What to do after a data breach: the first 72 hours
In the first 72 hours after a data breach you need to do four things, roughly in this order: contain it, preserve the evidence, work out what data was affected and whose, and decide who you have to tell. Speed matters most in the EU and the UK, where a reportable breach generally has to go to the regulator within 72 hours of you becoming aware of it. Elsewhere the deadlines differ, but the first steps are the same.
Hour zero: stop the damage, keep the evidence
Take a bookkeeping firm in Bristol with 14 staff. On a Tuesday morning a client rings: she’s had an email, apparently from the firm, asking her to pay a £6,200 invoice to new bank details. It turns out someone has been inside a partner’s mailbox for three weeks, reading client files and setting up forwarding rules.
The instinct is to wipe everything and start fresh. Don’t, at least not yet. You need to shut the attacker out without destroying the trail that shows what they saw.
- Reset the compromised passwords, sign the account out of every session, and turn on multi-factor authentication if it wasn’t already on.
- Find and remove what the attacker left behind: forwarding rules, new admin accounts, unfamiliar app connections.
- Isolate affected machines from the network rather than wiping them or switching them off.
- Export and secure logs (sign-ins, mailbox audit logs, firewall and server logs) before they roll over. Some systems only keep them for a few weeks.
- If money is moving, call your bank now. Payment recalls are far more likely to work within hours than days.
- Start a written timeline: who found what, when, and what you did about it.
If it’s ransomware, don’t pay anything before you’ve taken advice. Paying doesn’t guarantee your data comes back or stays private, and in the US and some other countries a payment to a sanctioned group creates legal trouble of its own.
Call the right people early
Most small businesses don’t have an incident response team. You borrow one.
- Your cyber insurer. Many policies require prompt notice and expect you to use their approved forensic firms and lawyers. Bring in someone else without asking and those costs may not be covered. Check the insurance terms, but make the call either way.
- A lawyer who handles breaches. In the US, having counsel direct the investigation can help keep the forensic report privileged, although courts don’t always agree that it is.
- Forensic IT support. Your usual IT provider may be great at fixing laptops and out of its depth here.
- Key suppliers, if the breach started in or spread through their systems.
Work out what was taken, and whose
Your notification duties depend on facts you probably don’t have yet. The job over the first day or two is to gather enough of them to make decisions.
- Which systems and accounts were accessed, and for how long?
- What kinds of personal data were in them? Names and emails are one thing. Bank details, passport scans, health information and passwords are another.
- Whose data is it: customers, staff, your clients’ customers? Roughly how many people, and in which countries?
- Was the data encrypted, and was the key exposed too?
- Is there evidence the data was copied out, or only that it could have been?
- Are you in charge of that data, or handling it for a client under a data processing agreement?
That last question matters more than people expect. An agency that runs email campaigns for clients is usually a processor. Its first duty is to tell the affected clients quickly, and the clients decide about regulators and individuals.
You won’t have perfect answers by hour 72, and that’s normal. Regulators in the EU and the UK accept reports in stages, with more detail to follow.
Who you have to tell, and how fast
EU and UK
Under the GDPR and the UK GDPR, a controller has to report a personal data breach to the regulator without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. If the risk is high, you also have to tell the affected people directly, without undue delay. And you have to keep an internal record of every breach, including the ones you decide not to report.
United States
Every state has its own breach notification law. They differ on what counts as personal information, whether encrypted data is exempt, whether the state attorney general must be told, and how fast you must act. Many say “without unreasonable delay,” and some set outer limits such as 30, 45 or 60 days. Health data under HIPAA has its own rules, with notice to individuals no later than 60 days after discovery, and public companies face separate disclosure rules for material cyber incidents.
Canada, Australia and the UAE
In Canada, businesses under the federal private sector law must report breaches that create a real risk of significant harm to the Privacy Commissioner and affected people as soon as feasible, and keep records of all breaches. Australia’s scheme requires businesses covered by the Privacy Act to assess a suspected breach promptly (generally within 30 days) and notify the regulator and affected people as soon as practicable if serious harm is likely. In the UAE, it depends on whether you fall under the federal data protection law or a free zone regime such as the DIFC or ADGM, each with its own notification rules.
| Where | Telling the regulator | Telling individuals |
|---|---|---|
| EU and UK | Without undue delay, within 72 hours where feasible | Without undue delay if the risk is high |
| US states | Varies; some states require attorney general notice above a set number of residents | Varies; often without unreasonable delay, with some 30 to 60 day limits |
| Canada (federal) | As soon as feasible, if there’s a real risk of significant harm | As soon as feasible, same test |
| Australia | As soon as practicable for eligible breaches | As soon as practicable, same test |
Check your contracts too
Regulators aren’t the only ones with deadlines. Customer contracts, especially with larger clients, often require you to report a security incident within 24 to 72 hours, sometimes to a named email address. Miss that and you’ve got a contract breach on top of a data breach.
- Look for incident reporting terms in your DPAs and main service agreements, and follow the notices clause to the letter.
- Check whether breaches fall under an indemnity, and whether the limitation of liability has a separate, higher cap for data incidents.
- If a supplier caused the breach, check what your contract with them says about cooperation and costs.
What to tell people
When you notify individuals, write plainly. Say what happened, what data was involved, what you’ve done about it, what they should do (change a password, watch for phishing, call their bank) and who to contact. Don’t guess, and don’t call it a “sophisticated attack” unless it really was. A phished password isn’t sophisticated, and people can tell.
Keep the story consistent across what you tell regulators, clients and the public. Three versions of events is a gift to anyone who later wants to argue you misled them.
After the first 72 hours
- Finish the investigation and send any follow-up information to regulators.
- Update your breach log with the facts, your decisions and the reasons behind them.
- Fix the root cause. For small businesses it’s usually missing multi-factor authentication, reused passwords or an unpatched system.
- Write a one-page incident plan with phone numbers, so next time nobody is hunting for the insurer’s policy number at 11pm.
- Review your DPAs and customer contracts for breach terms you can actually meet. LegalWolf can flag short notice deadlines and uncapped liability for data incidents.
This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.