Discovering leaked private data creates pressure to act immediately. Speed matters, but an unstructured response can destroy useful evidence or widen the incident.
A simple first-response plan gives security, legal and leadership teams a shared starting point.
1. Preserve the original evidence
Keep the original screenshot or image file whenever possible. Avoid repeatedly editing, exporting or recompressing it. Record where it was found, when it was collected and who handled it.
If the evidence appeared on a website or messaging platform, preserve the surrounding context as well as the artifact itself. URLs, timestamps, account details and conversation history may all become relevant later.
2. Control further exposure
Remove public access where you can do so without destroying evidence. Review whether links, accounts, sessions or credentials need to be revoked. Avoid broad changes that make it harder to reconstruct what happened.
Keep the response group small and use a dedicated channel for decisions. Sensitive incident details can create a second leak if they are circulated carelessly.
3. Establish what is known
Separate confirmed facts from assumptions. Document:
- The material that surfaced
- Where and when it was discovered
- The systems that originally displayed or distributed it
- The people who were legitimately able to access it
- Any signs that more than one item was exposed
This initial timeline will evolve, but it should always show which details are verified.
4. Analyse the artifact
If the page or copy was protected by ExactMark, submit the evidence without altering it first. Review the recovered viewer or recipient, the associated session and page, and the confidence score.
Preserve the analysis result with the original artifact. Attribution should be treated as part of the wider evidence set rather than as an isolated accusation.
5. Decide and document the response
The appropriate action depends on the data, contractual duties, applicable law and the strength of the evidence. Legal or regulatory advice may be necessary. Record the reasons behind containment, notification and escalation decisions.
Preparation makes the first hour easier
The best time to define owners, evidence-handling procedures and communication routes is before an incident. Traceability should also be installed before sensitive data surfaces; it cannot recreate session history that was never recorded.