Corporate Counsel has the ten steps to take right away. Oops, the first step is "Develop Your Plan Before the Incident," so get cracking. The rest of the tips are spot on, especially Step 4:
Continue to Consult with Counsel
It is imperative that the investigation and response be conducted in consultation with and at the direction of counsel (whether in-house or outside counsel). In addition to preserving the privilege of confidential communications, consulting with counsel is important to the myriad legal issues—from notice obligations to coordinating with law enforcement to managing litigation risks—that can arise when investigating and responding to a data security breach.