Skip to content

When it goes wrong

Incident Response & DFARS 72-Hour Reporting

DFARS 252.204-7012 gives you 72 hours from discovery to report a cyber incident to the Department of Defense. Not 72 hours to finish the investigation, just 72 hours to report. Companies without a plan spend the first two days deciding who is in charge.
  • Written, role-assigned incident response plan
  • Annual tabletop exercises with documented findings
  • Containment, eradication, and recovery support
  • DIBNet reporting and evidence preservation guidance
Close-up of circuitry representing digital forensics and incident investigation

The 72-hour clock

When a cyber incident affects a covered contractor information system or the CUI on it, you are required to conduct a review, and to rapidly report to the DoD via DIBNet within 72 hours of discovery. Reporting requires a medium assurance certificate, which takes time to obtain, so the moment to arrange it is emphatically not during an incident.

You are also obliged to preserve and protect images of affected systems and relevant monitoring data for at least 90 days, and to support DoD damage assessment activity if requested. Contractors who wipe and rebuild immediately to restore operations frequently destroy exactly what they were required to keep.

  • Report to DIBNet within 72 hours of discovery
  • Preserve system images and monitoring data for at least 90 days
  • Flow the same obligation down to your subcontractors
  • Notify your prime as your contract requires, often faster than 72 hours

A plan that has been used before it is needed

An incident response plan sitting unread in a folder is a compliance artifact, not a capability. We write plans that assign real names to real roles, define severity thresholds, and specify decision authority: who can take production offline, who calls the lawyers, who talks to the prime, who talks to staff.

Then we exercise it. An annual tabletop is explicitly expected under the requirements, and it is also the cheapest way to discover that your only backup admin left the company or that nobody knows where the DIBNet credentials are.

  • Defined roles, contact tree, and out-of-band communication method
  • Severity classification and escalation thresholds
  • Decision authority for containment actions that interrupt operations
  • Legal, insurance, prime, and law-enforcement notification paths
  • Evidence preservation procedures written for non-forensics staff

Live response

When something real happens, our security operations team moves immediately: contain the affected systems, preserve evidence before it is lost, establish what was accessed, and work the recovery. In parallel, we help you assemble the facts the 72-hour report requires and coordinate with your legal counsel and cyber insurer.

Afterwards, we run the post-incident review and turn what you learned into control changes, which is also what the requirements expect you to be able to demonstrate.

What you get

Concrete deliverables, not a slide deck

Every engagement produces artefacts you own, that live in your environment, and that an assessor can read.

  • 01

    Incident response plan

    Roles, severity model, decision authority, communications, and step-by-step procedures.

  • 02

    Annual tabletop exercise

    A facilitated scenario with your leadership and technical staff, plus a documented after-action report.

  • 03

    Reporting readiness

    Medium assurance certificate guidance, DIBNet registration prepared in advance, and report templates ready to fill.

  • 04

    Evidence preservation runbook

    What to capture, how to capture it, and what not to touch, written for the people who will actually be in the room.

  • 05

    Post-incident review

    Root cause, timeline, control failures, and a remediation plan that feeds back into your program.

Straight answers

Incident Response: questions we get asked

Ask us something else

What counts as a reportable cyber incident?

Broadly, an event that actually or potentially adversely affects a covered contractor information system or the CUI residing on it, or that affects your ability to perform operationally critical support. The threshold is lower than most people assume. It does not require confirmed data exfiltration. When in doubt, we help you make and document a defensible determination.

Do we need a medium assurance certificate before an incident?

Yes, and this is the single most common preventable failure. Reporting through DIBNet requires one, and obtaining it is not instant. We get that in place during onboarding so the 72-hour clock is never spent on procurement.

Do you provide forensic investigation?

We handle containment, preservation, triage, and recovery, and we coordinate with specialist digital forensics and incident response firms when the severity, insurance requirements, or legal exposure calls for one. We will tell you plainly when a situation is beyond the point where we should be the only ones in the room.

Next step

Ready to talk about incident response?

Tell us your size, your contracts, and where you are today. We will tell you what it takes and roughly what it costs, usually on the first call.