Free initial consultation · Flexible ongoing and project-based services Speak to our team: 020 3048 4048

What to Do After a Data Breach: A Step-by-Step Guide for UK Businesses

By Published 8 June 2026 8 min read
Quick answer: Contain the breach first, then work out what data was affected, then report to the ICO within 72 hours if it’s likely to put people’s rights and freedoms at risk. Tell affected individuals if the risk to them is high, document everything as you go, and fix the root cause once the immediate crisis is over. How you respond in the first few hours matters more than the breach itself for how much damage it does.

A data breach doesn’t have to mean disaster, but how you respond in the first few hours determines how much damage it causes to your customers, your reputation, and your legal standing. According to the UK Government’s Cyber Security Breaches Survey 2025/2026, 43% of UK businesses, around 612,000 organisations, experienced a cyber security breach or attack in the past year. If it happens to you, here’s exactly what to do.

72 hoursdeadline to report a notifiable breach to the ICO
43%of UK businesses reported a breach in the past year
£17.5m or 4%maximum fine, whichever is higher
7steps to work through, in order

Stay Calm, Move Fast

The worst thing you can do is panic and start deleting things. The second worst is doing nothing. Your goal in the first few minutes is to understand what’s happened and stop it spreading. Get the right people in the room, assign someone to lead the response, and work through the steps below in order.

1Contain the Breach

Before anything else, stop the breach from spreading. If a device has been compromised, disconnect it from your network, but don’t switch it off; powering down a server can destroy forensic evidence you may need later.

Change passwords on any affected accounts immediately. If login credentials were part of the breach, assume every account using those credentials is at risk. Revoke access tokens, close unauthorised sessions, and block suspicious IP addresses if your firewall allows it. Your cyber security team should lead this stage.

2Work Out What Was Affected

Once you’ve contained the immediate threat, work out exactly what was compromised. You need to know what types of personal data were involved (names, email addresses, financial data, health records), how many people are affected, whether the data was accessed, copied, or deleted, whether it was encrypted, and whether it could be used to cause harm such as identity theft, fraud, or discrimination.

Write everything down as you go. You’ll need this for your ICO report and your internal breach log.

3Report to the ICO Within 72 Hours

Under UK GDPR, you must report a personal data breach to the Information Commissioner’s Office within 72 hours of becoming aware of it, if the breach is likely to result in a risk to people’s rights and freedoms. The clock starts from the moment you discover the breach, not when it occurred.

You report online via the ICO’s breach reporting portal. The form is designed to be completed quickly. You don’t need all the information upfront; submit what you have and follow up with more detail later.

Not every breach needs reporting. If it’s unlikely to cause real risk to individuals, for example if the data was strongly encrypted and remains unreadable, you may not need to report to the ICO. But you must still document it: keep a written record of what happened, your risk assessment, and the reasons you decided not to report. That log is your proof of compliance if the ICO ever asks.

What to include in your report: a description of what happened and when, the types and approximate volume of personal data involved, the likely consequences, the steps you’ve taken to address it, and your contact details. The ICO allows follow-up submissions, so don’t let missing information stop you reporting within the 72-hour window.

4Tell the People Affected

If the breach is likely to result in a high risk to the individuals involved, you must contact them directly and without undue delay. Be honest and clear: tell them what happened, what data was involved, the potential consequences, and what steps they should take to protect themselves, such as changing passwords or monitoring their bank accounts. Don’t be vague. People need to know what’s actually at risk.

5Communicate Internally, Carefully

Brief your senior leadership team before anyone else. Appoint one spokesperson to handle press or customer enquiries so your messaging stays consistent. Don’t speculate publicly about the cause or blame before you have the full picture; misinformation spreads fast and makes a bad situation significantly worse.

If you work with a managed IT support provider, loop them in immediately. A good IT partner will have handled incidents like this before and can guide you through containment and recovery calmly and methodically.

6Document Everything

UK GDPR requires organisations to keep a written record of all personal data breaches, including ones that didn’t need to be reported to the ICO. Your breach log should cover what happened, when you became aware of it, what data was affected, how many people were involved, your risk assessment, the actions you took, and the reasoning behind your decisions.

This documentation is your legal protection. A clear, thorough log shows the ICO you took the breach seriously and responded responsibly.

