- Nationwide Digital Forensic & Cyber Investigation Services
In the hours after a suspected breach, most organizations do not know which agency to call, whether reporting is mandatory or voluntary, or what readiness materials exist for free. This page consolidates the primary federal reporting channels and readiness resources into one reference.
Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Nationwide breach response
| Resource | Purpose | Typically used by |
|---|---|---|
| FBI IC3 (ic3.gov) | Reports cybercrime to federal law enforcement for investigation and threat intelligence | Any business or individual affected by a cyber incident |
| CISA Report a Cyber Incident | Voluntary reporting channel; mandatory for covered critical infrastructure entities under CIRCIA | Businesses of any size; mandatory for covered sectors |
| HHS OCR Breach Portal | Mandatory notification for HIPAA covered entities and business associates | Healthcare providers, health plans, clearinghouses, business associates |
| State Attorney General Portals | State law notification for breaches affecting residents' personal information | Any business holding personal information of state residents |
| SEC EDGAR (Form 8-K filing) | Public disclosure of material cybersecurity incidents | Public companies |
| CISA StopRansomware Guide | Free readiness and response guidance for ransomware specifically | Any organization, before or during a ransomware event |
| Term | What it means |
|---|---|
| IC3 | The FBI Internet Crime Complaint Center, a public reporting mechanism that routes cybercrime complaints to appropriate federal, state, local, and international law enforcement. |
| CISA | The Cybersecurity and Infrastructure Security Agency, the federal civilian agency responsible for national cyber defense coordination and voluntary or mandated incident reporting for covered sectors. |
| HHS OCR | The Department of Health and Human Services Office for Civil Rights, which enforces HIPAA and operates the breach portal where covered entities report breaches of protected health information. |
| Covered critical infrastructure entity | An organization in a sector designated under CIRCIA regulations that is subject to mandatory cyber incident and ransom payment reporting to CISA. |
| Tabletop exercise | A structured discussion based exercise where a team walks through a simulated incident to test its response plan before a real event occurs. |
| Attribution report | Analysis linking an intrusion to a known threat actor group or campaign, useful for law enforcement reporting and for insurer and sanctions screening. |
Reporting is rarely a single phone call. Depending on the nature of the incident, a business may need to engage federal law enforcement, a sector regulator, a state authority, and its own insurance carrier, often on different timelines and with different information requirements.
Files a formal complaint with federal law enforcement, useful for building a record and supporting any future recovery or prosecution effort. Reporting to IC3 does not substitute for regulatory notification obligations.
Accepts voluntary reports from any organization and requires mandatory reporting from covered critical infrastructure entities under CIRCIA once implementing regulations take effect for the relevant sector.
The breach portal is the mandatory reporting mechanism for HIPAA covered entities and business associates, with reporting timing governed by the HIPAA Breach Notification Rule.
Many states require direct notice once a defined number of residents are affected, separate from the notice sent to the individuals themselves.
Public companies file Form 8-K disclosures of material cybersecurity incidents through the SEC EDGAR system.
Financial institutions, utilities, and other regulated sectors often have additional reporting obligations to their primary regulator beyond the general frameworks listed here.
We help counsel and incident response teams map the facts of an incident to the reporting channels that actually apply, and produce the evidence those filings depend on.
Several federal resources are available at no cost and are genuinely useful for building incident response capability, independent of any paid consulting engagement.
| Resource | What it provides |
|---|---|
| CISA StopRansomware Guide | Consolidated best practices for ransomware prevention, response, and recovery, including a response checklist |
| NIST SP 800-61 Rev. 3 | Federal guidance on incident response lifecycle, integrated with cybersecurity framework activities |
| CISA Cyber Hygiene Services | Free vulnerability scanning services for eligible organizations to reduce exposure before an incident occurs |
| FBI Cyber Division field office contacts | Direct relationships with local field offices that can accelerate law enforcement engagement during an active incident |
| CISA tabletop exercise packages | Downloadable scenario packages that organizations can run internally to test their incident response plan |
None of these resources replace an independent forensic examiner during an actual incident, but they materially shorten the learning curve for organizations building a response capability, and they cost nothing to use before a breach ever occurs.
