WARTIME
When Something Goes Wrong
The decisions made in the first hours of a cyber incident shape everything that follows. Select an incident type below for immediate priorities, common early errors, and interactive response tools.
Active incident?
•
Contact PierFerd CPT Immediately
•
Call 833-737-7444
•
Email cyber@pierferd.com
•
Active incident? • Contact PierFerd CPT Immediately • Call 833-737-7444 • Email cyber@pierferd.com •
01
Business Email Compromise
Time Critical | Preserve Evidence
Business email compromise is a social-engineering fraud that uses compromised, spoofed, or impersonated email communications to redirect payments or obtain sensitive information. When an actual mailbox is compromised, the incident may also create separate forensic, privacy, and notification issues.
02
Wire Fraud / Fraudulent Transfer
Time Critical
A fraudulent payment instruction succeeds and funds leave the account. From that moment, the recovery window narrows by the hour. Banks, law enforcement, and counsel each control a different lever, and the sequence in which an organization pulls them often determines whether the money comes back.
Engage Legal Counsel Early
Engage legal counsel promptly while time-sensitive recovery, containment, and evidence-preservation efforts proceed. Counsel can help coordinate the response, assess legal obligations, and structure sensitive communications to preserve applicable legal protections.
Primary Legal Issues
Potential civil liability to defrauded counterparties
Bank notification and fund recall timing
Regulatory exposure if client or trust funds were affected
Third-party liability if a vendor account was compromised
Notification obligations if mailbox contents included personal data
Immediate Priorities
Preserve all email chains; avoid deleting or archiving anything
Identify full scope: isolated event or ongoing access?
Contact the bank’s fraud department and legal counsel immediately and in parallel
Determine whether attacker access may still be active
Limit internal communications to those who need to know
Common Early Errors
Waiting to contact the bank or law enforcement while internal or legal review proceeds
Deleting or archiving affected email accounts
Assuming the fraudulent transaction is the only one
Broad internal announcements before scope is confirmed
Waiting until business hours if discovered after-hours
Educational only. For guidance specific to your situation, contact PierFerd CPT.
Financial Recovery Is Time Critical
If a fraudulent transfer was executed, act immediately. Recovery becomes more difficult with every passing hour. Contact the sending financial institution, legal counsel, and law enforcement promptly and begin the recall and recovery process.
Immediate Steps
Contact the bank’s fraud department and legal counsel immediately and in parallel
Preserve all wire instructions, emails, and authorizations
Identify the full scope: one transaction or a pattern?
Determine whether attacker access is ongoing
Document all discovered facts with precise timestamps
Common Early Errors
Delaying bank contact while internal or legal review proceeds
Deleting or archiving related emails
Assuming the fraudulent transaction is the only one
Broad internal announcements before scope is confirmed
Waiting until business hours if discovered off-hours
Recovery Notes
Wire recall success rates decline sharply after 24 hours
International transfers face additional recovery hurdles
FinCEN and law enforcement notification may be warranted
Document all recovery attempts and communications
Beware of follow-up fraud; scammers may pose as “recovery agents”
Wire Fraud Response Checklist • Maximize Recovery of Stolen Funds
1. Contact Your Bank
Notify your bank’s fraud department immediately and request a SWIFT recall or wire recall.
Ask the bank to initiate an immediate recall or reversal and provide any required indemnification or authorization documentation.
Request that your bank contact the recipient bank to freeze the fraudulent account.
Obtain written confirmation of your bank’s action (e.g., SWIFT recall message, email from fraud team).
2. Contact Law Enforcement
File a detailed complaint with the FBI’s Internet Crime Complaint Center (IC3) immediately. Depending on the transaction and available information, law enforcement may initiate additional asset-recovery measures, including the Financial Fraud Kill Chain process.
For significant or time-sensitive losses, contact the appropriate FBI field office in addition to filing with IC3.
If the FBI is not responsive, file a report with the Secret Service’s Cyber Fraud Task Force (CFTF) via your regional office.
Obtain a police report or case number for tracking purposes.
3. Contact the Recipient Bank Directly
Request the recipient bank’s fraud department to freeze the fraudulent account.
