Skip to content
Cybersecurity · · 2 min read

Data breach? A clear action plan for the first 72 hours

In a data breach every minute counts. A practical plan: what to do immediately, when to report to the data protection authority, and how to prevent a repeat.

By Limburg Cyber Group

A misaddressed email with an attachment, a stolen laptop, a hacked account: a data breach happens in a heartbeat. At such a moment, a cool head and a clear action plan make the difference. Here is what to do in the first hours.

Step 1: limit the damage (immediately)

Deal with the breach itself first. Revoke access to a hacked account, change passwords, disconnect an infected device, or try to recall a wrongly sent message. Goal: prevent more data from leaking.

Step 2: record what happened

Note the facts: what leaked, which (personal) data is involved, how many people are affected, when and how was it discovered? You need this documentation for your assessment and for a possible report.

Step 3: assess whether you must report

Under the GDPR there is a data breach reporting duty. The main rules:

  • Is there a risk to the individuals? Then you report it within 72 hours to the data protection authority.
  • Is the risk high (for example sensitive data)? Then you must also inform the individuals themselves.
  • Is a real risk unlikely? Then you need not report, but do record your reasoning.

If you also fall under NIS2, the NIS2 reporting duty may apply as well, towards a different authority. Two tracks you should not confuse.

Step 4: inform who needs to know

Besides the authority and the individuals: think of your processors, any insurer, and internally the responsible people. Communicate honestly and factually; covering up always makes it worse.

Step 5: prevent a repeat

Once the dust has settled, look back: how could this happen, and which measure prevents it next time? Often those are basic things, MFA, awareness of phishing, or better agreements on data sharing.

Prepare now, not later

The time to think about data breaches is now, not during an incident. We help you set up a simple incident and reporting process, so that in the heat of the moment you know what to do. See our cybersecurity service or book a conversation.

Read more

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.