7Find the Root Cause and Fix It

Once the immediate crisis is over, work out how the breach happened. Was it a phishing email that caught a staff member off guard, a weak password, an unpatched system, or a supplier with inadequate security? Find the root cause and fix that, rather than just the symptom.

Review your access controls, update your security policies, and check whether your team needs refreshed cyber security awareness training. If the breach came through your website, our guides on common WordPress security mistakes and building an IT audit checklist are good starting points for finding what else needs tightening. A breach is an expensive lesson; make sure it doesn’t happen twice for the same reason.

Data Breach Response Checklist

  • Affected device or account isolated from the network, without powering anything down
  • Passwords changed and sessions revoked on every account that could be affected
  • What data was involved, how much, and how sensitive it is, written down as you go
  • A decision made, and documented, on whether the breach meets the ICO reporting threshold
  • ICO report submitted within 72 hours of becoming aware, if it meets the threshold
  • Affected individuals contacted directly if the risk to them is high
  • One spokesperson agreed for any internal or external communication
  • A written breach log completed, even if the breach wasn’t reportable
  • Root cause identified and a fix scheduled, not just the immediate symptom patched
What happens if you don’t report a notifiable breach: The ICO can fine organisations up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious infringements of UK GDPR (ICO, maximum fine under UK GDPR and DPA 2018). Failing to report a notifiable breach on time is itself an infringement, separate from the underlying incident. Don’t assume that because a breach seems minor, there’s nothing to do.

Be Ready Before the Next Incident

The best time to prepare for a data breach is before one happens. That means having a written incident response plan, making sure every team member knows their role in it, keeping software patched and up to date, and training staff to recognise phishing attempts before they click. Our remote IT support and cyber security services help UK businesses stay ahead of threats rather than dealing with the fallout afterwards.

If you don’t have an incident response plan in place, or you’re not confident in your current security setup, get in touch. We’ll carry out a free IT and security review and tell you exactly where the gaps are.

Frequently Asked Questions

Does every data breach need to be reported to the ICO?

No. You only need to report to the ICO if the breach is likely to result in a risk to people’s rights and freedoms. You must still document every breach, reportable or not, and keep that record on file.

How long do I have to report a data breach in the UK?

Under UK GDPR, you have 72 hours from the moment you become aware of a personal data breach to notify the ICO, if the breach meets the reporting threshold. You can submit an initial report and add more detail in a follow-up later.

Do I have to tell the people whose data was breached?

Only if the breach is likely to result in a high risk to those individuals. If so, you must contact them directly, without undue delay, and give clear information about what happened and how to protect themselves.

What if a third-party supplier caused the breach?

You’re still responsible. If a supplier processes your data and suffers a breach, they must notify you without undue delay. You then assess whether to report it to the ICO. Don’t assume the supplier will handle it for you; the obligation sits with you as the data controller.

What is the fine for not reporting a breach to the ICO?

The ICO can issue fines of up to £17.5 million or 4% of global annual turnover for serious UK GDPR infringements, including failure to report a notifiable breach. The size of any fine depends on the severity of the breach, your response, and your compliance track record.

What is the difference between a cyber attack and a personal data breach?

A cyber attack is an attempt to compromise your systems. A personal data breach is the result, the accidental or unlawful loss, destruction, or disclosure of personal data. Not every cyber attack results in a data breach, but many do, and both need a prompt, structured response.

Dealing With a Breach Right Now?

Get in touch and we’ll help you contain it, work out what’s required, and get your systems back on solid ground.

Get in Touch

A data breach is stressful, but it’s manageable if you work through it in order: contain, assess, report, notify, communicate, document, and fix the cause. Businesses that treat it as a structured process, not a panic, come out the other side with their customers’ trust and the ICO’s confidence largely intact.

About the author

Kevin Marshal

Kevin Marshal is a content writer at UK IT Services, a UK-based IT support, cyber security and digital agency. He turns complex technology topics into clear, practical guidance that business owners and decision-makers can actually use. Drawing on the expertise of the wider UK IT Services team, Kevin writes about managed IT support, cyber security, Microsoft 365, web design and development, and digital marketing, always with a focus on what works for small and medium-sized UK businesses. His goal is simple: help organisations make smarter, safer technology decisions without the jargon.

Latest insights

Talk to a UK-based IT specialist

Managed IT support, cyber security and digital services for businesses across the UK.

Get a Free Consultation
Call Us Free Consultation