Appoint one incident lead
Give one person authority to coordinate technical, legal, operational and communications work. Move sensitive discussions to a trusted channel if normal email or messaging may be affected.
Practical incident response
Stay calm and collect the facts
What to do when your organisation—or a provider you rely on—may have suffered a data breach. Start with the facts, protect people, and keep a record of every decision.
If an attack is still in progress, treat this as an emergency.
Use trusted incident-response support and the UK government's reporting route. If money has been stolen, contact your bank immediately. Do not rely on this general checklist instead of professional advice.
These actions apply whether the first warning came from your own systems, a customer, a researcher or a supplier.
Give one person authority to coordinate technical, legal, operational and communications work. Move sensitive discussions to a trusted channel if normal email or messaging may be affected.
Record when you first became aware, who reported it, known facts, decisions, owners and times. Keep facts separate from assumptions. The UK GDPR reporting clock may already be running.
Protect relevant logs, alerts, emails, system images and supplier notices before they expire or are overwritten. Do not wipe, rebuild or delete affected systems until an incident specialist confirms it is safe.
Isolate affected systems where safe, revoke exposed sessions and tokens, block confirmed malicious access, and protect clean backups. Use a known-clean device for sensitive account changes.
Identify the systems, people, personal data, business services and suppliers involved. Check whether data may have been viewed, changed, destroyed or made unavailable.
Notify senior leadership, your data protection lead, insurer, legal adviser and incident-response provider as appropriate. Check policy and contract conditions before taking actions that could affect cover or evidence.
Work in parallel where you can. The order is a guide, not permission to delay urgent containment or reporting.
A provider announcement starts your assessment. It does not finish it.
Not every security incident is a personal data breach, and not every personal data breach must be reported to the ICO. Every breach must still be assessed and recorded.
If a personal data breach is likely to create a risk to people's rights and freedoms, notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. Further information can follow in phases.
Where the breach is likely to create a high risk for people, tell them without undue delay. Explain what happened, likely consequences, what you are doing and practical steps they can take.
Use a shared, controlled record and restrict access because it may contain sensitive information. If you would rather not build one from scratch, Incident Watch keeps a timestamped, tamper-evident record alongside the 72-hour clock — on every plan, including free.
Store only what the response needs, limit access, and apply an appropriate retention period. Avoid copying exposed personal data into general chat, ticketing or email systems merely for convenience.
This page tells you what to do. Incident Watch is where you do it — a live watch for one breach, built around the incident rather than a domain, because a breach usually involves more than one organisation and the person managing it is often not the one who was breached.
Free on every plan— one live incident at a time, and you keep access to everything you record whatever plan you are on. Publicly published news and statements only; it is not a substitute for your provider's notifications or your own regulatory assessment.
Open an incident — free