Incident Response for professional firms: what to do in the first 24 hours after a cyber attack
Summary
- The systemic vulnerability of professional firms in the current cyber landscape
- Threat types: from double extortion ransomware to transactional fraud
- Ransomware and preventive exfiltration of confidential documents
- Business Email Compromise
- The timeline of the first 24 hours: technical reaction operating protocol
- 0-2 hours: Isolation, containment and device management
- 2-6 AM: Technical investigation, scope, and credential rotation
- 6 AM - 12 PM: Containment verification, persistence, and remediation
- 12:00 - 24:00: Controlled restoration and institutional communications
- The regulatory and compliance framework: GDPR and NIS2, two plans not to be confused
- The data breach notification to the Data Protection Authority (Articles 33 and 34 GDPR)
- The NIS2 Directive and Supply Chain Management (Legislative Decree 138/2024)
- The five critical errors to absolutely avoid during incident response
- Business continuity and Lanpartners' integrated approach
- FAQ on Incident Response and cybersecurity
- What is meant by an Incident Response plan for a professional practice?
- Should you always turn off the computer when a cyber attack is suspected?
- How does the 72-hour period for notifying a data breach to the Italian Data Protection Authority (Garante Privacy) run?
- How does the NIS2 Directive impact a professional firm operating as a supplier?
- How does an immutable backup protect the firm from ransomware attacks?
- Request a Security Check-up and Vulnerability Assessment for your Studio
In this operational guide, we analyze in detail the response and management protocol for a cyber breach within law firms, notary offices, accounting firms, and tax consulting structures. The in-depth analysis examines the evolution of the cyber threat landscape and the specific vulnerability of professional firms, providing a technical timeline for the first twenty-four hours after the event to isolate the compromise and preserve forensic evidence. Regulatory compliance obligations are also clarified, distinguishing the obligation to notify the data breach to the Privacy Authority within 72 hours from the supply chain contractual requirements related to the transposition of the NIS2 Directive (Legislative Decree 138/2024), concluding with an analysis of the five operational errors to avoid, continuity strategies based on immutable backups, and a section of specific answers to the most frequently asked questions.
The systemic vulnerability of professional firms in the current cyber landscape
The complete digitalization of professional activities has profoundly transformed the daily operations of law firms, notary offices, accounting firms, and tax consultants. The management of the telematic civil process, cloud-based document archiving, the use of certified email, and document management systems have increased staff operational flexibility. At the same time, along with remote access to case files, they have multiplied the external vulnerability points. Consequently, professional firms are now one of the primary targets for cybercrime.
The motivation lies in the extremely high strategic value of the data processed. A single law firm holds confidential information on corporate acquisitions, pending litigation, patent disputes, and confidentiality agreements; notaries manage property transfers and deeds; accountants keep financial data and access credentials to tax portals. The breach of these databases generates significant economic consequences. But the most serious damage concerns the violation of the trust and professional secrecy that binds the professional to their clients. To understand the scope of these threats, you can consult our overview on advanced cybersecurity services for firms and businesses .
According to international analyses of the IBM Security Cost of a Data Breach Report , organizational preparedness and the adoption of structured Incident Response capabilities significantly reduce the time, costs, and overall impact of a breach. The extent of the benefit varies depending on technological maturity, detection speed, and attack type. However, a significant portion of professional firms still lack formalized procedures. As we highlighted in our review of risks of Shadow AI in law firms and protection of professional secrecy , the unregulated use of external tools and assistants exposes the network to unattended access channels, making the adoption of a rigorous and timely operational framework indispensable.
Threat types: from double extortion ransomware to transactional fraud
The evolution of attack techniques documented by the periodic reports of the ENISA (European Union Agency for Cybersecurity) highlight two primary risk vectors for professional firms:
Ransomware and preventive exfiltration of confidential documents
Modern ransomware attacks no longer just block systems through encryption, but operate according to the logic of double extortion. Attackers penetrate the infrastructure, can remain within the network for days or weeks (dwell time), and exfiltrate entire document archives. Only then do they activate the malware that makes servers inaccessible, threatening public disclosure or sale on the dark web of confidential files if the requested ransom is not paid.
Business Email Compromise
Through targeted spear phishing campaigns or the use of infostealer malware, attackers steal access credentials to the firm's email and certified email (PEC) accounts. Without altering the normal receipt of messages, they create silent forwarding rules to intercept communications related to real estate transactions, contract closures, or invoice payments, replacing legitimate IBAN codes with transit accounts managed by criminal networks.
