Blog · Playbook · 16 August 2026
A credential breach just hit the news.
Your first 24 hours.
Every few months a breach makes headlines and every team asks the same question: are we affected, and what do we do first? Keep this playbook. It is written to be run under pressure, and it works whether or not you use Keyvaci.
Hour 0 to 2: decide whether you are exposed
- Name the asset precisely. "Vendor X breached" matters only if you hold accounts, credentials, tokens, or data at vendor X, or reuse passwords that lived there. Write down the actual overlap before acting.
- Check reuse, not just presence. The blast radius of any leak is wherever the same password or a close variant was reused. If your credentials live in a searchable team vault, this query takes minutes; if they live in chat threads and spreadsheets, this step is your bottleneck and your lesson.
- Freeze convenience access. Pause any browser-extension autofill or shared session for the affected domain until rotation is done.
Hour 2 to 12: rotate in priority order
Do not rotate alphabetically. Rotate by damage potential:
- Credentials that move money: banking, payment processors, payroll.
- Identity roots: domain registrar, DNS, the admin accounts of your identity provider itself.
- Infrastructure roots: cloud accounts, CI/CD, code hosting.
- Long-lived machine secrets: API keys and tokens, which never expire on their own and are exactly what AI agents and integrations tend to hold.
- Everything else the leak touches.
After each rotation, revoke active sessions and refresh tokens where the service allows it; a rotated password does not log out a live attacker.
Hour 12 to 24: prove it and say it
- Prove completion from records, not memory. An append-only audit log answers "who accessed this credential recently, and did anyone touch it after the news broke?" without interviews. This is the moment audit trails are for.
- Tell your team what changed and, if customer data was in scope, follow your notification obligations rather than your comfort level.
- Schedule the postmortem within a week: which step was slow, which credential had no owner, what gets fixed.
The uncomfortable question the news is asking you
Every headline breach is also a question about your own vendor: if they were breached instead, what would the attacker have? If the honest answer is "our plaintext", the fix is architectural, not procedural. A zero-knowledge vault changes the answer to "ciphertext they cannot open", which is why we built Keyvaci so that even we cannot read what you store. Rotation drills still matter; needing them less is better.
Make the next headline someone else's fire drill
14 days, every feature, no credit card. Sign in with company SSO or a plain email address.