The 72-hour clock
When a cyber incident affects a covered contractor information system or the CUI on it, you are required to conduct a review, and to rapidly report to the DoD via DIBNet within 72 hours of discovery. Reporting requires a medium assurance certificate, which takes time to obtain, so the moment to arrange it is emphatically not during an incident.
You are also obliged to preserve and protect images of affected systems and relevant monitoring data for at least 90 days, and to support DoD damage assessment activity if requested. Contractors who wipe and rebuild immediately to restore operations frequently destroy exactly what they were required to keep.
- Report to DIBNet within 72 hours of discovery
- Preserve system images and monitoring data for at least 90 days
- Flow the same obligation down to your subcontractors
- Notify your prime as your contract requires, often faster than 72 hours
A plan that has been used before it is needed
An incident response plan sitting unread in a folder is a compliance artifact, not a capability. We write plans that assign real names to real roles, define severity thresholds, and specify decision authority: who can take production offline, who calls the lawyers, who talks to the prime, who talks to staff.
Then we exercise it. An annual tabletop is explicitly expected under the requirements, and it is also the cheapest way to discover that your only backup admin left the company or that nobody knows where the DIBNet credentials are.
- Defined roles, contact tree, and out-of-band communication method
- Severity classification and escalation thresholds
- Decision authority for containment actions that interrupt operations
- Legal, insurance, prime, and law-enforcement notification paths
- Evidence preservation procedures written for non-forensics staff
Live response
When something real happens, our security operations team moves immediately: contain the affected systems, preserve evidence before it is lost, establish what was accessed, and work the recovery. In parallel, we help you assemble the facts the 72-hour report requires and coordinate with your legal counsel and cyber insurer.
Afterwards, we run the post-incident review and turn what you learned into control changes, which is also what the requirements expect you to be able to demonstrate.
