Itaca Technologies
Guide
2 min readUpdated

The first 24 hours: an incident checklist for Florida businesses

What to do, and what not to touch, between discovering a problem and knowing what it is.

I

Itaca Systems

Infrastructure, cloud & security team

Key takeaways

  • Two clocks may already be running before anyone has decided what happened: Florida's 30-day notification window, and the FTC Safeguards Rule for non-bank financial institutions.
  • Preserve first, restore second. Restoring feels like recovery and destroys the record.
  • Call the insurer before you change anything they might later call material.
  • Leading means deciding hour by hour what is cut, what is kept and who is told, and writing each decision down with the time.
  • Three cheap decisions made in advance change the whole day: out-of-band verification for payment instructions, same-day access closure on departure, and backups someone has tested.
On this page
  1. Who it's for
  2. What it covers
  3. Two clocks are already running
  4. What does the first day ask, and in what order?
  5. Why must you preserve before you restore?
  6. Which three decisions should you make before an incident happens?

Who it's for

Owners and managers of Florida businesses without a dedicated security team, who want the first day of an incident decided before it happens.

What it covers

  • How to cut access without destroying the evidence you will need.
  • Who to notify, in what order: insurer, counsel, and the clocks that may be running.
  • What to preserve before anyone restores anything.
  • How to decide who leads, and what “leading” means hour by hour.

Two clocks are already running

When a Florida business discovers a compromised inbox, a diverted payment, or encrypted files, two clocks may already be running. Florida's data protection statute gives you 30 days from determining a breach to notify affected residents. And if the business is a non-bank financial institution (a mortgage broker, a title company, an advisory firm), the FTC Safeguards Rule has required reporting certain incidents to the FTC since May 2024.

ClockWho it applies toWhat it requires
Florida data protection statuteAny Florida business that determines a breachNotify affected residents within 30 days
FTC Safeguards RuleNon-bank financial institutions: mortgage brokers, title companies, advisory firmsReport certain incidents to the FTC, since May 2024
The two clocks

What does the first day ask, and in what order?

The first 24 hours decide most of what follows.

DiscoverCut access, keepthe evidenceInsurer first, thencounselPreserve, thenrestoreOne person leads,and writes it downTwo clocks may already be runningFlorida data protection statute30 days from determining the breach to notify affected residentsFTC Safeguards RuleNon-bank financial institutions report certain incidents to the FTC, since May 2024
What the first day asks, in order, with the two clocks that may already be running.
  1. Cut access without destroying evidence: change credentials, close sessions, preserve the logs.
  2. Notify your insurer before you change anything they might later call material, and bring in counsel early. The two clocks above are legal questions, not technical ones.
  3. Preserve before anyone restores anything. What that means is in the next section.
  4. Name one person, out loud, who leads the response. Leading means deciding, hour by hour, what is cut, what is kept, and who is told, and writing each decision down with the time.

Why must you preserve before you restore?

The most expensive mistake we see is restoring systems before preserving evidence. It feels like recovery; it destroys the record that decides what you know, what you must notify, and what the insurer covers. Preserve first, restore second.

Which three decisions should you make before an incident happens?

What comes after (investigation, notification, recovery in a decided order) goes better for businesses that made three cheap decisions in advance: out-of-band verification for any payment instruction, same-day access closure when people leave, and backups that someone has tested. None of those requires a security team. All of them require a decision.

Questions readers ask

Florida's data protection statute gives 30 days from determining a breach to notify affected residents. Separately, a non-bank financial institution has been required since May 2024 to report certain incidents to the FTC under the Safeguards Rule.

Customer Success Team

Itaca Technologies

Your question isn't here?

Ask it as you'd ask it across the table. The team that does the work reads it and answers with a concrete next step.

Founded in 2011
No software resale
No vendor commissions