Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

What to Do After a Data Breach: A Response Checklist

A calm, step-by-step guide to the first hours and days after a business data breach — what to do first, who to tell, and how to come out the other side.

A data breach is any time information you’re responsible for is lost, stolen, or exposed to someone who shouldn’t have it. That covers the dramatic version — a hacker inside your systems — but also the quiet, common ones: a laptop left on a train, a spreadsheet emailed to the wrong person, a mailbox someone phished their way into. If you’re reading this in the middle of one, take a breath. The first hour matters, but panic rarely helps. Here’s a clear order to work through.

First, contain it

Your first job isn’t to work out exactly what happened. It’s to stop it getting worse.

  • Isolate the affected systems. Disconnect the compromised device or account from the network — pull the network cable, turn off Wi-Fi, or have your IT team block it. Don’t switch machines off entirely if you can avoid it, as that can wipe evidence that helps you understand the attack later.
  • Lock out the intruder. Reset passwords on affected accounts and, crucially, anywhere the same password was reused. Force sign-out on cloud accounts and revoke active sessions.
  • Turn on or check multi-factor authentication. If an account was accessed without it, MFA is what stops the attacker walking straight back in after a password reset.

If this is a live, spreading incident — ransomware encrypting files in front of you, for instance — this is the moment to call for help rather than fight it alone. Fast, competent cyber security support in the first hour often decides how bad the whole thing gets.

Then, work out what actually happened

Once the bleeding has stopped, you assess. You’re trying to answer three questions: what data was involved, how many people it affects, and how serious the impact could be.

Be specific. “Some customer data” isn’t good enough for the decisions coming next. Was it names and emails, or names, addresses, card details and health information? A breach of low-risk marketing emails is a very different situation from a breach of financial or medical records. Write down what you find as you go — dates, times, systems, who you spoke to. You’ll need that record, and memory fades fast under stress.

This is also where you look at logs to understand the entry point. If you don’t have logging or monitoring in place, this stage is much harder, which is one of the quiet arguments for managed IT support: the evidence you need after a breach is the evidence someone had to be collecting before it.

Report it — to the right people, in time

For UK businesses, this is where the clock matters. Under UK GDPR, if a personal data breach is likely to result in a risk to people’s rights and freedoms, you must report it to the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of it. You report what you know and update them as you learn more — you don’t have to wait until you have the full picture.

Separately, consider:

  • Action Fraud (or Police Scotland) if a crime has been committed, such as fraud or extortion.
  • Your bank and card provider if financial details or payment systems are involved.
  • Your insurer, if you hold cyber insurance — many policies require prompt notification and can provide response specialists.
  • Affected individuals, if the breach is likely to cause them high risk. Tell them plainly what happened, what data was involved, and what they should do — change a password, watch for scam calls, check statements.

Some sectors carry extra duties. A law firm, dental practice or accountant will have professional or regulatory bodies that also expect to be told, so if you run one, know those obligations before you ever need them.

Recover, safely

Getting back to normal is not just flipping systems back on. If you restore a compromised environment without removing how the attacker got in, you invite them straight back.

  • Rebuild from a known-clean state. This is where good backups and continuity planning earn their keep — a recent, tested, offline-or-immutable backup is often the difference between a bad week and a closed business. If files are lost or damaged and your backups fall short, specialist data recovery may still retrieve some of what’s gone.
  • Patch the hole. Close the vulnerability, remove any malware, rotate every credential that could have been exposed, and confirm the attacker no longer has a way in before you reconnect anything.
  • Watch closely afterwards. Attackers often return. Keep a close eye on accounts and systems for unusual activity in the weeks that follow.

Afterwards, learn from it

When trading is back to normal, hold a short, blame-free review. How did it happen? What was slow or missing? What would you change? Most breaches trace back to a handful of ordinary gaps: reused passwords, missing MFA, an unpatched system, a convincing phishing email, or a backup nobody had ever tested. Fixing those is far cheaper than living through a second incident.

Write down the improvements and actually make them. Keep your written record of the whole event too — the ICO expects you to document breaches even when they don’t meet the reporting threshold.

Who this is for — and when to get help

Every business that holds customer or staff information needs a plan for this, not just big ones. Small firms are targeted precisely because attackers assume the defences are thinner. You don’t need a thick binder — a single page covering “who we call, what we shut down first, where our backups are, who we have to tell” puts you miles ahead of most.

The best time to prepare is before anything happens. If you’re not confident your business could contain, report and recover from a breach cleanly, we’re happy to talk it through — from tightening your cyber security and testing your backups to being the people you call when something does go wrong. Reach us any time via our contact page; a calm plan now is worth a great deal on a bad day.

Frequently asked questions

How quickly do I have to report a breach to the ICO?

If the breach is likely to risk people's rights and freedoms, UK GDPR gives you 72 hours from becoming aware of it to report to the Information Commissioner's Office. You don't need every detail to start — you can report what you know and follow up. If a breach is unlikely to pose a risk, you may not need to report it at all, but you must still record it internally.

Should I pay a ransomware demand to get my data back?

UK guidance, including from the National Cyber Security Centre, is not to pay. Payment doesn't guarantee you get your data back or that it hasn't already been copied, and it marks you as a target for repeat attacks. A tested backup is what actually gets you trading again, which is why sorting backups before an incident matters so much.

Do I have to tell customers if their data was involved?

If a breach is likely to result in a high risk to affected individuals, you must tell them without undue delay, in plain language, explaining what happened and what they can do. Even when the legal bar isn't met, telling people honestly is usually the right call — it protects trust far better than a leak they discover later.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.