Updated: February 2024 • Reading time: 11 minutes

Discovering that your personal data or your organization's data has been breached triggers an immediate cascade of questions. What happened? How bad is it? Who needs to know? The actions you take in the first 24 hours have an outsized impact on the outcome. A methodical, well-rehearsed response limits damage, preserves evidence, satisfies legal obligations, and maintains trust with the people whose data was exposed.

This guide provides a step-by-step action plan for responding to a data breach, whether you are an individual whose personal accounts have been compromised or a business responsible for protecting customer data.

Phase 1: Contain the Breach (First Hour)

Your immediate priority is stopping the breach from getting worse. The specific containment actions depend on the nature of the breach, but these steps apply to most scenarios:

  1. Disconnect Affected Systems

    If the breach involves an active intrusion, disconnect affected systems from the network immediately. Pull the Ethernet cable or disable Wi-Fi rather than shutting down the system, as shutdown destroys volatile evidence in memory. If the breach affects a cloud service, revoke access keys, rotate credentials, and terminate suspicious sessions from the service's admin console.

  2. Change Compromised Credentials

    Change passwords for any accounts known or suspected to be compromised. Start with the most critical accounts: email (which can be used to reset other passwords), banking, cloud infrastructure, and administrative accounts. Use a clean device for password changes, not a potentially compromised one.

  3. Preserve Evidence

    Take screenshots of any unusual activity, error messages, or suspicious files. Save log files, network traffic captures, and system images before they are overwritten. This evidence is essential for understanding what happened and may be required for law enforcement or regulatory investigations.

  4. Activate Your Incident Response Team

    For organizations, notify your designated incident response team immediately. This team should include IT security, legal counsel, communications, and senior leadership. If you do not have an internal team, contact a third-party incident response firm that can be deployed quickly.

Key Point: Move quickly on containment, but do not rush past the evidence preservation step. Understanding the full scope of the breach requires forensic evidence that is easily destroyed by hasty cleanup actions. Isolate systems, but do not wipe them until evidence has been collected.

Phase 2: Assess the Damage (Hours 1-4)

Once the immediate threat is contained, determine the scope and nature of the breach:

  1. Identify the breach type. Was it a credential theft (phishing, password reuse), a system vulnerability exploit, an insider threat, a lost or stolen device, or a third-party vendor compromise? The breach type determines your notification obligations and remediation priorities.
  2. Determine what data was accessed or stolen. Personally identifiable information (PII) such as names, email addresses, and phone numbers carries different notification requirements than financial data, health records, or authentication credentials. Be specific about what was exposed, as vague descriptions erode trust.
  3. Estimate the number of affected individuals. This number determines your regulatory notification obligations. Most data breach notification laws have thresholds that trigger mandatory reporting, and the timeline for notification often depends on the number of affected individuals.
  4. Identify the root cause. Understanding how the breach occurred is essential for preventing recurrence. Was a server left exposed without authentication? Did an employee fall for a phishing email? Was a software vulnerability left unpatched? Document the chain of events that led to the exposure.
  5. Check whether the data is publicly available. Search for the compromised data on paste sites, dark web forums, and data breach notification services like Have I Been Pwned. If the data is already circulating, your notification timeline becomes more urgent.

Phase 3: Notify Affected Parties (Hours 4-24)

Notification is one of the most sensitive aspects of breach response. Notify too early with incomplete information, and you may cause unnecessary alarm or need to issue corrections. Wait too long, and you risk regulatory penalties and loss of trust.

Legal Obligations

Data breach notification laws vary by jurisdiction, but many require notification within 72 hours of discovery. Key regulations include:

Key Point: Engage legal counsel familiar with data breach notification laws before sending any notifications. Premature or improperly worded notifications can create legal liability. An attorney can help you determine which laws apply and what your notification must include.

What to Include in Breach Notifications

Effective breach notifications are clear, honest, and actionable. Include these elements:

Phase 4: Remediate and Prevent Recurrence (Ongoing)

After containing the breach and notifying affected parties, focus on fixing the vulnerabilities that allowed the breach to happen:

  1. Patch the vulnerability. If the breach exploited a software vulnerability, apply patches and verify they resolve the issue. If a configuration error caused the exposure, fix the configuration and audit similar systems for the same issue.
  2. Strengthen access controls. Review and tighten access permissions. Implement the principle of least privilege. Revoke credentials that may have been exposed and issue new ones.
  3. Enhance monitoring. Deploy additional monitoring for the affected systems and accounts to detect any follow-up attacks. Attackers sometimes return weeks or months later through backdoors they installed during the initial breach.
  4. Update your incident response plan. Document what worked and what did not during your response. Update your plan so the next incident is handled more effectively.
  5. Conduct a post-incident review. Hold a blameless post-mortem meeting with all involved parties. Focus on improving processes and systems rather than assigning fault. The goal is to prevent recurrence, not to find a scapegoat.
  6. Consider additional security measures. Based on the root cause analysis, evaluate whether additional security controls would reduce the risk of similar breaches. This might include multi-factor authentication, endpoint detection and response tools, security awareness training, or third-party security assessments.

For Individuals: Personal Data Breach Response

If you are an individual who discovers that your personal data has been exposed in a breach, the response steps are simpler but no less urgent:

  1. Change the password for the breached account immediately. Use a strong, unique password stored in a password manager.
  2. Change passwords for any accounts where you reused the same password. This is critical. Credential stuffing attacks rely on password reuse.
  3. Enable multi-factor authentication on the breached account and any related accounts. Use an authenticator app rather than SMS when available.
  4. Check the breached account's settings for unauthorized changes. Attackers may have added forwarding rules to your email, changed recovery contact information, or connected third-party applications.
  5. Review financial accounts for unauthorized transactions. If financial data was involved in the breach, monitor your accounts closely and consider placing a fraud alert with credit bureaus.
  6. Accept any free credit monitoring offered by the breached organization. These services provide alerts about new accounts opened in your name or changes to your credit report.
  7. Be alert for follow-up phishing attempts. Attackers who have your email and other personal details from a breach may use that information to craft convincing targeted phishing messages.

Build Your Breach Response Plan Before You Need It

Explore our security tool reviews to find products that help detect and prevent data breaches before they happen.

Explore Security Tools