It is 2:00 AM on a Tuesday, and your systems administrator sends the message every business owner dreads: “We’ve detected unauthorized access to our core database.”
In the heat of a cyber incident, chaos is your enemy. The choices you make—and the speed at which you make them—in the first 24 hours will determine whether your business suffers a minor operational hiccup or a catastrophic, brand-destroying disaster.
Worse yet, under the Nigeria Data Protection Act (NDPA), the legal clock for mandatory regulatory reporting starts ticking the exact moment you become aware of a breach.
Here is your step-by-step, hour-by-hour operational checklist to navigate the critical first 24 hours.

Phase 1: Hours 0 to 2 — Triage & Immediate Containment
The priority right now is stopping the bleeding. Do not panic; execute the playbook.
- [ ] Activate the Incident Response Team (IRT): Immediately pull together your core leads—IT Admin, Legal/DPO, and Executive Leadership. Move communication to an out-of-band channel (e.g., a secure, encrypted mobile group) because your primary corporate email or Slack might be compromised.
- [ ] Isolate Affected Systems: Disconnect compromised servers, databases, or infected workstations from the broader network. Rule of thumb: Isolate, don’t turn off. Shutting down a machine completely can wipe valuable volatile memory (RAM) evidence needed for forensics.
- [ ] Revoke Compromised Credentials: Immediately force a global password reset for all admin accounts, API keys, and privileged user tokens associated with the breach vector.
Phase 2: Hours 2 to 6 — Evidence Preservation & Scoping
Once the immediate threat is quarantined, you must figure out what happened and what was touched.
- [ ] Preserve System Logs: Export and secure all relevant server, firewall, and access logs. These will serve as your digital paper trail.
- [ ] Determine the “Scope”: Answer the critical questions:
- What data was exposed? (e.g., customer emails, internal memos, financial details, or customer BVNs/NINs).
- How many individuals are affected?
- Is the attacker still inside the environment?

Phase 3: Hours 6 to 12 — Legal & Regulatory Alignment (The NDPR Clock)
In Nigeria, a data breach is not just an IT issue; it is a legal liability.
- [ ] Check the NDPA 72-Hour Rule: Under Section 40 of the NDPA, if the breach poses a risk to the rights and freedoms of individuals, you are legally mandated to notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the incident.
- [ ] Consult Your DPO and Legal Counsel: Review whether the compromised data meets the threshold for mandatory reporting. If third-party vendors or payment processors were the entry point, notify them immediately to secure their endpoints.
Phase 4: Hours 12 to 24 — Internal Communication & Remediation
As the dust settles, alignment across your organization and customer-facing teams becomes vital.
- [ ] Brief Executive Leadership & PR: Prepare clear, factual talking points for your internal team. Silence breeds rumors; transparency builds internal trust.
- [ ] Draft Customer Communications (If Required): If high-risk personal data was compromised, draft notification templates for affected data subjects. Do not point fingers; focus on what steps you are taking to protect them.
- [ ] Begin Patching & System Restoration: Using clean, verified backups (adhering to the 3-2-1 backup rule), begin restoring critical operations only after the vulnerability that caused the breach has been completely patched.
The 24-Hour Action Summary Checklist
| Timeframe | Core Objective | Key Deliverable | Status |
| Hours 0–2 | Stop the spread | Isolate systems & revoke compromised tokens | [ ] |
| Hours 2–6 | Preserve facts | Secure log files & scope affected data | [ ] |
| Hours 6–12 | Legal review | Evaluate NDPR 72-hour reporting triggers | [ ] |
| Hours 12–24 | Recovery prep | Patch vulnerabilities & brief stakeholders | [ ] |
The Takeaway: Preparedness Beats Panic
An incident response plan is only as good as its execution. When a breach happens, you don’t have time to think about what to do—you only have time to do what you planned.
Want to make sure your team is ready before an incident occurs?
At Apexium, we help Nigerian businesses build, test, and drill custom Incident Response Plans, ensuring your organization stays compliant with the NDPC and resilient against modern threats.





