Data breach? A clear action plan for the first 72 hours
In a data breach every minute counts. A practical plan: what to do immediately, when to report to the data protection authority, and how to prevent a repeat.
By Limburg Cyber Group
A misaddressed email with an attachment, a stolen laptop, a hacked account: a data breach happens in a heartbeat. At such a moment, a cool head and a clear action plan make the difference. Here is what to do in the first hours.
Step 1: limit the damage (immediately)
Deal with the breach itself first. Revoke access to a hacked account, change passwords, disconnect an infected device, or try to recall a wrongly sent message. Goal: prevent more data from leaking.
Step 2: record what happened
Note the facts: what leaked, which (personal) data is involved, how many people are affected, when and how was it discovered? You need this documentation for your assessment and for a possible report.
Step 3: assess whether you must report
Under the GDPR there is a data breach reporting duty. The main rules:
- Is there a risk to the individuals? Then you report it within 72 hours to the data protection authority.
- Is the risk high (for example sensitive data)? Then you must also inform the individuals themselves.
- Is a real risk unlikely? Then you need not report, but do record your reasoning.
If you also fall under NIS2, the NIS2 reporting duty may apply as well, towards a different authority. Two tracks you should not confuse.
Step 4: inform who needs to know
Besides the authority and the individuals: think of your processors, any insurer, and internally the responsible people. Communicate honestly and factually; covering up always makes it worse.
Step 5: prevent a repeat
Once the dust has settled, look back: how could this happen, and which measure prevents it next time? Often those are basic things, MFA, awareness of phishing, or better agreements on data sharing.
Prepare now, not later
The time to think about data breaches is now, not during an incident. We help you set up a simple incident and reporting process, so that in the heat of the moment you know what to do. See our cybersecurity service or book a conversation.
Read more
Passkeys for your business: logging in without a password, and hard to phish
Passkeys replace the password with a key on your device that will not work on a fake site. What they are, what to watch for and how to start sensibly.
Securing your company website: the maintenance nobody gets round to
Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.
QR code phishing: how quishing works and how your team can spot it
Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.