Skip to main content
The state of ai impact assessment
Third-Party Breach Response: Your 48-Hour ChecklistCyber Threats & Attacks
7 min readFor Incident Response Teams

Third-Party Breach Response: Your 48-Hour Checklist

When McKesson discovered unauthorized access to third-party applications on August 25, the clock started ticking. ShinyHunters set a September 1 deadline for ransom negotiations. That's just seven days to assess scope, notify stakeholders, and activate your incident response plan.

You won't get more warning. This checklist guides you through the critical first 48 hours after discovering a third-party application breach. Your decisions in this period determine whether you contain the damage or watch it spread across your supply chain.

What This Checklist Covers

This is your operational guide for the immediate aftermath of discovering a third-party application breach with data exfiltration. It focuses on containment, assessment, and stakeholder management before extortion threats go public.

This checklist doesn't cover pre-breach vendor risk management or long-term recovery. It's built for the compressed timeline between "we've been breached" and "the threat actor is making demands."

Prerequisites

Before executing this checklist, ensure you have:

  • Documented third-party application inventory with data flow maps showing what information each application processes, stores, or transmits.
  • Pre-negotiated incident response retainer with a breach coach who can provide legal privilege within the first hour.
  • Stakeholder contact tree including legal, executive leadership, affected business units, cyber insurance carrier, and regulatory counsel.
  • Access to system logs from the compromised application and any connected infrastructure for the past 90 days minimum.

If you're missing any of these, note it now. You'll work around the gaps, but you need to know where they are.

The 48-Hour Checklist

Hour 0-2: Immediate Containment and Legal Privilege

☐ Engage breach coach before any written communications
Contact your pre-retained Breach Coach immediately. Route all communications about the breach through them to establish attorney-client privilege. Don't send emails or document findings in Slack; everything goes through counsel first.
Good looks like: Your breach coach on a call within 60 minutes, establishing privilege over all investigation work.

☐ Isolate compromised third-party application access
Revoke API keys, disable SSO integration, or segment network access to the affected application. Don't assume the vendor has done this; you control your perimeter.
Good looks like: Network logs showing zero traffic between your environment and the compromised application within two hours of discovery.

☐ Identify the data classification of potentially exposed information
Pull your data flow map for this application. What categories of information did it process? Protected health information? Personally identifiable information? Employee records? Payment card data? Each category triggers different notification requirements.
Good looks like: A written list of data types with regulatory classification (PHI under HIPAA, Nonpublic Information under state breach laws, etc.) ready for legal review.

Hour 2-8: Scope Assessment

☐ Pull access logs from the compromised application
Request complete access logs from the vendor for the past 90 days. If they can't provide them immediately, document that refusal in writing through your breach coach. You need to know when unauthorized access started, not just when you discovered it.
Good looks like: Timestamped logs showing authentication events, data queries, and file transfers, with anomalies flagged for forensic review.

☐ Map affected business units to customer populations
If your breach involves specific divisions, identify which customer segments those units serve. This determines your notification scope.
Good looks like: A spreadsheet linking business unit codes to customer databases, with record counts for each potentially affected population.

☐ Notify your cyber insurance carrier
File your First Notice of Loss with your cyber insurer. Include what you know about the breach vector (third-party application), the data types involved, and your initial containment steps. If your policy includes Cyber Extortion Coverage, flag that now, before any ransom demand arrives.
Good looks like: FNOL submitted within eight hours, with your breach coach copied, and acknowledgment from your carrier's claims team.

☐ Activate your breach response panel providers
Most Stand-Alone Cyber Policies include pre-approved vendors for forensics, notification, and credit monitoring. Engage them now under your policy's Insurer Consent Requirement framework. Don't wait for the full scope assessment.
Good looks like: Forensic investigators accessing your logs by hour 10, and notification vendor on standby with templates ready.

Hour 8-24: Regulatory and Stakeholder Notification Planning

☐ Calculate breach notification deadlines by jurisdiction
Different states have different rules. HIPAA gives you 60 days for PHI breaches affecting fewer than 500 people, but some state laws require notification within 30 days or "without unreasonable delay." Your breach coach should build a deadline matrix based on your affected populations.
Good looks like: A calendar showing the earliest notification deadline you face, accounting for state laws, HIPAA, and any contractual obligations.