Reporting decisions should never be made in isolation from the forensic investigation. A law enforcement report, a regulatory filing, and a customer notification letter should all be consistent with the facts as the investigation currently understands them, and updated together if new facts emerge.
Elite Digital Forensics supplies the forensic evidence and technical analysis that supports these coordinated decisions. We do not provide legal advice or determine which reports are legally required; that determination belongs to your counsel.
Businesses sometimes hesitate to involve law enforcement out of concern about disruption or disclosure. In most cases, an IC3 report or a direct contact with a local FBI field office does not require public disclosure and does not compel the business to pause its own investigation or remediation.
IC3 and FBI reporting are separate from regulatory and state law notification requirements, which have their own deadlines and content requirements.
Mandatory reporting under CIRCIA currently applies to covered critical infrastructure entities as defined by CISA regulations; other organizations can report voluntarily.
Law enforcement reporting is not generally a public disclosure event on its own, though other legal obligations may separately require public notice.
Several federal agencies publish free tabletop exercise packages, hygiene scanning, and incident response guidance that cost nothing to use.
We work with counsel and incident response teams to produce the technical findings that law enforcement reports, regulatory filings, and readiness exercises depend on, and we help organizations build response capability before an incident using proven, defensible methodology.
Preparing technical indicators in the format needed for law enforcement and CISA reporting.
Analysis linking observed tactics and infrastructure to known threat actor patterns where the evidence supports it.
Running realistic incident response exercises so your team is not learning the process for the first time during a real breach.
Assessing an existing incident response plan against current retention, evidence, and reporting realities.
Aligning forensic timelines with law enforcement reports, regulatory filings, and customer notifications so the facts are consistent.
A documented lessons learned report identifying what evidence was available, what was missing, and what to fix before the next incident.
Consultations are confidential. We work directly with affected businesses, with outside counsel, and with cyber insurance carriers and brokers nationwide.
Elite Digital Forensics is an independent digital forensics firm serving businesses, attorneys, and insurers nationwide. Our examiners include former law enforcement forensic examiners who have testified as court qualified expert witnesses in state and federal proceedings. We do not sell security software and we do not manage client networks, so our findings carry no conflict of interest when the question is whether an environment was adequately secured.
Every engagement follows documented chain of custody, defensible acquisition methods, and reporting written for attorney review, insurer submission, regulator response, or courtroom use. Work performed at the direction of counsel is generally treated as attorney work product prepared in anticipation of litigation. Call (833) 292-3733 or request a confidential consultation.
No, IC3 reporting is generally voluntary for private businesses. It creates a law enforcement record that can support investigation, sanctions screening, and future recovery efforts, but it does not substitute for mandatory regulatory or state law notification.
Mandatory reporting applies to organizations that meet the definition of a covered critical infrastructure entity under CIRCIA and its implementing regulations. Other organizations can report cyber incidents to CISA voluntarily at any time.
HIPAA covered entities and business associates report breaches of protected health information through the HHS Office for Civil Rights breach portal, on the timeline set by the HIPAA Breach Notification Rule.
In many states, yes, once the number of affected residents crosses a defined threshold, though the exact threshold and process vary by state. Counsel should confirm the requirements for every state where affected individuals reside.
Yes. CISA publishes the StopRansomware Guide, downloadable tabletop exercise packages, and free cyber hygiene scanning for eligible organizations. NIST SP 800-61 provides incident response lifecycle guidance at no cost.
We can prepare the technical indicators, timeline, and supporting documentation that these reports require, and coordinate with counsel on submission, but we do not provide legal advice about whether a specific filing is required.
#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #DataBreachResponse #DataBreachInvestigation #IncidentResponse #CyberForensics #IncidentReporting #CISA #BreachResponse #IncidentReadiness
This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.
Elite Digital ForensicsΒ is a Professional Digital Forensics and Cyber Consulting Company that provides services nationwide.Β
Elite Digital Forensics Assistant
By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β
IMPORTANT: Please remember to check your spam or junk folder
We use cookies for site functionality and, only with your permission, analytics and advertising. See our Privacy Policy for details. California residents have the right to Do Not Sell or Share My Personal Information.