Data breach response: what to do first
A possible data breach rarely announces itself clearly. It might be a misdirected email, a lost laptop, an exposed database, a supplier telling you their systems were compromised, or simply a feeling that something you hold has been accessed by someone who should not have it.
This page sets out how to work through the uncertainty calmly: what to check first, what to preserve, who typically needs to be told and by when, and where Cyber Crisis Desk turns those steps into a tracked case rather than a scramble.
Signs a breach may have occurred
- A colleague, customer or supplier reports receiving data that is not theirs.
- A device holding customer, staff or financial records is lost, stolen or left unlocked.
- A cloud storage folder, spreadsheet or database link was shared more widely than intended.
- A vendor or processor notifies you that their systems were compromised and your data may be affected.
- Unusual export, download or query activity appears in a system that holds personal or sensitive data.
- An email was sent to the wrong recipient list, or an attachment contained more than intended.
- You find personal data offered or referenced somewhere it should never appear.
Safe immediate actions, in order
- Contain the exposure first. Revoke a shared link, disable a compromised account, or recall a message where the platform allows it, before doing anything else.
- Establish the basic facts calmly. What data, whose data, how much, and how it was likely accessed or disclosed. Avoid guessing beyond what you can actually confirm.
- Identify the system or file involved and who has access to it, so you can check logs before they roll over or are overwritten.
- Change credentials for any account that may have been used to access or exfiltrate the data.
- Note the discovery time precisely. Many notification deadlines run from when you became aware, not from when the breach actually happened.
- Loop in whoever holds authority to decide next steps — an owner, director or data-protection contact — rather than making the call alone if you can avoid it.
- Start a written timeline covering what was found, when, and what action was taken, updated as you go rather than reconstructed later.
Evidence worth preserving
Regulators, insurers and affected individuals will all ask similar questions. Capturing the following early saves having to reconstruct it under pressure later.
- Access and download logs for the affected system, covering the relevant time window.
- A copy or precise description of the data fields involved (not the data itself, where avoidable).
- The message, link, file-share setting or configuration that caused or allowed the exposure.
- A list of who had or could have had access, and when that access changed.
- Correspondence with any vendor or processor involved.
- A running timeline: discovery, containment steps, decisions, and who made them.
What to avoid
- Do not delete logs, files or accounts before you have captured what you need — even to “tidy up” — as this removes the record of what happened.
- Do not speculate publicly or to affected individuals about scope or cause before you have reasonably confirmed it. Correcting an early guess is harder than waiting.
- Do not attempt to trace, access or investigate any third party's systems. Cyber Crisis Desk is strictly defensive: no hack-back, no unauthorised investigation.
- Do not assume a small-looking exposure is automatically below any reporting threshold — that assessment depends on the data and the risk to individuals, not the volume alone.
- Do not wait for full certainty before starting containment and internal notification.
Who to involve
- Your data-protection authority — many jurisdictions set a strict notification clock once you become aware of a likely reportable breach; in the UK that is the ICO, with a 72-hour expectation for qualifying breaches, and other countries run their own deadlines and thresholds. Check the applicable rule for where you and your data subjects are based, early.
- Your insurer — if you hold cyber or data-liability cover, notify promptly; some policies require notice within a set window to remain valid.
- Affected individuals — where the exposure creates a real risk to them, clear and timely communication is usually expected, even where a regulator filing is not.
- Any data processor or vendor involved — to confirm what they can see on their side and what containment steps they have already taken.
- Your bank — if financial account details were part of the exposed data.
Cyber Crisis Desk does not decide notifiability for you and does not file reports on your behalf. It helps you assemble the facts a regulator, insurer or legal adviser will ask for, in one place.
How Cyber Crisis Desk helps
A free emergency triage asks what happened, what kind of data may be involved and whether the exposure is ongoing. From that, the platform selects a data-exposure playbook and builds an Immediate Rescue Plan grouped by urgency.
- Client Next Action keeps containment, fact-finding and notification tasks in a sensible order instead of everything arriving at once.
- Evidence requests tell you exactly what logs, screenshots and descriptions to capture, stored in your private case.
- A running timeline records discovery time, decisions and actions as they happen, ready to hand to a regulator, insurer or adviser.
- Structured reports turn the case into a document you can share with the parties who need it.
- Monitoring and closure keeps the case open until follow-up checks are actually complete.
See how the guided workflow fits together or compare the plans and the one-time Emergency Pass.
Clear limitations
- We do not decide notifiability for you. Whether a breach must be reported to a regulator or affected individuals depends on your jurisdiction, the data involved and the assessed risk — that judgement rests with you and, where appropriate, your legal adviser.
- We do not provide legal advice or make legal determinations of any kind.
- We cannot access, change or investigate systems on your behalf; only you or your administrator can perform containment actions.
- This is guided response, not a substitute for a qualified incident-response team or legal counsel where an incident is severe, regulated or contested.
Common questions
- How do I know if a breach is 'reportable'?
- It depends on the data involved, the number of people affected and the likely risk to them, assessed against the rules that apply where you and your data subjects are based. Cyber Crisis Desk helps you gather the facts; the notifiability decision itself needs your own judgement or legal advice.
- Do I need to tell customers even if I'm not sure data was actually taken?
- Many organisations choose to communicate proactively once a credible risk exists, even before full certainty. Waiting for complete confirmation can mean missing deadlines that run from when you became aware.
- What if the breach happened at a supplier, not us?
- You may still hold obligations to your own customers or staff even when the underlying failure was a vendor's. Get written confirmation from the supplier of what happened and when, and treat it as part of your evidence.
- Can Cyber Crisis Desk file the regulator report for us?
- No. We are not a legal or regulatory filing service. We help you organise the timeline, evidence and facts so that you, or whoever files on your behalf, can do so accurately and on time.
Related incident help
- Small-business incident responseCoordinate a response when you have no internal security team.
- Business email compromiseInvoice and payment fraud through a trusted mailbox — contain it and involve your bank.
- Hacked email accountRegain access, remove attacker persistence and check what was read or sent.
- Website hacked or defacedContain a compromised site, preserve logs and rebuild safely.
Work through it with a plan
Emergency triage is free and takes a couple of minutes.