☐ Draft executive briefing on operational impact
Your CEO doesn't need forensic details. They need to know: Are services disrupted? Which customers are affected? What's our legal exposure? What's the cost projection? Keep it to one page.
Good looks like: A briefing deck with three slides, scope, impact, next steps, reviewed by legal before distribution.

☐ Review third-party contract for liability and indemnification
Pull your contract with the compromised vendor. What are their data security obligations? Do they carry cyber insurance? Is there an indemnification clause covering breaches? This determines whether you have cost recovery options.
Good looks like: Contract sections on data security, breach notification, and liability highlighted and summarized for your breach coach.

☐ Prepare holding statement for affected customers
You'll need to communicate before you have complete answers. Draft a statement confirming the incident, explaining what you're doing to investigate, and providing a contact point for questions. Run it through legal review.
Good looks like: A two-paragraph statement with no speculation about scope, no promises about timelines, and a dedicated email address for inquiries.

Hour 24-48: Extortion Threat Preparedness

☐ Document any ransom demands without responding
If you receive an extortion threat, preserve it exactly as received. Screenshot it, save headers, note the timestamp. Do not reply or negotiate. Hand it to your breach coach and your cyber insurer.
Good looks like: A forensic copy of the demand saved in a privileged legal folder, with chain of custody documented.

☐ Verify claims of data exfiltration
Threat actors lie. If they claim to have stolen specific record counts or data types, cross-reference against your logs and the vendor's access records. Can you confirm exfiltration actually occurred? How much data could they have accessed?
Good looks like: A forensic analysis comparing claimed data volumes against actual network transfer logs from your environment and the vendor's.

☐ Engage law enforcement through your breach coach
Your counsel should coordinate any FBI or Secret Service notification. Direct contact from your IT team can complicate legal strategy. Law enforcement involvement doesn't stop you from paying ransom if that's your decision, but it creates a record.
Good looks like: A law enforcement case number assigned, with all communication routed through your breach coach to preserve privilege.

☐ Confirm your cyber policy's extortion payment sublimit
Most policies cap Cyber Extortion Coverage at a sublimit well below the overall policy limit. Know that number now. If ShinyHunters is demanding amounts that exceed your coverage, you need to brief your CFO on the gap.
Good looks like: Your cyber policy declaration page with extortion sublimit highlighted, and a written confirmation from your broker on coverage terms.

Common Mistakes

Waiting for the vendor to investigate before acting. You don't control their timeline or their priorities. Start your own forensic review immediately, using whatever logs and access records you have.

Treating this as an IT problem instead of a legal one. Data breach response is a legal process with regulatory deadlines and privilege considerations. Your CISO doesn't run this, your breach coach does, with IT support.

Assuming "no systems disconnected" means no operational impact. McKesson emphasized that services weren't affected, but that's not the same as no impact. Customer trust, regulatory scrutiny, and notification costs are operational impacts even when systems stay online.

Negotiating with extortion groups without legal and insurance coordination. Paying ransom has sanctions implications (OFAC), tax implications (no deduction for illegal payments), and insurance implications (some policies require Insurer Consent before payment). Never negotiate alone.

Underestimating notification costs. Credit monitoring for hundreds of thousands of individuals runs into millions of dollars. If you're budgeting for this incident, assume $200-300 per affected individual for notification, monitoring, and call center support. Your Data Restoration Coverage won't cover that, you need separate breach response coverage.

Next Steps

Once you're past 48 hours, shift from containment to recovery. Your priorities:

  • Complete forensic investigation to establish timeline and full scope
  • Execute breach notification to affected individuals per your deadline matrix
  • File regulatory reports (HHS for HIPAA breaches, state attorneys general per state law)
  • Initiate vendor risk management review for all third-party applications with similar access
  • Document lessons learned for your cyber insurance renewal underwriting questionnaire

The McKesson breach involved third-party applications, the same vector that's compromised dozens of healthcare organizations in the past year. Your checklist for the next breach starts with the vendor risk work you do this month.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like