Provide proof of fraud (e.g., fraudulent invoice, email chain, wire details).
Request written confirmation of action taken by the recipient bank.
4. Notify Your Internal Teams
Alert finance and treasury teams to halt any further payments to the fraudulent account.
Alert IT and cybersecurity teams to check for email compromises.
Alert legal to assess next steps. PierFerd CPT: cyber@pierferd.com | 833-737-7444 (833-PF-SSHHH)
5. Escalate with Regulators if Necessary
If your bank is unresponsive, escalate to its primary regulator (e.g., OCC, FDIC, Federal Reserve, or CFPB).
If the recipient bank is non-cooperative, consider filing a complaint with foreign banking regulators if applicable.
Act within the first 24 to 72 hours. Document every step. Beware of follow-up fraud attempts; scammers may pose as recovery agents to further exploit the situation.
Wire fraud requires immediate action. Contact PierFerd CPT: cyber@pierferd.com | 833-737-7444
03
Ransomware & Cyber Extortion
Preserve Evidence First
A threat actor encrypts systems, steals data, or both, then demands payment. Operations stop while leadership faces decisions that carry legal, regulatory, and sanctions consequences. Many extortion events now pair encryption with threatened publication of stolen data, which changes the analysis entirely.
04
Data Breach / Notification Event
Notification Deadlines Multi-State Analysis
An unauthorized party accesses or acquires personal information. Notification obligations may attach quickly and run in parallel across many jurisdictions, each with its own deadlines, thresholds, and content requirements. The legal analysis must begin immediately, not after forensics concludes.
Critical: Preserve Before You Remediate
Remediation can alter or destroy important forensic evidence. Before significant restoration or remediation begins, coordinate with legal counsel and the forensic team to identify and preserve relevant evidence while addressing urgent operational needs.
Primary Legal Issues
Data exfiltration and notification exposure
OFAC and sanctions analysis before any payment
Board and executive reporting obligations
Sector- and entity-specific regulatory obligations, including HIPAA, GLBA, SEC requirements for public companies, and state regulatory requirements
Business interruption documentation begins now
Immediate Priorities
Isolate affected systems from the network immediately. Avoid powering them down unless you cannot isolate them or the forensic team directs otherwise
Engage legal counsel early and coordinate the forensic investigation through counsel where appropriate
Notify your insurer and confirm approved vendor panel
In many circumstances, do not pay without proper legal coordination
Establish secure out-of-band communications
Common Early Errors
Restoring from backups before forensics completes
Communicating about the incident on company systems
Assuming no data was exfiltrated because files are encrypted
Engaging vendors without insurer coordination
PierFerd CPT Tool
Cyber Extortion Payment Decision Tree
Work through this framework before making any extortion payment decision. Each step requires coordination with legal counsel. Educational only; not legal advice.
Educational only. Contact PierFerd CPT for situation-specific guidance.
Notification Deadlines May Already Be Running
In some jurisdictions, statutory notification deadlines may begin running from discovery or awareness of a breach, and those deadlines can run while forensic work continues. Begin the legal notification analysis early rather than waiting for the forensic investigation to conclude.
Primary Legal Issues
State breach notification across potentially 50+ jurisdictions
AG notification thresholds vary by state
HIPAA breach-notification safe harbor for PHI rendered unusable, unreadable, or indecipherable in accordance with HHS guidance
Sector-specific regulatory triggers (healthcare, finance)
Third-party class action exposure
Common Notification Triggers
Social Security numbers
Financial account numbers with access credentials
Medical and health information
Login credentials (email and password combinations)
Biometric identifiers
Government ID numbers
Common Early Errors
Waiting for forensics to complete before starting the legal analysis
Assuming notification applies in only one state
Notifying individuals before insurer coordination
Sending premature or inaccurate notifications
Failing to notify regulators where required
Educational only. Contact PierFerd CPT for situation-specific guidance.
05
Vendor / Supply Chain Breach
Independent Obligations
A vendor or service provider suffers an incident involving your data. Your organization may carry independent notification obligations even though the breach happened on someone else’s systems. The vendor’s timeline, analysis, and interests are not the same as yours.
