Reporting and Readiness Resources

Data Breach Legal Resources and ReportingWhere to Report, and Free Federal Readiness Materials

In the hours after a suspected breach, most organizations do not know which agency to call, whether reporting is mandatory or voluntary, or what readiness materials exist for free. This page consolidates the primary federal reporting channels and readiness resources into one reference.

Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Nationwide breach response

Multiple agenciesA single incident can involve reporting to the FBI, CISA, HHS OCR, and one or more state attorneys general.
Voluntary vs mandatoryIC3 and CISA reporting are largely voluntary for private businesses outside covered critical infrastructure sectors, while HIPAA and state law reporting are mandatory.
Free readiness toolsCISA and other federal resources publish incident response planning materials and tabletop exercise guides at no cost.

Quick answer

Businesses reporting a data breach commonly interact with several channels: the FBI Internet Crime Complaint Center (IC3) for cybercrime reporting, CISA for voluntary or, for covered critical infrastructure entities, mandatory cyber incident reporting, the HHS Office for Civil Rights breach portal for HIPAA covered entities, and the relevant state attorney general notification portal for consumer breach notices. Reporting obligations and voluntary channels are not the same thing, and counsel should confirm which apply before submissions are made. This page is a navigation reference, not legal advice.

Common questions, answered in one line

ResourcePurposeTypically used by
FBI IC3 (ic3.gov)Reports cybercrime to federal law enforcement for investigation and threat intelligenceAny business or individual affected by a cyber incident
CISA Report a Cyber IncidentVoluntary reporting channel; mandatory for covered critical infrastructure entities under CIRCIABusinesses of any size; mandatory for covered sectors
HHS OCR Breach PortalMandatory notification for HIPAA covered entities and business associatesHealthcare providers, health plans, clearinghouses, business associates
State Attorney General PortalsState law notification for breaches affecting residents' personal informationAny business holding personal information of state residents
SEC EDGAR (Form 8-K filing)Public disclosure of material cybersecurity incidentsPublic companies
CISA StopRansomware GuideFree readiness and response guidance for ransomware specificallyAny organization, before or during a ransomware event

Key terms defined

TermWhat it means
IC3The FBI Internet Crime Complaint Center, a public reporting mechanism that routes cybercrime complaints to appropriate federal, state, local, and international law enforcement.
CISAThe Cybersecurity and Infrastructure Security Agency, the federal civilian agency responsible for national cyber defense coordination and voluntary or mandated incident reporting for covered sectors.
HHS OCRThe Department of Health and Human Services Office for Civil Rights, which enforces HIPAA and operates the breach portal where covered entities report breaches of protected health information.
Covered critical infrastructure entityAn organization in a sector designated under CIRCIA regulations that is subject to mandatory cyber incident and ransom payment reporting to CISA.
Tabletop exerciseA structured discussion based exercise where a team walks through a simulated incident to test its response plan before a real event occurs.
Attribution reportAnalysis linking an intrusion to a known threat actor group or campaign, useful for law enforcement reporting and for insurer and sanctions screening.

Where a business actually reports a data breach

Reporting is rarely a single phone call. Depending on the nature of the incident, a business may need to engage federal law enforcement, a sector regulator, a state authority, and its own insurance carrier, often on different timelines and with different information requirements.

FBI IC3

Files a formal complaint with federal law enforcement, useful for building a record and supporting any future recovery or prosecution effort. Reporting to IC3 does not substitute for regulatory notification obligations.

CISA

Accepts voluntary reports from any organization and requires mandatory reporting from covered critical infrastructure entities under CIRCIA once implementing regulations take effect for the relevant sector.

HHS OCR

The breach portal is the mandatory reporting mechanism for HIPAA covered entities and business associates, with reporting timing governed by the HIPAA Breach Notification Rule.

State attorney general offices

Many states require direct notice once a defined number of residents are affected, separate from the notice sent to the individuals themselves.

SEC EDGAR

Public companies file Form 8-K disclosures of material cybersecurity incidents through the SEC EDGAR system.

Sector-specific regulators

Financial institutions, utilities, and other regulated sectors often have additional reporting obligations to their primary regulator beyond the general frameworks listed here.

A practical reporting sequence

  1. Engage counsel and an independent forensic examiner immediately to begin scoping and preservation.
  2. File an IC3 report to create a law enforcement record, particularly for ransomware, business email compromise, and wire fraud.
  3. Determine, with counsel, whether the organization is a covered critical infrastructure entity subject to mandatory CISA reporting.
  4. Confirm sector-specific and state law obligations that apply based on the type of data and the residency of affected individuals.
  5. Coordinate the timing of notifications so that public disclosures, regulator filings, and individual notices are factually consistent.

