Suspect a Data Breach? Read this before you tell anyone.
In the UK, the 72-hour ICO clock starts from 'awareness' — not from when you confirmed the breach. Acting before the clock is critical. Here's what evidence to preserve, what NOT to do, and how Gridisys helps you decide whether notification is even required.
We respond to incident triage requests within 60 minutes during UK business hours, and on-call within 4 hours overnight and weekends.
YOU MAY HAVE SEARCHED
Do these 4 things in the next 10 minutes
- 1
Don't reset any account passwords yet. Password resets blow away the evidence of who did what, when. Instead, disable sign-in on the suspicious account(s) from the M365 / Entra admin console.
- 2
Preserve the evidence trail BEFORE you investigate. Save copies of: the suspicious email, the wrong-recipient sent item, the log showing who accessed what, the lost/stolen device's last-known sync logs.
- 3
Document the 'awareness' moment — who first saw the indicator, at what time, what they saw. This is the timestamp the ICO will use for the 72-hour clock.
- 4
Stop the bleeding. If a person is responsible (an employee accessing records they shouldn't), restrict their sign-in, not their whole account. If a vendor was involved, contact them now and ask them to preserve their own logs.
What we do — the Gridisys incident timeline
From the moment you engage, within fixed-price limits.
Triage (Hours 0-4)
- ▸Confirm the incident is real — vs a near-miss, an email mis-send, a false positive from a tight security rule.
- ▸Identify the categories of personal data involved — special category (health, biometric, ethnic, sexual orientation, criminal) is far higher risk than contact details.
- ▸Estimate the approximate number of affected individuals — exact counts come later, but an order of magnitude drives risk.
- ▸Document the chain of 'awareness' — names and timestamps — so the 72-hour start is defensible.
Risk assessment (Hours 4-24)
- ▸Apply the ICO's 'risk to rights and freedoms' test — likelihood and severity of harm to individuals.
- ▸Document the reasoning chain — the ICO wants to see HOW you reached your decision, not just the decision.
- ▸If 'likely risk' is met: notification is required. If 'low risk': document why, sign the register entry, and move on.
- ▸Where Article 34 'high risk' threshold is met: prepare data subject notification letter ready for send.
Notification (Hours 24-72)
- ▸If required: draft ICO submission through the ICO online service — description, data categories, individuals affected, consequences, mitigation, DPO contact.
- ▸Submit. Confirm receipt. Reference number registered in your file.
- ▸Where Article 34 'high risk' applies: send the data subject communication (you have controllership responsibility here, not the ICO).
- ▸Notify any telecoms operators / sector regulators where applicable (e.g. if incident affects telecoms confidentiality).
Close-out & supply chain
- ▸Register entry finalised with timeline, cause, mitigations, and individuals notified.
- ▸1-month update to ICO if material new facts emerge.
- ▸Lessons learned review: controls update, training refresh, vendor risk reassessment.
- ▸If breach originated with a processor/supplier: contract and security review triggered.
What it costs
A Gridisys breach triage + risk assessment is fixed-price and concludes with a documented notification decision (yes/no) and (if required) a drafted ICO submission ready to file. Article 34 data-subject communication drafting is included. Live incident response extension (if active compromise continues): handled separately as a fixed-scope engagement. The initial 15-minute triage call is free. Contact us for a tailored quote.
Full pricing breakdownWhat we cover
RELATED INCIDENT RESPONSE GUIDES
Frequently asked questions
Talk to us now
The first 15-minute triage call is free. We'll tell you whether it's a real incident, what's at risk, and what to do next — no obligation, no commitment.