What it means
A laptop containing customer files goes missing, and the business needs to know whether its contents were encrypted, whether anyone accessed them and which customers are at risk. A prepared plan lets the right people start those checks without improvising under pressure.
Define what staff should report, because a stolen device, misdirected email, unauthorised account access or exposed cloud folder can all merit investigation. Provide an emergency contact route with alternates, since security, operations, legal, privacy and communications may each have roles, and one incident lead should coordinate decisions and a log even if specialists perform the technical work.
Preserve relevant evidence while limiting harm by isolating a compromised account or system where appropriate, revoking access and capturing logs before they disappear. Avoid wiping a device or deleting messages without considering the investigation.
Establish what information was involved, how many records, who could access it and for how long, because sensitive health or financial data may pose different risks from an internal brochure. Identify the organisation's role, as a service provider processing data for a customer may have a contractual duty to tell that customer while the customer may decide regulatory notice.
Review the actual agreement and applicable law rather than assuming one universal route. The UK Information Commissioner's Office says certain personal-data breaches must be reported within 72 hours of awareness where feasible, and high-risk cases require telling affected people without undue delay.
Not every UK breach is reportable, and other regimes have different thresholds and clocks. A plan should include a legal decision point as soon as credible facts emerge, since the ICO allows phased information in some notifiable cases, with later details supplied promptly, and a reporting clock may be running before the forensic report is complete.
Communicate carefully with affected people when required or useful, saying what happened, what is known and not known, what protective steps are available and how updates will arrive, without guaranteeing that no harm occurred before an investigation supports it. Coordinate external messages, because customers, insurers, regulators, police and staff may need different facts at different times.
Plan recovery as well as notification by restoring from trusted backups, resetting compromised credentials, removing unauthorised access and verifying systems before normal use. NIST SP 800-61 revision 3 frames incident response within preparation, detection, response and recovery, with lessons feeding back into risk management, but it is guidance and not a promise that every breach can be prevented or contained within a fixed time.
Practise with a tabletop exercise on a plausible lost-device or phishing scenario, test contact details and vendor contacts, and note gaps in authority, technical access and drafting rather than declaring a pass. Retain an incident record of chronology, evidence, decisions, risk assessment, notices and remediation, including the reason for not notifying when the rule did not require it, review the cause after stabilisation, and turn lessons into owned changes.
In practice
Real-world examples.
Example
A lost encrypted laptop triggers an investigation of its contents and access status. The response lead confirms the encryption was active and no login attempts occurred. The incident is logged with the reason no notification was required.
Example
A payroll-file exposure leads to account containment and a legal notification assessment. IT disables the exposed link and preserves access logs. Legal and HR then decide whether affected staff and any regulator must be told.
Example
A misdirected email is logged, recalled where possible and assessed for harm. The sender asks the recipient to delete the message and confirm in writing. The privacy lead records the assessment even though no notice is sent.
Formula
Calculation
Illustrative initial containment time = recorded containment time minus discovery time. If discovered at 09:00 and contained at 15:00, it is six hours; exposure may have begun earlier.
Clock illustration. Where a 72-hour reporting window runs from awareness at 09:00 on a Monday, it ends at 09:00 on Thursday. Six hours spent on containment leaves 72 - 6 = 66 hours, which is why the legal decision point should not wait for the full forensic report.Case study
Seen in the real world.
This entirely fictional example follows Palm Clinics, an invented healthcare group. A shared folder was accidentally opened to outside accounts. The team restricted access, preserved logs and assessed the records before deciding what notices were required. A later exercise found an outdated vendor contact and fixed the plan. The case does not assert a universal deadline or that a response prevents all harm.
Watch out
Common mistakes.
- Waiting for perfect forensic certainty before checking applicable notification clocks.
- Erasing logs while trying to clean up a compromised system.
- Treating an exercise as complete without assigning fixes for the gaps it found.
Questions
People also ask.
What is a data breach response plan?
A prepared route for containing, assessing, communicating and recovering from information incidents.
What are the main steps?
Detect, contain, investigate, assess duties, notify where required, recover and learn.
Do regulators need to be told?
Sometimes. Check the data, role, risk threshold and specific law rather than assuming every case is reportable.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%