sensitive communications to preserve applicable legal protections.

Primary Legal Issues

  • Potential civil liability to defrauded counterparties

  • Bank notification and fund recall timing

  • Regulatory exposure if client or trust funds were affected

  • Third-party liability if a vendor account was compromised

  • Notification obligations if mailbox contents included personal data

Immediate Priorities

  • Preserve all email chains; avoid deleting or archiving anything

  • Identify full scope: isolated event or ongoing access?

  • Contact the bank’s fraud department and legal counsel immediately and in parallel

  • Determine whether attacker access may still be active

  • Limit internal communications to those who need to know

Common Early Errors

  • Waiting to contact the bank or law enforcement while internal or legal review proceeds

  • Deleting or archiving affected email accounts

  • Assuming the fraudulent transaction is the only one

  • Broad internal announcements before scope is confirmed

  • Waiting until business hours if discovered after-hours


Educational only. For guidance specific to your situation, contact PierFerd CPT.

Financial Recovery Is Time Critical

If a fraudulent transfer was executed, act immediately. Recovery becomes more difficult with every passing hour. Contact the sending financial institution, legal counsel, and law enforcement promptly and begin the recall and recovery process.

Immediate Steps

  • Contact the bank’s fraud department and legal counsel immediately and in parallel

  • Preserve all wire instructions, emails, and authorizations

  • Identify the full scope: one transaction or a pattern?

  • Determine whether attacker access is ongoing

  • Document all discovered facts with precise timestamps

Common Early Errors

  • Delaying bank contact while internal or legal review proceeds

  • Deleting or archiving related emails

  • Assuming the fraudulent transaction is the only one

  • Broad internal announcements before scope is confirmed

  • Waiting until business hours if discovered off-hours

Recovery Notes

  • Wire recall success rates decline sharply after 24 hours

  • International transfers face additional recovery hurdles

  • FinCEN and law enforcement notification may be warranted

  • Document all recovery attempts and communications

  • Beware of follow-up fraud; scammers may pose as “recovery agents”

Wire Fraud Response Checklist • Maximize Recovery of Stolen Funds

View the Tool Here

1. Contact Your Bank

  • Notify your bank’s fraud department immediately and request a SWIFT recall or wire recall.

  • Ask the bank to initiate an immediate recall or reversal and provide any required indemnification or authorization documentation.

  • Request that your bank contact the recipient bank to freeze the fraudulent account.

  • Obtain written confirmation of your bank’s action (e.g., SWIFT recall message, email from fraud team).

2. Contact Law Enforcement

  • File a detailed complaint with the FBI’s Internet Crime Complaint Center (IC3) immediately. Depending on the transaction and available information, law enforcement may initiate additional asset-recovery measures, including the Financial Fraud Kill Chain process.

  • For significant or time-sensitive losses, contact the appropriate FBI field office in addition to filing with IC3.

  • If the FBI is not responsive, file a report with the Secret Service’s Cyber Fraud Task Force (CFTF) via your regional office.

  • Obtain a police report or case number for tracking purposes.

3. Contact the Recipient Bank Directly

  • Request the recipient bank’s fraud department to freeze the fraudulent account.

  • Provide proof of fraud (e.g., fraudulent invoice, email chain, wire details).

  • Request written confirmation of action taken by the recipient bank.

4. Notify Your Internal Teams

  • Alert finance and treasury teams to halt any further payments to the fraudulent account.

  • Alert IT and cybersecurity teams to check for email compromises.

  • Alert legal to assess next steps. PierFerd CPT: cyber@pierferd.com | 833-737-7444 (833-PF-SSHHH)

5. Escalate with Regulators if Necessary

  • If your bank is unresponsive, escalate to its primary regulator (e.g., OCC, FDIC, Federal Reserve, or CFPB).

  • If the recipient bank is non-cooperative, consider filing a complaint with foreign banking regulators if applicable.

Act within the first 24 to 72 hours. Document every step. Beware of follow-up fraud attempts; scammers may pose as recovery agents to further exploit the situation.


Wire fraud requires immediate action. Contact PierFerd CPT: cyber@pierferd.com | 833-737-7444

03

Ransomware & Cyber Extortion

Preserve Evidence First

A threat actor encrypts systems, steals data, or both, then demands payment. Operations stop while leadership faces decisions that carry legal, regulatory, and sanctions consequences. Many extortion events now pair encryption with threatened publication of stolen data, which changes the analysis entirely.

04

Data Breach / Notification Event

Notification Deadlines Multi-State Analysis

An unauthorized party accesses or acquires personal information. Notification obligations may attach quickly and run in parallel across many jurisdictions, each with its own deadlines, thresholds, and content requirements. The legal analysis must begin immediately, not after forensics concludes.

Critical: Preserve Before You Remediate

Remediation can alter or destroy important forensic evidence. Before significant restoration or remediation begins, coordinate with legal counsel and the forensic team to identify and preserve relevant evidence while addressing urgent operational needs.

