Read further to better understand what a forensic investigation involves and how to prepare, because this knowledge can save you time and money.
A PCI Forensic Investigator (PFI)/qualified assessor, directed by the card brands and acquiring bank, scopes the environment. This includes images affected devices onsite, analyzes the data, and issues a preliminary report within about a week followed by a full final report. Forensic investigations typically cost $10,000 to well over $100,000 depending on organization size, and merchants should preserve evidence, avoid restoring from backup, and activate a tested incident response plan before a PFI arrives.
Data breaches can be stressful, scary events. If you’ve experienced a data breach, you will likely need a forensic investigator to come and discover the cause of your breach. This blog gives a comprehensive overview of the top asked forensic questions, so you can better understand what the forensic investigation process looks like.
Unfortunately, breaches aren't rare or theoretical. The IBM Cost of a Data Breach Report 2026 put the global average cost of a breach at $4.99 million, a 12% jump over the prior year, with U.S. breaches averaging $11.5 million.
Read further to better understand what a forensic investigation involves and how to prepare, because this knowledge can save you time and money.
David Ellis Updated: August 7, 2026 Data Breaches
How does a forensic investigation work?
Here are the typical actions a forensic investigator would take:
Step One: Preliminary Research
Forensic investigations begin with some research on the company. The PFI needs to "scope" the merchant's environment, identifying where critical data resides, the systems that connect to it, and how data flows in and out of the network.
Step Two: Onsite Data Gathering
The forensics team then goes onsite and gathers data from identified devices.
Step Three: Analysis
The investigation team brings the data back to headquarters and analyzes it thoroughly to confirm whether a data breach occurred, determine what data the attacker stole, and identify which vulnerabilities were exploited.
Step Four: Report
About a week after the initial data acquisition, the investigator will issue a short preliminary report showing whether they've found any indicators of compromise or other overt evidence of a data compromise. After fully analyzing the forensic data, the investigator will submit a complete final report that explains how the attack happened, which vulnerabilities were exploited, and what data was at risk.
What to Know About Forensic Investigations
According to Verizon's 2026 Data Breach Investigations Report, exploited vulnerabilities have overtaken stolen credentials as the number one way attackers gain initial access, now accounting for 31% of breaches. IBM's 2026 report found that breach lifecycles (time to identify and contain) actually got longer this year after five straight years of improvement, and every hour a breach goes unresolved adds roughly $1,100 to its cost. The faster your organization can engage a forensic investigator and hand over clean, preserved evidence, the faster it can contain the breach.
Professional advice: Don't wipe, rebuild, or restore systems from backup before the PFI has imaged the affected devices. Well-intentioned "cleanup" is one of the most common ways merchants unintentionally destroy the evidence an investigator needs to determine scope and root cause.
Who conducts a forensic investigation?
If your business processes, stores, or transmits payment card data, a suspected card-data breach must be investigated by a PCI Forensic Investigator (PFI), not just any incident response firm. The PCI Security Standards Council maintains a formal qualification program. PFI companies must be Qualified Security Assessor (QSA) companies with a dedicated forensic practice, and both the company and its individual investigators must requalify every year.
A few things worth knowing about the PFI process:
- You generally don't get to choose your PFI freely. The card brands and your acquiring bank direct which qualified PFI is engaged.
- The PFI's job isn't to assign blame; it's to determine whether a compromise occurred, how it happened, what data was exposed, and which PCI DSS requirements were missing or ineffective.
- The PFI's findings help the card brands and your acquirer determine fines, card reissuance costs, and any additional compliance validation you'll need to complete afterward (often a full Report on Compliance, regardless of your merchant level).
How much does a forensic investigation cost?
Forensic investigations can be expensive. However, remember that the investigation involves one or more PFI's examining a mountain of data. This takes a lot of manpower and expertise, which is reflected in their price.
The cost depends on the size of your organization. The larger your organization, the more data you need reviewed.
Industry estimates for a PFI engagement typically range from around $10,000 for a small, well-scoped case to well over $100,000 for a large, complex environment with multiple locations, cloud and on-premises systems, or limited existing logging. Large-scale card-data breaches involving parallel forensic reviews (a PFI report plus a separate attorney-directed investigation) can push total forensic spend into the hundreds of thousands or even millions of dollars.
That cost is only one piece of the total breach bill. For context:
- Globally, the average cost of a data breach reached $4.99 million in 2026, up 12% year over year (IBM Cost of a Data Breach Report, 2026).