06
Insider Misuse / Credential Abuse
Coordinate Legal First
An employee or contractor misuses legitimate access to take data, sabotage systems, or assist an outside actor. These events demand careful sequencing of legal, forensic, and HR steps. Moving against the individual too quickly destroys evidence and can create new exposure.
Your Obligations Are Independent of the Vendor’s
A breach at a vendor can trigger your own notification requirements even where the vendor handles its own notifications. If the vendor processed personal data on your behalf, you may carry independent obligations. Avoid assuming the vendor’s response subsumes yours.
Primary Legal Issues
Independent notification obligations as the data owner
Vendor contract terms: indemnification, cooperation rights
Data Processing Agreement obligations
HIPAA Business Associate Agreement obligations
Immediate Priorities
Obtain written breach notification from the vendor
Identify exactly what data the vendor held on your behalf
Pull the vendor contract and DPA immediately
Engage legal counsel before communicating further with the vendor
Common Early Errors
Relying entirely on the vendor's timeline and analysis
Failing to independently confirm what data was affected
Not preserving communications with the vendor
Delaying notice on the theory that “it was not our fault”
Educational only. Contact PierFerd CPT for situation-specific guidance.
Sequence Matters: Coordinate the Response
Insider incidents can create simultaneous employment, forensic, privacy, and legal issues. Coordinate counsel, HR, and forensic personnel before taking significant disciplinary or investigative action so that relevant evidence is preserved and additional exposure is avoided.
Primary Legal Issues
Potential CFAA and state computer-access claims, depending on the scope of the individual’s authorized access
Trade secret misappropriation (DTSA)
Notification obligations where data was taken
Employment law constraints on the investigation
A Coordinated Response May Include
Counsel engaged
Relevant devices and evidence preserved
Forensics engaged as appropriate
Access restricted or revoked
HR and employment counsel coordinated
Subject interview or other investigative steps considered
Common Early Errors
Terminating the employee before preserving devices
IT deleting access logs as routine "cleanup"
Confronting the subject before forensics completes
Assuming internal access requires no notification analysis
Educational only. Contact PierFerd CPT for situation-specific guidance.
First Response Guide
The First 72 Hours
A time-sequenced guide to the most critical window of any cyber incident.
-
The Most Common Unforced Error
Beginning significant remediation before the incident has been properly scoped and relevant evidence preserved. Engage counsel and forensics early while urgent containment measures proceed.
Containment & Preservation
Technical
Isolate affected systems; do not power them off (powered-off systems lose volatile memory evidence)Legal
Avoid deleting, altering, or archiving any affected systems, accounts, or emailLegal
Engage legal counsel early to coordinate the legal response and structure sensitive incident communicationsTechnical
Establish an out-of-band communication channel; assume company systems may be compromisedLegal
Begin a written decision log; document every action with date, time, person, and rationaleBusiness
Limit internal communications strictly to those who need to knowLegal
Avoid communicating directly with a threat actor unless coordinated through experienced counsel and appropriate incident-response professionals -
Engagement Sequencing
Legal
Formalize outside counsel's role and establish the legal incident-response workstreamBusiness
Notify your cyber insurer if applicable and confirm any applicable panel or consent requirements. Coordinate the forensic engagement through counsel where appropriate to support the legal investigation and preserve applicable protectionsTechnical
Conduct an initial scope assessment: what systems, what data, what time windowBusiness
Prepare an executive briefing using confirmed facts, clearly identify unknowns, avoid speculation, and coordinate legal review as appropriateBusiness
Begin business interruption documentation; track losses from day one -
Notification Analysis & Governance
Legal
Begin or continue the formal notification analysis with counsel: affected individuals, applicable jurisdictions, regulators, contractual obligations, and relevant deadlinesLegal
Calendar all applicable notification deadlines immediatelyLegal
Review all third-party contractual notification obligationsBusiness
Prepare a board or audit committee briefing with counsel’s inputLegal
Review and document all decisions in the decision log; this record will be scrutinized later
This content is for general educational purposes and does not constitute legal advice or create an attorney-client relationship.