In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with potential losses exceeding $12.5 billion — a 22% increase in losses over the previous year. And those are just the incidents that were actually reported. In my experience, for every cyber incident that gets reported, at least three more go unreported because the victim didn't know how to report a cyber incident or assumed it wasn't worth the effort. That assumption costs organizations millions.
This guide walks you through exactly what to do when a cyber incident hits — from the first 15 minutes of internal response to filing reports with the right federal agencies. Whether you're dealing with credential theft, ransomware, a business email compromise, or a full-blown data breach, the steps below apply.
Why Reporting a Cyber Incident Matters More Than You Think
Most people treat incident reporting like an afterthought. They focus on containment and recovery — which makes sense — but skip the reporting step entirely. That's a mistake for three reasons.
First, federal agencies like CISA and the FBI use your report to warn others. Your phishing report today might prevent a massive data breach at another organization tomorrow. Second, many regulatory frameworks — HIPAA, PCI DSS, CMMC, and state breach notification laws — legally require you to report incidents within specific timeframes. Third, filing a report creates a paper trail that protects you legally and can support insurance claims.
I've worked with organizations that lost cyber insurance payouts specifically because they failed to report the incident to law enforcement within the policy's required window. Don't let that be you.
Step 1: Contain the Incident Before You Report It
Before you pick up the phone or fill out a form, take immediate containment steps. Reporting a cyber incident to the FBI won't help if the threat actor is still active inside your network.
Immediate Containment Actions
- Isolate affected systems. Disconnect compromised machines from the network but do not power them off — forensic evidence lives in memory.
- Disable compromised accounts. If credential theft is involved, reset passwords and revoke active sessions immediately.
- Preserve logs. Firewall logs, email headers, authentication logs, and endpoint detection alerts are critical evidence.
- Document everything. Screenshots, timestamps, error messages, ransom notes — capture it all before anything changes.
If your organization has an incident response plan, activate it now. If you don't have one, that's a problem you'll need to fix after this crisis. Our cybersecurity awareness training program covers incident response fundamentals that every employee should understand before an incident occurs.
Step 2: Report to the FBI's Internet Crime Complaint Center (IC3)
The FBI's IC3 is the primary federal mechanism for reporting cyber incidents in the United States. You can file a complaint at ic3.gov.
What to Include in Your IC3 Report
- Date and time the incident was discovered
- Type of incident (ransomware, phishing, business email compromise, etc.)
- How the attack occurred (malicious email, compromised credentials, exploited vulnerability)
- Financial losses, if any — include wire transfer details and recipient account information
- IP addresses, email addresses, Bitcoin wallet addresses, or domains used by the threat actor
- Any communication from the attacker (ransom notes, extortion emails)
Here's a critical tip I share with every client: if you're a victim of business email compromise and wire fraud, report within 48 hours. The FBI's Recovery Asset Team has successfully frozen and recovered funds in cases reported quickly. After 72 hours, the money is almost always gone.
Step 3: Report to CISA
The Cybersecurity and Infrastructure Security Agency (CISA) wants to hear from you — especially if you're in critical infrastructure, healthcare, energy, finance, or government. But even if you're a small business, CISA reports feed national threat intelligence.
You can report incidents directly at cisa.gov/report. CISA also operates a 24/7 hotline at (888) 282-0870 for urgent incidents.
Under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), certain organizations will be required to report significant cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. Even before those rules are fully enforced, voluntarily reporting positions your organization as a responsible actor — and CISA may provide direct technical assistance.
Step 4: Notify Your State Attorney General
If the incident involves personal data of customers, employees, or users, every U.S. state has breach notification laws. Most require you to notify affected individuals and the state attorney general within 30 to 60 days of discovery.
The specific requirements vary by state. California, New York, and Texas have particularly aggressive notification requirements. The FTC maintains a reference page on state breach notification laws that I recommend bookmarking.
Don't assume a small breach doesn't trigger notification requirements. In many states, even a single compromised record containing a Social Security number or financial account number triggers the obligation.
How to Report a Cyber Incident: Quick Reference
This section answers the question directly for anyone searching for a fast answer.
To report a cyber incident in the United States:
- FBI IC3: File a complaint at ic3.gov — for all types of cybercrime including phishing, ransomware, social engineering, and fraud.
- CISA: Report at cisa.gov/report or call (888) 282-0870 — especially for critical infrastructure and significant incidents.
- State Attorney General: Required if personal data was exposed. Check your state's breach notification statute for deadlines.
- Your cyber insurance carrier: Notify immediately. Most policies have 24-48 hour reporting windows.
- Local FBI field office: For large-scale incidents, direct contact with your regional field office can accelerate the response.
Step 5: Internal Reporting and Post-Incident Action
External reporting is only half the equation. Your internal reporting process determines whether this incident becomes a one-time event or a recurring nightmare.
Conduct a Post-Incident Review
Within 72 hours of containment, gather your team for a blameless post-mortem. Answer these questions:
- How did the threat actor gain initial access?
- What security controls failed or were missing?
- Did employees follow existing incident response procedures?
- Were multi-factor authentication and zero trust principles in place?
- How long did detection take, and how can you reduce that window?
Train Your People — Before the Next Incident
I've investigated hundreds of incidents, and the pattern is painfully consistent: the initial compromise almost always traces back to a human action. A clicked phishing link. A reused password. A social engineering call that bypassed every technical control you had in place.
Phishing simulation programs are one of the most effective ways to reduce this risk. Our phishing awareness training for organizations lets you run realistic simulations and track which employees need additional coaching — before a real threat actor finds them first.
Common Mistakes That Delay Incident Reporting
I see the same errors repeatedly. Avoid these:
- Waiting for "all the facts." You don't need a complete forensic analysis to file an initial report. Report what you know now and update later.
- Assuming it's too small to report. The FBI and CISA want volume. Small incidents often connect to larger campaigns they're already tracking.
- Letting legal paralyze you. Yes, involve your attorneys — but don't let legal review delay reporting past critical windows. These processes should run in parallel.
- Wiping systems before preserving evidence. I've seen organizations nuke compromised servers within hours of discovery, destroying the forensic evidence that law enforcement — and their own insurance carrier — needed.
The Reporting Mindset Shift Your Organization Needs
Knowing how to report a cyber incident is a skill, not just a checklist. It requires preparation before anything goes wrong. Your employees need to know what phishing looks like. Your IT team needs to know which logs to preserve. Your leadership needs to know which phone numbers to call and which regulators to notify.
That preparation starts with security awareness training. Not a once-a-year compliance checkbox — real, ongoing training that builds muscle memory. When a ransomware note appears on a screen at 2 a.m., nobody is going to calmly Google the right steps. They'll either know what to do, or they won't.
Build that knowledge now. Start with the cybersecurity awareness training at computersecurity.us, and layer in phishing simulations to test and reinforce what your team learns.
The next cyber incident isn't a matter of if. It's a matter of when. The only question is whether you'll be ready to report it correctly — and fast enough to limit the damage.