- In the U.S., the average breach cost hit $11.5 million, which is more than double the global average.
- Healthcare organizations continue to face the steepest breach costs of any industry, averaging $6.64 million per incident (IBM, 2026).
Professional advice: Build the cost of a potential PFI engagement into your incident response budget and breach-response reserve before you need one — not after. If you carry cyber insurance, confirm now (not during a breach) whether your policy covers PFI fees, card brand fines, and card reissuance costs, since coverage varies widely by carrier and policy.
What is an incident response plan?
An incident response plan is a documented, written plan with 6 distinct phases that helps IT professionals and staff recognize and deal with a cybersecurity incident like a data breach or cyberattack.
Remember, creating and managing an incident response plan properly requires regular updates and training. A well-executed incident response plan can minimize breach impact, reduce fines, decrease negative press, and help you get back to normal operations more quickly.
Here's a helpful blog that goes over the six phases of incident response.
IBM's 2026 report found that organizations using AI and automation extensively in their security operations saved an average of $1.93 million per breach compared to those using none, but a quarter of organizations still use no AI or automation in security.
A documented, regularly tested incident response plan is one of the best and least expensive ways to close your security gaps.
What should I include in my incident response plan?
An incident response plan should address a suspected data breach in a series of phases. The incident response phases are:
- Prepare: Establish policies, assign roles, and stock the tools and contacts (legal, forensic, PR) you'll need before an incident, not during one.
- Identify: Detect and confirm that an incident has actually occurred, and determine its initial scope.
- Contain: Limit the damage by isolating affected systems without destroying evidence.
- Eradicate: Remove the root cause, whether that's malware, an exposed credential, or an unpatched vulnerability.
- Recover: Restore systems and operations carefully, and confirm the threat is gone.
- Review: Conduct a post-incident review to capture lessons learned and update your plan and controls.
Professional advice: Test your plan with tabletop exercises at least annually, and after any significant change to your environment (new vendors, new payment channels, cloud migrations). A plan that's never been rehearsed tends to fall apart under real pressure. The middle of a breach is the worst time to discover your IRP doesn’t work.
SEE ALSO: How to Make and Implement a Successful Incident Response Plan
What should I do if I'm breached?
After a data breach, quick action is vital to protecting your brand and mitigating the impact on your reputation.
Follow these five essential steps to respond effectively, prevent further damage, and restore normal operations as quickly as possible.
- Start Your Incident Response Plan: Activate your documented plan immediately and notify your response team.
- Preserve Evidence: Avoid the temptation to "fix" things right away; preserving logs, images, and affected systems is essential for an accurate forensic investigation.
- Contain the Breach: Stop ongoing data loss without tipping off attackers still in your environment or destroying evidence.
- Start Incident Response Management: Coordinate legal counsel, your PFI (if payment card data is involved), your acquiring bank, and your communications team.
- Investigate, Fix Your Systems, and Implement Your Breach Protection Services: Use the forensic investigation's findings to close the specific vulnerabilities that were exploited, not just generic security gaps.
Professional advice: Loop in your legal counsel early, ideally before the forensic investigation begins. Depending on your jurisdiction and industry, breach notification laws may impose tight deadlines. Your counsel can help determine what's discoverable versus privileged as the investigation proceeds.
SEE ALSO: How to Effectively Manage a Data Breach
Final Thoughts: How Can You Prevent a Breach?
Most breaches that trigger a forensic investigation are preventable. To prevent a potential breach, it’s important to regularly:
- Patch known vulnerabilities. Exploited vulnerabilities are now the leading initial access vector in breaches, per Verizon's 2026 DBIR, and organizations remediate only about 26% of their most critical known vulnerabilities on average.
- Train employees continuously. The human element (phishing, credential reuse, simple error) was present in 62% of breaches analyzed in the 2026 DBIR.
- Vet your vendors. Third-party involvement in breaches jumped 60% year over year and now factors into nearly half (48%) of all breaches. This is a reminder that your security posture is only as strong as your weakest vendor.
- Maintain PCI DSS compliance year-round, not just at assessment time. The current standard, PCI DSS v4.0.1, made all of its previously future-dated requirements mandatory as of March 31, 2025. Continuous compliance (not a once-a-year snapshot) is now the expectation that card brands and PFIs will hold you to if a breach occurs.