Not sure which agency applies to your incident

We help counsel and incident response teams map the facts of an incident to the reporting channels that actually apply, and produce the evidence those filings depend on.

Free federal readiness resources worth using before an incident

Several federal resources are available at no cost and are genuinely useful for building incident response capability, independent of any paid consulting engagement.

ResourceWhat it provides
CISA StopRansomware GuideConsolidated best practices for ransomware prevention, response, and recovery, including a response checklist
NIST SP 800-61 Rev. 3Federal guidance on incident response lifecycle, integrated with cybersecurity framework activities
CISA Cyber Hygiene ServicesFree vulnerability scanning services for eligible organizations to reduce exposure before an incident occurs
FBI Cyber Division field office contactsDirect relationships with local field offices that can accelerate law enforcement engagement during an active incident
CISA tabletop exercise packagesDownloadable scenario packages that organizations can run internally to test their incident response plan

None of these resources replace an independent forensic examiner during an actual incident, but they materially shorten the learning curve for organizations building a response capability, and they cost nothing to use before a breach ever occurs.

Coordinating reporting with counsel and forensic findings

Reporting decisions should never be made in isolation from the forensic investigation. A law enforcement report, a regulatory filing, and a customer notification letter should all be consistent with the facts as the investigation currently understands them, and updated together if new facts emerge.

  • Counsel should determine which reporting obligations are mandatory versus voluntary before any filing is made, since the content and tone of a mandatory regulatory filing differs from a voluntary law enforcement report.
  • Forensic findings shared with law enforcement, such as indicators of compromise or attribution analysis, can be useful for the broader response but do not themselves satisfy regulatory notification requirements.
  • Public statements, SEC filings, and individual notification letters should be reviewed against the current forensic timeline before release, since inconsistencies between them are a common source of later scrutiny.

Elite Digital Forensics supplies the forensic evidence and technical analysis that supports these coordinated decisions. We do not provide legal advice or determine which reports are legally required; that determination belongs to your counsel.

What to expect when engaging law enforcement

Businesses sometimes hesitate to involve law enforcement out of concern about disruption or disclosure. In most cases, an IC3 report or a direct contact with a local FBI field office does not require public disclosure and does not compel the business to pause its own investigation or remediation.

  • Law enforcement involvement can support insurance claims, sanctions screening for ransom payment decisions, and any future civil recovery effort.
  • Sharing indicators of compromise with law enforcement or CISA can also benefit other potential victims of the same threat actor, though sharing decisions should be made with counsel's input.
  • Law enforcement engagement is generally separate from, and does not substitute for, mandatory regulatory notification to individuals or agencies.

What matters most

  • Sequencing. Reporting decisions should follow, not precede, an initial forensic scoping of the incident.
  • Consistency. Every report and notification should reflect the same underlying facts at the time it is issued.
  • Distinguishing voluntary from mandatory channels before deciding what and when to file.
  • Using free readiness resources before an incident occurs, not for the first time during one.
  • Keeping legal determinations with counsel while forensic examiners supply the underlying facts.

Common misconceptions

Reporting to the FBI satisfies our notification obligations

IC3 and FBI reporting are separate from regulatory and state law notification requirements, which have their own deadlines and content requirements.

CISA reporting is required for every business

Mandatory reporting under CIRCIA currently applies to covered critical infrastructure entities as defined by CISA regulations; other organizations can report voluntarily.

Involving law enforcement will make the incident public

Law enforcement reporting is not generally a public disclosure event on its own, though other legal obligations may separately require public notice.

There is no cost effective way to prepare before a breach

Several federal agencies publish free tabletop exercise packages, hygiene scanning, and incident response guidance that cost nothing to use.

When this applies, and when it does not

This applies when

  • A business has just discovered a suspected breach and does not know which agencies or portals apply.
  • Counsel needs a consolidated view of federal and state reporting channels before advising the client.
  • An organization wants to build incident response readiness using free resources before any incident occurs.
  • A ransomware event raises questions about law enforcement engagement and sanctions screening.

This does not apply when

  • The organization already has established counsel and reporting relationships in place and needs case specific forensic work rather than a resource overview.
  • The question is a purely legal one about which statute applies, which should go to counsel rather than a forensic examiner.