The timeline of the first 24 hours: technical reaction operating protocol
The reaction in the first twenty-four hours after the incident discovery must follow a rigorous chronological scan, inspired by NIST incident response principles and our field experience, to neutralize the threat, preserve useful evidence, and initiate safe recovery:
0-2 hours: Isolation, containment and device management
The absolute priority is to contain the infection, avoiding destructive actions:
- Confirm the veracity of the incident through alarm correlation and the exclusion of false positives;
- Immediately activate the default response team (IT contacts, legal counsel, and firm management);
- Isolate compromised devices from the local network by disconnecting the ethernet cable and disabling Wi-Fi cards;
- Manage power in a targeted manner: do not automatically shut down compromised systems, but promptly involve the IT team or forensic specialists to assess whether to acquire volatile data residing in RAM or to stop the attack's execution to block its propagation;
- Logically and physically segregate backup units to prevent ransomware from reaching historical archives;
- Block, when technically reliable and without side effects, the indicators of compromise (IoCs) detected in outgoing traffic.
2-6 AM: Technical investigation, scope, and credential rotation
Once the initial perimeter is contained, technical analysis focuses on understanding the intrusion dynamics:
- Identify the initial entry vector (phishing, credentials stolen via infostealer, exposed VPN or RDP vulnerabilities);
- Perform coordinated revocation of active sessions and rotation of compromised or at-risk credentials, including privileged accounts, administrative accounts, and cloud environments, planning activities with the IT team to avoid compromising analysis and containment;
- Thoroughly inspect authentication logs, system logs, and network traffic to map the attacker's lateral movements;
- Preliminary assessment of the type of data involved (personal data, documentation related to judicial proceedings, financial details, or intellectual property).
6 AM - 12 PM: Containment verification, persistence, and remediation
In this phase, the effectiveness of containment is verified and the removal of root causes is initiated:
- Perform a thorough scan to check for attacker-installed persistence mechanisms (scheduled tasks, new service accounts, altered tokens, or web shells);
- Apply security patches and fix misconfigurations on the systems before proceeding with reconnection;
- Collect and preserve evidence in a documented manner: when necessary and technically possible, commission specialists to acquire forensic images or collect logs, audit trails, authentication events, and cloud configurations in compliance with the chain of custody;
- Prepare the internal communication for the studio's collaborators, providing clear instructions and prohibiting premature external communications.
12:00 - 24:00: Controlled restoration and institutional communications
The closure of the first twenty-four hours is oriented towards controlled recovery and the involvement of institutional stakeholders:
- Promptly activate the cyber insurance policy, requesting the assistance of surveyors and forensic specialists indicated or contracted by the company;
- Verify the integrity of backups and assess the possible presence of compromised files or configurations before initiating data recovery, starting from copies as close as possible to before the compromise and performing operations in an isolated environment with subsequent monitoring;
- Initiate the gradual and prioritized restoration of essential operational services in segregated and constantly monitored network environments;
- Formalize the technical minutes and share the evidentiary framework with the legal team for statutory compliance.
The regulatory and compliance framework: GDPR and NIS2, two plans not to be confused
A cyber incident may trigger different regulatory obligations that must be evaluated separately on a legal and contractual level.
The data breach notification to the Data Protection Authority (Articles 33 and 34 GDPR)
If the breach involves personal data and presents a risk to the rights and freedoms of natural persons, the data controller must notify the data breach to Data Protection Commissioner without undue delay and, where possible, within seventy-two hours of becoming aware of it. The deadline runs from the moment of awareness of the breach: it is not necessary to wait for the conclusion of the full technical investigation, as the initial notification can be validly supplemented later with the information subsequently acquired. It is essential to remember that any breach must be assessed and documented by the controller, indicating the circumstances, consequences, and measures taken, even when it is not notified to the Authority or communicated to the data subjects.
If the breach is likely to result in a high risk to the rights and freedoms of data subjects, Article 34 of the GDPR also provides for the obligation to inform the data subjects directly, barring specific legal exceptions (for example, if appropriate technical measures have been applied that render the data unintelligible to unauthorized persons, such as encryption, or when individual communication would involve disproportionate effort).
The NIS2 Directive and Supply Chain Management (Legislative Decree 138/2024)
The NIS2 regulations, transposed in Italy by Legislative Decree No. 138 of September 4, 2024, apply to entities that fall within the sectors and requirements set forth by national legislation, dividing them into essential and important entities. For such entities, an incident that meets the significance requirements established by the regulations can trigger a notification procedure consisting of an Early Warning within twenty-four hours to the CSIRT Italy and in a subsequent notification within seventy-two hours, in accordance with applicable procedures. NIS2 notifications must be submitted through the channels and procedures specified by ACN and CSIRT Italia (via the ACN Services Portal), always referring to the most recent version of the official instructions. Professional firms are not automatically subject to NIS2 simply because they provide services to companies subject to the directive.
