Running a live incident

A breach has already happened. This is where you run it.

The clock, the record and the coverage in one place

Most of a breach is not the technical work. It is knowing when the clock started, keeping a record that will hold up months later, and answering the same questions from your board, your insurer and possibly the ICO — while the supplier who was breached tells you very little.

If it has only just happened, start with the playbook.

The data breach response playbook covers the first hour: containment, preserving evidence, the UK reporting decision and what to ask a breached supplier. Read that first, then open an incident to keep track of having done it.

How it works

This is the one part of MyDomainRisk that is not organised around a website. A breach usually involves several organisations, and the person managing it is often not the one who was breached — your supplier lost the data, and you are the one who has to account for it.

1

Name the incident and record when you became aware

That date is the one the whole thing hangs on — the 72-hour clock runs from it, not from when the breach happened or when the news broke. Recording it deliberately, at the start, is what lets you point to it later.

2

Add the organisations involved

Yours, the supplier who was breached, and anyone else caught up in it. Each one gets the role it plays in this incident: the supplier who lost the data is usually the processor, and the organisation whose data they held is usually the controller.

3

Give us their incident or status page

Saving an organisation reads its own website straight away, along with any status page you give and the incident pages that page points to or names. Their statement is on your record from the start.

4

Write down what you know, as you learn it

Your own notes, the supplier's notification pasted in whole, a decision and who made it. Each entry keeps when the event happened separately from when you wrote it down.

5

Press Check for updates

We re-read every page held and collect the public coverage — dated, deduplicated and per organisation — so you can see what is new since you last looked, and whether the supplier's statement has changed.

6

Close it when it is over

A closed incident stays fully readable with everything you gathered, and frees space to open another. It can be reopened. There is no delete.

The roles are yours to state, not ours to guess. Controller and processor decide who has to report a breach, so you record them per incident — the same organisation can be a processor in one and a controller in another.

A record that will still be worth something in a year

Everything you add is timestamped and chained together, so a later change to an earlier entry can be detected. Corrections are added as new entries — nothing is rewritten, and nothing can be quietly removed.

What it holds

  • When you became aware, and the 72-hour deadline counted from it
  • The organisations involved and the role each plays in this incident
  • Your own notes, decisions and who made them
  • The supplier's notification, pasted in whole
  • Statements read from an organisation's own published incident pages
  • When each event happened, kept apart from when it was written down
  • The public coverage as it appeared, dated and per organisation
  • Corrections — added as new entries, never overwriting the old ones

Why chained entries matter

Think about who eventually reads this. A regulator, an insurer or a solicitor will ask whether the record could have been edited after the fact. A document or a notes app cannot answer that question; a chained record can.

It also means an honest correction looks like a correction. You add what you now know, against today's date, and the original stays visible — which is exactly what someone assessing your response wants to see.

And because each entry separates when something happened from when you wrote it down, the gap between the two is on the record too. That gap is often the thing you are asked about.

A written briefing, on Pro and MSP

When you want one, a plain-English briefing can be written from the record — versioned, downloadable as a PDF, and it names who prepared it. It is the document you hand to the people asking you questions.

What it covers

  • Who the parties are and what each role means in practice
  • What is established, and what is still unconfirmed
  • What has changed since the last version
  • The decision in front of you, argued both ways
  • The questions to send the supplier, ready to use
  • What the coverage establishes that nobody involved has said

You decide what it may see

It is off until you turn it on, for one incident at a time — never account-wide.

Then you choose entry by entry what may be used, and private is the default. If anything was held back, the briefing says so on its face rather than quietly reading as complete.

Earlier versions are kept — the current one in full, the rest a line each — so you can show what you understood at the time, not just what you understand now. Nothing is deleted.

It is an interpretation, not advice. A briefing is our reading of the facts on your record — not legal, regulatory, insurance or forensic advice — and every copy says so, on screen and on every page of the PDF. Duties depend on your role, sector, contracts and the people affected.

How many at once

Plans differ on how many incidents you may have open at the same time — not on what you may read.

Free

One incident at a time

The clock, the record and the coverage. Everything you record stays readable.

Pro

Five open at once

Adds the written briefing, versioned and downloadable as a PDF.

MSP

Twenty-five open at once

For running several clients' incidents side by side, each with its own briefing.

Reading is never restricted by plan. You keep access to everything you have recorded — including briefings already written — whatever plan you are on, and whatever it changes to. Closing an incident frees capacity without costing you the record.

What it will not do

Worth being plain about, because breach tooling is often sold on the opposite claim.

  • It collects publicly published news and statements only
  • It does not access criminal forums or marketplaces
  • It does not purchase data
  • It does not retain breach data or show credentials
  • It is not a substitute for your supplier's own notifications
  • It is not a substitute for your own regulatory assessment

The organisations you add here are not scanned and do not count towards your tracked-domain allowance. Adding a supplier to an incident is not the same as pointing a scanner at them.

Open an incident

Free on every plan — one live incident at a time, and you keep everything you record. If the breach is live right now, read the playbook first and open the incident alongside it.

Important: Incident Watch helps you record and track a breach. It does not provide legal, regulatory, insurance or forensic advice, and it does not decide whether an incident is reportable. Duties depend on your role, sector, contracts, the people affected and the jurisdictions involved.

Back to top