How Elite Digital Forensics helps

We work with counsel and incident response teams to produce the technical findings that law enforcement reports, regulatory filings, and readiness exercises depend on, and we help organizations build response capability before an incident using proven, defensible methodology.

Indicator of compromise packaging

Preparing technical indicators in the format needed for law enforcement and CISA reporting.

Attribution support

Analysis linking observed tactics and infrastructure to known threat actor patterns where the evidence supports it.

Tabletop exercise facilitation

Running realistic incident response exercises so your team is not learning the process for the first time during a real breach.

Readiness plan review

Assessing an existing incident response plan against current retention, evidence, and reporting realities.

Coordinated reporting support

Aligning forensic timelines with law enforcement reports, regulatory filings, and customer notifications so the facts are consistent.

Post-incident debrief

A documented lessons learned report identifying what evidence was available, what was missing, and what to fix before the next incident.

Problems we solve

  • You do not know whether your incident requires mandatory reporting to CISA or is purely voluntary.
  • Counsel needs a consolidated view of every reporting channel that might apply to a single incident.
  • Your organization has never run a tabletop exercise and does not know where to start.
  • Law enforcement has asked for indicators of compromise and you need them properly packaged.
  • Your public statements and regulatory filings need to be checked against the current investigative timeline.

Talk with a forensic examiner about your incident

Consultations are confidential. We work directly with affected businesses, with outside counsel, and with cyber insurance carriers and brokers nationwide.

About Elite Digital Forensics

Elite Digital Forensics is an independent digital forensics firm serving businesses, attorneys, and insurers nationwide. Our examiners include former law enforcement forensic examiners who have testified as court qualified expert witnesses in state and federal proceedings. We do not sell security software and we do not manage client networks, so our findings carry no conflict of interest when the question is whether an environment was adequately secured.

Every engagement follows documented chain of custody, defensible acquisition methods, and reporting written for attorney review, insurer submission, regulator response, or courtroom use. Work performed at the direction of counsel is generally treated as attorney work product prepared in anticipation of litigation. Call (833) 292-3733 or request a confidential consultation.

Frequently asked questions

Is reporting to the FBI IC3 required after a data breach?

No, IC3 reporting is generally voluntary for private businesses. It creates a law enforcement record that can support investigation, sanctions screening, and future recovery efforts, but it does not substitute for mandatory regulatory or state law notification.

When is CISA reporting mandatory rather than voluntary?

Mandatory reporting applies to organizations that meet the definition of a covered critical infrastructure entity under CIRCIA and its implementing regulations. Other organizations can report cyber incidents to CISA voluntarily at any time.

Where do healthcare organizations report a breach of patient data?

HIPAA covered entities and business associates report breaches of protected health information through the HHS Office for Civil Rights breach portal, on the timeline set by the HIPAA Breach Notification Rule.

Do we need to notify a state attorney general as well as affected individuals?

In many states, yes, once the number of affected residents crosses a defined threshold, though the exact threshold and process vary by state. Counsel should confirm the requirements for every state where affected individuals reside.

Are there free resources to prepare before a breach happens?

Yes. CISA publishes the StopRansomware Guide, downloadable tabletop exercise packages, and free cyber hygiene scanning for eligible organizations. NIST SP 800-61 provides incident response lifecycle guidance at no cost.

Can a forensic firm submit reports to CISA or the FBI on our behalf?

We can prepare the technical indicators, timeline, and supporting documentation that these reports require, and coordinate with counsel on submission, but we do not provide legal advice about whether a specific filing is required.

References and authoritative sources

  1. FBI Internet Crime Complaint Center (IC3) — https://www.ic3.gov/
  2. CISA, Report a Cyber Incident — https://www.cisa.gov/report
  3. CISA, StopRansomware Guide — https://www.cisa.gov/stopransomware
  4. HHS Office for Civil Rights, HIPAA Breach Notification Rule — https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
  5. CISA, Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) — https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia
  6. NIST SP 800-61 Rev. 3, Incident Response Recommendations (April 2025) — https://csrc.nist.gov/pubs/sp/800/61/r3/final

#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #DataBreachResponse #DataBreachInvestigation #IncidentResponse #CyberForensics #IncidentReporting #CISA #BreachResponse #IncidentReadiness

This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.

Assistant Icon Elite Digital Forensics Assistant
πŸ‘‹ Live Chat Now!
Free Virtual Consultation 24/7
Chat Now!

By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β 

IMPORTANT: Please remember to check your spam or junk folder