However, as clarified by the ACN Guidelines on Supply Chain Security and explored in more detail in our guide on corporate cybersecurity and NIS2 requirements , law firms may be indirectly involved: clients subject to these regulations contractually require their legal and tax service providers to provide documented guarantees, security clauses, standardized incident management procedures, and prompt cooperation in the event of a security breach.
Knowing regulatory obligations is only half the job: equally important is avoiding operational errors that, in practice, compromise even the best-planned response.
The five critical errors to absolutely avoid during incident response
Field experience shows how procedural errors made during an emergency can turn a contained incident into a serious operational compromise. Here are five behaviors to categorically avoid:
- Immediately format or reinstall compromised systems, erasing the technical evidence essential for understanding the attack and documenting the firm's diligence;
- Assuming the incident is over as soon as the visible malware is blocked, neglecting to check for any backdoors or secondary accounts created by the attacker to regain access later;
- Disseminate premature or fragmented external communications to clients before having certainly verified the actual scope of the incident;
- Omit or delay the involvement of legal counsel and the insurance company in the very first hours after discovery;
- Initiate infrastructure restoration by blindly relying on backup copies not previously verified and scanned for latent infections.
Business continuity and Lanpartners' integrated approach
The effectiveness of the response rests on the quality of the preventive infrastructure. Lanpartners supports professional firms in designing resilient architectures that integrate immutable backup technology (Write Once, Read Many – WORM). This technology makes stored data unmodifiable and undeletable during the configured retention period, based on configured access policies. In the event of a ransomware attack, an immutable backup reduces reliance on ransom payment and significantly increases the ability to restore data safely, as illustrated in our Managed IT services for law firms and notary offices .
Lanpartners's security proposal combines detection and response tools to identify threats in real-time, continuous endpoint monitoring to detect anomalous behaviors before they escalate into incidents, vulnerability assessment to anticipate infrastructure weaknesses, advanced email protection against phishing and Business Email Compromise, and periodic cloud configuration checks to ensure document storage remains secure and compliant, with monitoring and support methods defined according to the activated service level.
The offering is completed by periodic phishing simulations to train staff and consulting to support the firm in defining and documenting security processes and controls consistent with the principles and controls of information security management systems according to ISO/IEC 27001, also leveraging the experience gained by Lanpartners as a certified company ( ISO/IEC 27001 Certification of Lanpartners ), allowing the firm to attest to the maturity and reliability of its security processes.
FAQ on Incident Response and cybersecurity
Note: The following guidelines are for general informational and operational purposes and do not replace the specific assessment of an IT, legal, or privacy professional on the concrete case.
What is meant by an Incident Response plan for a professional practice?
Incident Response is the structured set of technical, organizational, and legal procedures aimed at identifying, containing, neutralizing, and remedying a cybersecurity breach, minimizing downtime, data loss, and sanctioning risks.
Should you always turn off the computer when a cyber attack is suspected?
Not necessarily. The shutdown does not have to be automatic: the decision must be agreed upon with the IT team or forensic specialists, evaluating whether it is a priority to preserve volatile data in RAM to understand the attack or to immediately stop the device's activity to prevent further propagation.
How does the 72-hour period for notifying a data breach to the Italian Data Protection Authority (Garante Privacy) run?
The 72-hour period begins from the moment the controller becomes aware of the personal data breach that may result in a risk to the rights and freedoms of data subjects. It is not necessary to wait for the completion of the full technical investigation: the notification can be sent promptly and supplemented at a later stage with information subsequently acquired. All breaches must in any case be documented in the internal register detailing circumstances, consequences, and countermeasures.
How does the NIS2 Directive impact a professional firm operating as a supplier?
For entities falling within the scope of Legislative Decree 138/2024, an incident meeting the significance requirements set by the regulation may lead to a 24-hour pre-alarm to CSIRT Italia and a subsequent 72-hour notification. For a professional firm operating as a supplier, the direct obligation does not automatically arise from the contractual relationship; however, clients subject to NIS2 require documented guarantees, audits, and collaboration procedures in the event of a supply chain compromise.
How does an immutable backup protect the firm from ransomware attacks?
Immutable backup adopts technology that makes data unmodifiable and undeletable during the configured retention period. This prevents malware from altering backup copies, increasing recovery capability and reducing reliance on ransom payments.
Request a Security Check-up and Vulnerability Assessment for your Studio
Don't wait for an incident to jeopardize the confidentiality of your files and the continuity of your work. Lanpartners experts carry out a complete assessment of your IT infrastructure, analyzing perimeter vulnerabilities, backup system resilience, and team preparedness through controlled phishing tests. At the end of the assessment, you will receive a clear report with intervention priorities and concrete actions to implement. Book a confidential consultation today on our page Lanpartners Contact Information and protect your firm's fiduciary assets.