Skip to content
Tool4SaaS
HomeAboutContactBlog
Tool4SaaS

185 fast, local utilities for developers and creators. No sign-ups. Most tools run locally in your browser; 4 network tools need internet (see /privacy). Ads/analytics in Privacy.

185 free tools across 12 categories. (12 categories live.)

Categories

  • Text & Documents

  • Business & Writing

  • Developer Tools

  • Converters

  • Generators

  • Images & Design

  • PDF Tools

  • Calculators

  • Finance & Money

  • Health & Fitness

  • SEO & Marketing

  • Time & Date

Popular Tools

  • Invoice Generator

  • QR Code Generator

  • Word Counter

  • Password Generator

  • JSON Formatter

  • Unit Converter

  • Color Converter

  • Age Calculator

  • EMI Calculator

  • SIP Calculator

  • Mortgage Calculator

  • Compound Interest Calculator

Company

  • All Tools

  • About Us

  • Author

  • Methodology

  • Privacy Policy

  • Terms of Service

  • Contact Us

  • Blog — Tool Guides

  • Invoice Generator Guide

  • QR Code Generator Guide

  • Resume Builder Guide

  • Mortgage Calculator Guide

  • Password Generator Guide

  • Word Counter Guide

  • Contact Support

© 2026 Tool4SaaS. All rights reserved.

  1. Home
  2. /
  3. Blog
  4. /
  5. Password Guide
  6. /
  7. What to Do After a Data Breach: 7-Step Checklist (2026)

What to Do After a Data Breach: 7-Step Checklist (2026)

Data breach response in priority order: contain, rotate reuses, MFA, kill sessions, scope, monitor, no mass rotation. CISA/NIST-aligned checklist.

By Tool4SaaS Editorial Team · Published 2026-09-25 · Updated 2026-09-25 · 3 min read

Try it now — Password Generator, free in your browser

Strong random passwords · No signup · No watermark · Free forever.

Open Password Generator →
On this page
  • 7 steps in order
  • The week after
  • Small-business drill

“We found your email in a breach.” Your stomach drops — then the dangerous part starts: panic-changing one password while twelve reused siblings stay live. Breach response has a correct order, and order matters more than speed. This data breach checklist gives the 7 steps in priority sequence, tested against CISA and NIST compromise guidance.

Part of the password generator guide. Generate replacements in the password generator; unique OTPs for resets via the OTP tool; fingerprint public keys with the hash generator where applicable.

The 7 steps, in order (do not skip ahead)

  1. Contain the breached account: change its password immediately — generated, unique, 16+ — from a clean device. If malware is suspected, clean the device first or the new secret is compromised at birth.
  2. Rotate every reuse: list all sites sharing the password or its pattern, change each to unique generated secrets, email and bank first. This step — not step 1 — stops the spread.
  3. Enable MFA everywhere it matters: authenticator app on email, bank, cloud storage and socials. Attackers holding old session tokens get locked out at next challenge.
  4. Kill sessions and keys: “log out all devices” on email/socials, revoke app passwords and API tokens minted under the old credential, re-issue where needed.
  5. Check exposure scope: breach-notification details (what fields leaked: passwords only, or IDs, cards, addresses?) set steps 6–7. Screenshot the notice for records.
  6. Watch money and identity: bank alerts on, statements scanned 60 days, credit freeze or fraud alert if IDs leaked. India: report at cybercrime.gov.in + 1930 helpline promptly.
  7. Do NOT calendar-rotate everything else: clean unique passwords stay. Mass rotation wastes the window where steps 1–6 matter and breeds weaker replacements.

Aftermath: the week after (lock in the lesson)

  • Audit with a manager report: most managers flag reused/weak/compromised vault entries — clear every flag within 7 days while motivation is hot.
  • Upgrade email to hardware-grade: breach survivors should move email MFA to the strongest available option (passkey or hardware key) — your inbox is the recovery path for everything.
  • Document what leaked where: one note (offline) mapping breached service → data types → actions taken. Future-you triages the next notice in minutes.
  • India specifics: UPI-linked email breaches deserve same-day bank notification; SIM-swap symptoms (sudden no-signal) mean call the carrier and bank immediately, then the cyber helpline.

Small-business breach drill (quarterly, 30 minutes)

Five-person shops face the same ransomware and stuffing attacks with no SOC. Quarterly drill: verify backups restore (actually restore one file), confirm MFA on email/cloud/bank for every staffer, rotate the three shared credentials (Wi-Fi, socials, vendor portals), and check haveibeenpwned-style exposure for company domains. Assign one owner per item — shared responsibility means no responsibility. Log date + findings on one page; cyber-insurance applications and client security questionnaires accept documented drills as evidence. When a real notice lands, the team runs the 7-step order above instead of improvising — drills convert panic into procedure. Cost: two working hours per quarter for the whole company.

General information only, not security advice. Generate offline, store in a manager, enable MFA on email/bank. If you lose your master password it cannot be recovered by us.

Related free tools

Hash Generator →OTP Generator (TOTP 2FA) →

Frequently asked questions

Change the breached account's password from a clean device, then immediately rotate every account sharing it — email and bank first. Containment then spread-stopping, in that order.

No — change breached plus reused ones, enable MFA, kill sessions. Mass-rotating clean unique passwords wastes effort and breeds weaker replacements.

Read the breach notice for field types (passwords, IDs, cards). Screenshot it; scope sets whether you also freeze credit and watch statements for 60 days.

Treat as critical: new unique passphrase, strongest MFA available, kill all sessions, revoke app passwords — your inbox recovers everything else.

cybercrime.gov.in plus the 1930 helpline, fast — recovery odds decay with hours. Notify the bank same-day for UPI-linked breaches.

Done reading — open the Password Generator

Strong random passwords — free in your browser, no signup.

Open Password Generator →

Keep reading in this guide

Pillar guide

How to Generate a Strong Password (Free Offline Tool)

In this silo

How to Create a Strong Password: The 16-Character Rule (2026)

In this silo

How to Remember Passwords Without Reusing Them (2026)

In this silo

2FA vs Passkeys: Strength Ladder + Setup Order (2026)