Skip to main content

Playbook: Breach Response

Business-Critical

Suspect card data got out? The next 72 hours decide whether this is a manageable incident or the end of your business. Move now.

TL;DR
  • Hour 0-4: contain it, preserve evidence, call your processor by phone rather than email
  • Hour 4-24: engage a PCI Forensic Investigator, notify your acquirer formally
  • Day 1-3: card brand notification through the acquirer, legal review, scope assessment
  • Week 1-4: full investigation, remediation, re-certification
  • Silence isn't an option. Mastercard and Amex want 24 hours, Discover 48, Visa 3 days.

The clock starts when you suspect a breach, not when you confirm it.

Workflow Overview

PhaseKey Actions
ContainStop the bleeding, preserve evidence, contact processor
NotifyEngage PFI, formal notifications to acquirer and brands
InvestigateScope assessment, forensic analysis, affected card identification
RemediateFix vulnerabilities, re-certify, handle fines and liabilities
Have these on hand before you need them
  • Your processor's emergency contact number
  • Your acquirer's breach notification requirements
  • Your cyber liability policy number, if you carry one
  • Who in the building can sign off on an external vendor at 2am

When to Use This Playbook

Start this playbook when you see:

SignalUrgency
Confirmed malware on payment systemsImmediate
Anomalous outbound data transfers from POS/e-commerceImmediate
Card brand notification of fraud clusterImmediate
Suspicious files in payment environmentHigh
Unusual database queries on card dataHigh
Third-party breach affecting your dataHigh
Ransomware attack on any systemsHigh

When in doubt, assume breach and start the clock.


Hour 0-4: Contain

Stop the Bleeding (First 30 Minutes)

□ Isolate affected systems (don't turn off - preserve evidence)
□ Disconnect payment systems from network (if actively exfiltrating)
□ Block suspicious IPs/connections at firewall
□ Change all administrative passwords (payment systems, databases)
□ Disable compromised user accounts
Don't
  • Don't wipe systems - you'll destroy the forensic evidence
  • Don't reboot servers - volatile memory is holding evidence
  • Don't try to fix it yourself - you may still need a PFI
  • Don't discuss it on email or Slack - assume the attacker is reading

Preserve Evidence (Hour 1)

□ Take memory dumps of affected systems (if capable)
□ Capture full disk images before any changes
□ Export firewall and network logs (last 90 days minimum)
□ Export database query logs
□ Screenshot any suspicious activity
□ Document timeline: when discovered, by whom, initial observations

Call Your Processor (Hour 1-2)

Call, don't email. Email is too slow and may be compromised.

What to say:

"We have a suspected data security incident affecting our payment environment. We're in containment mode and need to initiate your breach response process."

Ask:

  1. Who is my incident response contact?
  2. What's the formal notification process?
  3. Do you have a preferred PCI Forensic Investigator (PFI)?
  4. What are my immediate obligations?

Assemble Response Team (Hour 2-4)

RoleResponsibility
Incident CommanderSingle decision maker, coordinates response
IT/Security LeadTechnical containment and evidence preservation
LegalNotification requirements, liability, communications
FinanceReserve funds for PFI, fines, customer notification
CommunicationsInternal and external messaging (if required)
Vendor ContactPoint person for processor, PFI, insurance

Hour 4-24: Notify

Engage a PCI Forensic Investigator (PFI)

You'll need one for most breaches. The PCI SSC certifies them to investigate card data.

When you're required to bring one in:

  • Your card brand or acquirer asks for one
  • More than 10,000 cards may have been exposed
  • Malware turned up on your payment systems
  • A Common Point of Purchase has been identified

How to find one:

  1. Ask your processor or acquirer for their preferred list
  2. Check PCI SSC's list of approved PFIs
  3. Your cyber insurance may have a panel of approved investigators

Expect to pay: $20,000-$100,000+ depending on scope and urgency.

Formal Acquirer Notification (Hour 8-12)

You have to notify your acquirer formally. That's the bank behind your merchant account.

□ Written notification (email + certified letter)
□ Include: Date discovered, initial scope estimate, containment steps taken
□ Request: Confirmation of receipt, next steps, timeline requirements
□ Ask: Card brand notification requirements and process

Card Brand Notifications (Hour 12-24)

The brands run hard notification windows. Your acquirer usually does the talking, and you feed them the facts.

