What to do after a data breach: the first 72 hours

In the first 72 hours after a data breach you need to do four things, roughly in this order: contain it, preserve the evidence, work out what data was affected and whose, and decide who you have to tell. Speed matters most in the EU and the UK, where a reportable breach generally has to go to the regulator within 72 hours of you becoming aware of it. Elsewhere the deadlines differ, but the first steps are the same.

Hour zero: stop the damage, keep the evidence

Take a bookkeeping firm in Bristol with 14 staff. On a Tuesday morning a client rings: she’s had an email, apparently from the firm, asking her to pay a £6,200 invoice to new bank details. It turns out someone has been inside a partner’s mailbox for three weeks, reading client files and setting up forwarding rules.

The instinct is to wipe everything and start fresh. Don’t, at least not yet. You need to shut the attacker out without destroying the trail that shows what they saw.

If it’s ransomware, don’t pay anything before you’ve taken advice. Paying doesn’t guarantee your data comes back or stays private, and in the US and some other countries a payment to a sanctioned group creates legal trouble of its own.

Call the right people early

Most small businesses don’t have an incident response team. You borrow one.

Timeline of the first 72 hours after a breach: hours 0 to 4 contain the breach, preserve evidence and call the insurer; hours 4 to 24 work out what data was affected and whose; hours 24 to 72 decide who to notify, with the EU and UK regulator deadline at 72 hours
A realistic order of work for the first three days.

Work out what was taken, and whose

Your notification duties depend on facts you probably don’t have yet. The job over the first day or two is to gather enough of them to make decisions.

  1. Which systems and accounts were accessed, and for how long?
  2. What kinds of personal data were in them? Names and emails are one thing. Bank details, passport scans, health information and passwords are another.
  3. Whose data is it: customers, staff, your clients’ customers? Roughly how many people, and in which countries?
  4. Was the data encrypted, and was the key exposed too?
  5. Is there evidence the data was copied out, or only that it could have been?
  6. Are you in charge of that data, or handling it for a client under a data processing agreement?

That last question matters more than people expect. An agency that runs email campaigns for clients is usually a processor. Its first duty is to tell the affected clients quickly, and the clients decide about regulators and individuals.

You won’t have perfect answers by hour 72, and that’s normal. Regulators in the EU and the UK accept reports in stages, with more detail to follow.

Who you have to tell, and how fast

Decision flow for EU and UK breach notification: if personal data is involved and the breach is likely to risk people’s rights, notify the regulator within 72 hours where feasible; if the risk is high, also tell the affected people without undue delay; in every case record the breach internally
The EU and UK notification test. US states, Canada and Australia use their own tests.

EU and UK

Under the GDPR and the UK GDPR, a controller has to report a personal data breach to the regulator without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. If the risk is high, you also have to tell the affected people directly, without undue delay. And you have to keep an internal record of every breach, including the ones you decide not to report.

United States

Every state has its own breach notification law. They differ on what counts as personal information, whether encrypted data is exempt, whether the state attorney general must be told, and how fast you must act. Many say “without unreasonable delay,” and some set outer limits such as 30, 45 or 60 days. Health data under HIPAA has its own rules, with notice to individuals no later than 60 days after discovery, and public companies face separate disclosure rules for material cyber incidents.

Canada, Australia and the UAE

In Canada, businesses under the federal private sector law must report breaches that create a real risk of significant harm to the Privacy Commissioner and affected people as soon as feasible, and keep records of all breaches. Australia’s scheme requires businesses covered by the Privacy Act to assess a suspected breach promptly (generally within 30 days) and notify the regulator and affected people as soon as practicable if serious harm is likely. In the UAE, it depends on whether you fall under the federal data protection law or a free zone regime such as the DIFC or ADGM, each with its own notification rules.

WhereTelling the regulatorTelling individuals
EU and UKWithout undue delay, within 72 hours where feasibleWithout undue delay if the risk is high
US statesVaries; some states require attorney general notice above a set number of residentsVaries; often without unreasonable delay, with some 30 to 60 day limits
Canada (federal)As soon as feasible, if there’s a real risk of significant harmAs soon as feasible, same test
AustraliaAs soon as practicable for eligible breachesAs soon as practicable, same test

Check your contracts too

Regulators aren’t the only ones with deadlines. Customer contracts, especially with larger clients, often require you to report a security incident within 24 to 72 hours, sometimes to a named email address. Miss that and you’ve got a contract breach on top of a data breach.

What to tell people

When you notify individuals, write plainly. Say what happened, what data was involved, what you’ve done about it, what they should do (change a password, watch for phishing, call their bank) and who to contact. Don’t guess, and don’t call it a “sophisticated attack” unless it really was. A phished password isn’t sophisticated, and people can tell.

Keep the story consistent across what you tell regulators, clients and the public. Three versions of events is a gift to anyone who later wants to argue you misled them.

After the first 72 hours

This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.