Primary Legal Issues

  • Data exfiltration and notification exposure

  • OFAC and sanctions analysis before any payment

  • Board and executive reporting obligations

  • Sector- and entity-specific regulatory obligations, including HIPAA, GLBA, SEC requirements for public companies, and state regulatory requirements

  • Business interruption documentation begins now

Immediate Priorities

  • Isolate affected systems from the network immediately. Avoid powering them down unless you cannot isolate them or the forensic team directs otherwise

  • Engage legal counsel early and coordinate the forensic investigation through counsel where appropriate

  • Notify your insurer and confirm approved vendor panel

  • In many circumstances, do not pay without proper legal coordination

  • Establish secure out-of-band communications

Common Early Errors

  • Restoring from backups before forensics completes

  • Communicating about the incident on company systems

  • Assuming no data was exfiltrated because files are encrypted

  • Engaging vendors without insurer coordination

PierFerd CPT Tool

Cyber Extortion Payment Decision Tree

Work through this framework before making any extortion payment decision. Each step requires coordination with legal counsel. Educational only; not legal advice.

View the Tool Here


Educational only. Contact PierFerd CPT for situation-specific guidance.

Notification Deadlines May Already Be Running

In some jurisdictions, statutory notification deadlines may begin running from discovery or awareness of a breach, and those deadlines can run while forensic work continues. Begin the legal notification analysis early rather than waiting for the forensic investigation to conclude.

Primary Legal Issues

  • State breach notification across potentially 50+ jurisdictions

  • AG notification thresholds vary by state

  • HIPAA breach-notification safe harbor for PHI rendered unusable, unreadable, or indecipherable in accordance with HHS guidance

  • Sector-specific regulatory triggers (healthcare, finance)

  • Third-party class action exposure

Common Notification Triggers

  • Social Security numbers

  • Financial account numbers with access credentials

  • Medical and health information

  • Login credentials (email and password combinations)

  • Biometric identifiers

  • Government ID numbers

Common Early Errors

  • Waiting for forensics to complete before starting the legal analysis

  • Assuming notification applies in only one state

  • Notifying individuals before insurer coordination

  • Sending premature or inaccurate notifications

  • Failing to notify regulators where required


Educational only. Contact PierFerd CPT for situation-specific guidance.

05

Vendor / Supply Chain Breach

Independent Obligations

A vendor or service provider suffers an incident involving your data. Your organization may carry independent notification obligations even though the breach happened on someone else’s systems. The vendor’s timeline, analysis, and interests are not the same as yours.

06

Insider Misuse / Credential Abuse

Coordinate Legal First

An employee or contractor misuses legitimate access to take data, sabotage systems, or assist an outside actor. These events demand careful sequencing of legal, forensic, and HR steps. Moving against the individual too quickly destroys evidence and can create new exposure.

Your Obligations Are Independent of the Vendor’s

A breach at a vendor can trigger your own notification requirements even where the vendor handles its own notifications. If the vendor processed personal data on your behalf, you may carry independent obligations. Avoid assuming the vendor’s response subsumes yours.

Primary Legal Issues

  • Independent notification obligations as the data owner

  • Vendor contract terms: indemnification, cooperation rights

  • Data Processing Agreement obligations

  • HIPAA Business Associate Agreement obligations

Immediate Priorities

  • Obtain written breach notification from the vendor

  • Identify exactly what data the vendor held on your behalf

  • Pull the vendor contract and DPA immediately

  • Engage legal counsel before communicating further with the vendor

Common Early Errors

  • Relying entirely on the vendor's timeline and analysis

  • Failing to independently confirm what data was affected

  • Not preserving communications with the vendor

  • Delaying notice on the theory that “it was not our fault”


Educational only. Contact PierFerd CPT for situation-specific guidance.

Sequence Matters: Coordinate the Response

Insider incidents can create simultaneous employment, forensic, privacy, and legal issues. Coordinate counsel, HR, and forensic personnel before taking significant disciplinary or investigative action so that relevant evidence is preserved and additional exposure is avoided.

Primary Legal Issues

  • Potential CFAA and state computer-access claims, depending on the scope of the individual’s authorized access

  • Trade secret misappropriation (DTSA)

  • Notification obligations where data was taken

  • Employment law constraints on the investigation

A Coordinated Response May Include

  • Counsel engaged

  • Relevant devices and evidence preserved

  • Forensics engaged as appropriate

  • Access restricted or revoked

  • HR and employment counsel coordinated

  • Subject interview or other investigative steps considered

Common Early Errors

  • Terminating the employee before preserving devices

  • IT deleting access logs as routine "cleanup"

  • Confronting the subject before forensics completes

  • Assuming internal access requires no notification analysis


Educational only. Contact PierFerd CPT for situation-specific guidance.

First Response Guide

The First 72 Hours

A time-sequenced guide to the most critical window of any cyber incident.

This content is for general educational purposes and does not constitute legal advice or create an attorney-client relationship.