ACTIVE INCIDENT RIGHT NOW? Gridisys 24/7 emergency triage — £0 first 15 minutes.
24/7 EMERGENCY INCIDENT RESPONSE · UK

Suspect a Data Breach? Read this before you tell anyone.

In the UK, the 72-hour ICO clock starts from 'awareness' — not from when you confirmed the breach. Acting before the clock is critical. Here's what evidence to preserve, what NOT to do, and how Gridisys helps you decide whether notification is even required.

We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.

YOU MAY HAVE SEARCHED

"data breach response UK""ICO 72 hour breach reporting help""personal data breach UK GDPR""I have a data breach UK""employee stole customer data UK""lost laptop with customer data UK""email sent to wrong recipient GDPR UK"

Do these 4 things in the next 10 minutes

  1. 1

    Don't reset any account passwords yet. Password resets blow away the evidence of who did what, when. Instead, disable sign-in on the suspicious account(s) from the M365 / Entra admin console.

  2. 2

    Preserve the evidence trail BEFORE you investigate. Save copies of: the suspicious email, the wrong-recipient sent item, the log showing who accessed what, the lost/stolen device's last-known sync logs.

  3. 3

    Document the 'awareness' moment — who first saw the indicator, at what time, what they saw. This is the timestamp the ICO will use for the 72-hour clock.

  4. 4

    Stop the bleeding. If a person is responsible (an employee accessing records they shouldn't), restrict their sign-in, not their whole account. If a vendor was involved, contact them now and ask them to preserve their own logs.

The ICO handled over 14,000 personal data breach reports in a recent year. The vast majority of UK breaches are survivable — the firms that get fined are usually those that mishandled the notification, not those that reported cleanly.

What we do — the Gridisys incident timeline

From the moment you engage, within fixed-price limits.

First 4 hours

Triage (Hours 0-4)

  • Confirm the incident is real — vs a near-miss, an email mis-send, a false positive from a tight security rule.
  • Identify the categories of personal data involved — special category (health, biometric, ethnic, sexual orientation, criminal) is far higher risk than contact details.
  • Estimate the approximate number of affected individuals — exact counts come later, but an order of magnitude drives risk.
  • Document the chain of 'awareness' — names and timestamps — so the 72-hour start is defensible.
Day 1

Risk assessment (Hours 4-24)

  • Apply the ICO's 'risk to rights and freedoms' test — likelihood and severity of harm to individuals.
  • Document the reasoning chain — the ICO wants to see HOW you reached your decision, not just the decision.
  • If 'likely risk' is met: notification is required. If 'low risk': document why, sign the register entry, and move on.
  • Where Article 34 'high risk' threshold is met: prepare data subject notification letter ready for send.
Day 1-3

Notification (Hours 24-72)

  • If required: draft ICO submission through the ICO online service — description, data categories, individuals affected, consequences, mitigation, DPO contact.
  • Submit. Confirm receipt. Reference number registered in your file.
  • Where Article 34 'high risk' applies: send the data subject communication (you have controllership responsibility here, not the ICO).
  • Notify any telecoms operators / sector regulators where applicable (e.g. if incident affects telecoms confidentiality).
Weeks 1-4

Close-out & supply chain

  • Register entry finalised with timeline, cause, mitigations, and individuals notified.
  • 1-month update to ICO if material new facts emerge.
  • Lessons learned review: controls update, training refresh, vendor risk reassessment.
  • If breach originated with a processor/supplier: contract and security review triggered.

What it costs

A Gridisys breach triage + risk assessment is fixed-price and concludes with a documented notification decision (yes/no) and (if required) a drafted ICO submission ready to file. Article 34 data-subject communication drafting is included. Live incident response extension (if active compromise continues): handled separately as a fixed-scope engagement. The initial 15-minute triage call is free. Contact us for a tailored quote.

Full pricing breakdown

What we cover

Phishing-related mailbox access — attacker read mail, set Inbox rules, exported contacts
Lost or stolen devices containing or able to access personal data
Misdirected communications — spreadsheet sent to wrong recipient, Bcc failure, mail-merge failure
Internal misuse — employees accessing records beyond their role (often an HR-disclosed trigger)
Vendor or third-party breaches — if a processor who handles your data tells you they've had an incident
Ransomware with personal data exposure — encryption of personal data without exfiltration is often still a breach
Cloud misconfiguration — exposed storage, public S3/Blob, public SharePoint link, public OneDrive folder
Special category data — health, biometric, criminal, sexual orientation, religious — drives the highest-risk assessments

Frequently asked questions

Talk to us now

The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.