Skip to content

We had a data breach and must report it within 72 hours

Short answer

Three things run at once: stop the leak, preserve evidence before it disappears, and produce a report that satisfies the obligation. In Indonesia, a personal data breach must be reported within 72 hours, and administrative fines can reach 2% of annual revenue. We come in the same day, contain it, and stay until the report is filed.

Typical duration: Same-day response · containment in 24–72 hours

USD 750/day · emergency rate, three-day minimum

What this looks like

  • Company or customer data appears on a forum or is offered by a stranger
  • Unrecognised sign-in activity on critical systems
  • Files encrypted and a ransom note appears
  • Customers or media reach you before your own team knows
  • The internal team does not know where to start, and the clock is running

Why this happens

Breaches rarely begin with a sophisticated attack. Most often it is one account without a second factor, one piece of software left unpatched, or one access key stranded in a repository.

What usually makes things worse is not the attack but the first hours after it: evidence is destroyed because machines are rebooted in a hurry, logs roll over because storage is full, and decisions get made without anyone knowing exactly what data left.

How we solve it

  1. 01

    First call

    We engage the same day, map what is known and what is not, and set the order of actions.

  2. 02

    Containment

    Close the paths still open without destroying evidence — this order is what most teams get wrong.

  3. 03

    Evidence collection

    Logs, system images, and access traces preserved before they roll over.

  4. 04

    Scoping

    What data actually left, whose it was, and since when. This determines what the report says.

  5. 05

    Report & notification

    Prepare the filing for the 72-hour obligation and the notice to affected parties.

  6. 06

    Root cause

    Once things are calm, close the cause so it cannot repeat through the same path.

Numbers from our own work

  • Indonesia recorded 5.5 billion cyber attacks through 2025 — a 714% rise over the previous five-year average

  • Data leakage is the most frequently observed incident type

  • 49 of our 54 engagements are security work, including post-incident handling

Mistakes we keep seeing

  • Rebooting or wiping machines first — evidence disappears and the scope becomes impossible to establish
  • Announcing before the scope is known, then having to correct it in public
  • Waiting for full certainty past the 72-hour mark, when an initial filing can be updated later
  • Closing one entry point and assuming it is over, when attackers usually leave a spare

Questions we are asked most

We are not sure this is really a breach. Should we still call?

Yes. Confirming it is not a breach is far cheaper than confirming it too late. The initial check is short and does not disrupt operations.

How fast can your team engage?

Same day for remote triage. The first hours decide whether the evidence can still be saved.

Are we obliged to notify our customers?

It depends on what data left and whose it was. That scope is what we establish first, because it determines your obligation.

Can this work be kept confidential?

A confidentiality agreement applies from the first conversation, before anything else is signed.

What do we get when it is over?

An incident report, remediation evidence, a defensible timeline, and the steps that close the same path for good.

Updated 29 July 2026 · Neuraltan

If this is happening to you

Tell us the situation. We will say plainly whether this is worth doing now, and how long it takes.