We had a data breach and must report it within 72 hours
Short answer
Three things run at once: stop the leak, preserve evidence before it disappears, and produce a report that satisfies the obligation. In Indonesia, a personal data breach must be reported within 72 hours, and administrative fines can reach 2% of annual revenue. We come in the same day, contain it, and stay until the report is filed.
Typical duration: Same-day response · containment in 24–72 hours
USD 750/day · emergency rate, three-day minimum
What this looks like
- Company or customer data appears on a forum or is offered by a stranger
- Unrecognised sign-in activity on critical systems
- Files encrypted and a ransom note appears
- Customers or media reach you before your own team knows
- The internal team does not know where to start, and the clock is running
Why this happens
Breaches rarely begin with a sophisticated attack. Most often it is one account without a second factor, one piece of software left unpatched, or one access key stranded in a repository.
What usually makes things worse is not the attack but the first hours after it: evidence is destroyed because machines are rebooted in a hurry, logs roll over because storage is full, and decisions get made without anyone knowing exactly what data left.
How we solve it
- 01
First call
We engage the same day, map what is known and what is not, and set the order of actions.
- 02
Containment
Close the paths still open without destroying evidence — this order is what most teams get wrong.
- 03
Evidence collection
Logs, system images, and access traces preserved before they roll over.
- 04
Scoping
What data actually left, whose it was, and since when. This determines what the report says.
- 05
Report & notification
Prepare the filing for the 72-hour obligation and the notice to affected parties.
- 06
Root cause
Once things are calm, close the cause so it cannot repeat through the same path.
Numbers from our own work
Indonesia recorded 5.5 billion cyber attacks through 2025 — a 714% rise over the previous five-year average
Data leakage is the most frequently observed incident type
49 of our 54 engagements are security work, including post-incident handling
Mistakes we keep seeing
- Rebooting or wiping machines first — evidence disappears and the scope becomes impossible to establish
- Announcing before the scope is known, then having to correct it in public
- Waiting for full certainty past the 72-hour mark, when an initial filing can be updated later
- Closing one entry point and assuming it is over, when attackers usually leave a spare
Questions we are asked most
We are not sure this is really a breach. Should we still call?
Yes. Confirming it is not a breach is far cheaper than confirming it too late. The initial check is short and does not disrupt operations.
How fast can your team engage?
Same day for remote triage. The first hours decide whether the evidence can still be saved.
Are we obliged to notify our customers?
It depends on what data left and whose it was. That scope is what we establish first, because it determines your obligation.
Can this work be kept confidential?
A confidentiality agreement applies from the first conversation, before anything else is signed.
What do we get when it is over?
An incident report, remediation evidence, a defensible timeline, and the steps that close the same path for good.
Updated 29 July 2026 · Neuraltan
If this is happening to you
Tell us the situation. We will say plainly whether this is worth doing now, and how long it takes.