NetworkNotification WindowKey Requirements
VisaWithin 3 calendar days of discoveryAccount Data Compromise (ADC) process
MastercardWithin 24 hoursAccount Data Compromise (ADC) process
AmexWithin 24 hoursDirect notification (separate from Visa/MC)
DiscoverWithin 48 hoursSeparate process from other networks

Document Everything

□ Create incident log (timestamped actions and decisions)
□ Record all phone calls (date, time, who, summary)
□ Save all emails related to incident
□ Document any evidence collected
□ Track hours spent (for insurance claims)

Day 1-3: Investigate

PFI Initial Assessment

The PFI will:

□ Deploy forensic tools on affected systems
□ Analyze malware (if present)
□ Determine entry point and attack timeline
□ Identify systems with card data access
□ Estimate date range of exposure
□ Begin card number identification

Scope Assessment

Work out:

QuestionImpact
How many cards exposed?Determines reissuance liability
What data elements?PAN only vs. PAN + CVV vs. track data
Date range of exposure?Card brand operational costs
How did attacker get in?Remediation requirements
Is attack ongoing?Containment priority
□ Identify applicable breach notification laws (by state/country)
□ Determine customer notification timeline requirements
□ Review contracts with partners/vendors for notification requirements
□ Assess regulatory reporting obligations (if any)
□ Review cyber insurance policy coverage and notification requirements

Internal Communication

What to tell employees:

  • The incident is under investigation right now
  • Don't discuss it outside the company at all
  • Send every inquiry to the named spokesperson
  • Cooperate fully with the investigators
  • Preserve anything that might turn out to be evidence

Week 1-4: Remediate

Fix the Vulnerabilities

Based on PFI findings, you'll need to address root causes:

FindingTypical Remediation
Malware on POSClean rebuild, endpoint protection, network segmentation
Unpatched systemsPatch management program, vulnerability scanning
Weak credentialsPassword policy, MFA implementation
No network segmentationSegment payment systems, firewall rules
Third-party compromiseVendor security review, access restrictions

Re-Certification

After remediation, you may need:

□ PCI DSS re-assessment (if Level 1 or required by acquirer)
□ New SAQ completion (for smaller merchants)
□ Vulnerability scan by Approved Scanning Vendor (ASV)
□ Penetration test (if required)
□ Remediation validation by PFI

Handle Fines and Liabilities

Potential costs:

Cost CategoryTypical Range
PFI investigation$15,000-$100,000+
Card reissuance$3-$10 per card reissued
Operational costsVariable (fraud monitoring by networks)
Non-compliance fines$5,000-$100,000+
Customer notification$1-$5 per customer
Credit monitoring$10-$30 per affected customer/year
Legal feesVariable
Increased processing ratesPotential 0.5-2% increase

Customer Notification (If Required)

If notification is required by law or contract:

□ Draft notification letter (legal review)
□ Prepare FAQ for customer inquiries
□ Set up dedicated phone line or email
□ Offer credit monitoring if appropriate
□ Document all notifications sent

Post-Incident: Recovery

Return to Normal Processing

□ Get written clearance from acquirer
□ Confirm PFI has closed investigation
□ Resume full processing (may be phased)
□ Monitor for any attack resumption
□ Verify reserves/holds are released on schedule

Lessons Learned

Within 30 days of resolution:

□ Conduct post-incident review
□ Document what worked and what didn't
□ Identify control gaps that allowed breach
□ Create action plan for improvements
□ Update incident response procedures
□ Train staff on new controls

Long-Term Improvements

What to fix for next time:

AreaTypical Improvements
DetectionLog monitoring, SIEM, intrusion detection
PreventionNetwork segmentation, endpoint protection, access controls
ResponseUpdated playbooks, regular drills, vendor relationships
ComplianceRegular assessments, continuous compliance monitoring

Cost Planning Template

Use this to estimate breach costs:

Breach Cost Estimate
--------------------

Investigation:
PFI engagement: $_________
Internal labor (hours x rate): $_________
External legal: $_________

Card Brand Assessments:
Cards exposed: _________
Estimated reissuance: $_________ (cards x $5 avg)
Operational costs: $_________ (from network)

Fines:
Non-compliance fines: $_________
Late notification fines: $_________

Customer Costs:
Customers affected: _________
Notification costs: $_________
Credit monitoring: $_________
Customer compensation: $_________

Recovery:
Remediation: $_________
Re-certification: $_________
Increased rates: $_________/year

TOTAL ESTIMATED COST: $_________

When to Get a Lawyer

Call a lawyer today if:

  • The breach may touch more than 10,000 records
  • You operate across states or countries, so notification law gets messy
  • The attackers are demanding a ransom
  • You carry cyber insurance. The policy may name your counsel for you
  • Regulatory obligations apply, like HIPAA or SOX
  • Third-party data was caught in it
  • Litigation looks likely

Quick Reference: Key Deadlines

DeadlineRequirement
ImmediateContain and preserve evidence
24 hoursNotify acquirer and card brands
State-specificCustomer notification (varies by state: 30-90 days typical)
30 daysBegin PFI investigation
90 daysComplete remediation (typical)
VariesRe-certification (depends on level and scope)

Emergency Contacts Template

Fill in for your organization:

RoleNamePhoneEmail
Incident Commander
IT/Security Lead
Legal
Processor Emergency Line
Acquirer Contact
Cyber Insurance Broker
PFI (pre-selected)

Test to Run

Breach response drill (quarterly):

Run a tabletop exercise:

  1. Scenario: "We found unknown files on our payment server, and customers are reporting fraudulent charges."
  2. Walk through first 4 hours of this playbook
  3. Identify the gaps. Who didn't know their role, and what contact info was missing?
  4. Update the playbook and the contact list from what you found

Success criteria: Team can execute first 4 hours without confusion about roles or contacts.