top of page

What to do if data is lost or exposed, hour by hour

  • Aug 29
  • 3 min read

Updated: 3 days ago

Introduction


An email with a spreadsheet attached goes to the wrong recipient. A laptop is left on a train. A supplier tells you their system was accessed and your customer records were on it.

Each of these is a personal data breach, and in most frameworks the notification clock begins when you become aware rather than when you have established the details. Small businesses lose the first days trying to decide whether it is serious enough to be a real incident, which is exactly the period in which the response is judged. The clock does not pause while you decide whether it counts. Regulators look closely at the interval between discovery and action.


1. What to do if data is lost or exposed begins with recognising it as a breach


Broader than a hack.

A breach generally covers loss, unauthorised access, accidental disclosure and destruction. An email to the wrong person and a mislaid file both qualify, and treating only cyber incidents as breaches is the common error. Most breaches in small businesses involve no attacker at all.


2. Contain it first


Before anything else.

Recall the email if you can, ask the recipient to delete it and confirm, disable the account, or remotely wipe the device. Reducing the exposure comes before assessing or reporting it.


3. Find out what data and how many people


The assessment everything depends on.

Which categories, how many individuals, and whether anything sensitive was involved. Whether you must notify a regulator, and whether you must tell the individuals, both follow from this.


4. Know your notification deadline


Short and starting immediately.

Many regimes require notification to the regulator within around seventy-two hours of becoming aware, where the breach meets a risk threshold. Find out your jurisdiction's rule before you need it, because there is no time to research it during an incident. Knowing the number of hours in advance is most of the preparation.


5. Assess the risk to the individuals


The test for notification.

Not how embarrassing it is for the business, but what harm could come to the people whose data it was: fraud, identity theft, distress, discrimination. That assessment determines your obligations and should be recorded.


6. Tell the individuals where the risk is high


Directly and usefully.

What happened, what data was involved, what they should do, and who to contact. People handle this far better when told promptly and plainly than when they discover it later.


7. Record every breach, including the ones you do not report


An obligation in most regimes.

A log of what happened, when, the assessment, the decision and the reasoning. Regulators ask to see this, and a business that reported nothing and recorded nothing is in a considerably worse position than one that assessed and documented.


8. Tell your insurer


Early and before appointing anybody.

Cyber policies typically require prompt notification and provide response specialists. Engaging your own consultant first can compromise the cover you are relying on.


9. Fix what allowed it


The part regulators focus on.

Autocomplete in the email client, an unencrypted laptop, an account without multi-factor authentication, or a process that emailed data unnecessarily. The remedial action matters as much as the notification.

Do not conceal it. Frameworks generally treat a prompt, honest and well-documented response far more favourably than a serious breach, and they treat concealment as an aggravating factor in its own right. The instinct to keep it quiet is what turns a manageable incident into a serious one.


Conclusion


Recognise the breach immediately and act within hours rather than days.

Understand that loss, misdirected email and accidental disclosure all count, contain the exposure before assessing it, establish what data and how many people were involved, know your jurisdiction's notification deadline in advance, assess the risk to individuals rather than to the business, tell affected people promptly where the risk is high, log every breach including unreported ones, notify your insurer before engaging anybody, fix the underlying cause, and never conceal it.


Related reading


 
 
 

Comments


bottom of page