ICO Breach Notification Consulting — UK
If you've had a data breach in the UK, the ICO clock is ticking. UK GDPR Article 33 requires notification within 72 hours of awareness — and the decision on whether you must report is rarely simple. Gridisys helps you assess the risk, decide, and (if required) draft and submit a defensible ICO notification.
72 hours
Article 33 deadline from the moment you become aware
£17.5m / 4%
maximum UK GDPR fine for notification failures or breach mishandling
Fixed
Gridisys breach risk assessment — fixed-price emergency engagement
<4 hrs
typical time-to-triage for live breach engagements
Cybersecurity Consulting + 24/7 SOC Monitoring
Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.
Cybersecurity Consulting
UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.
- Risk assessment + security architecture review
- Conditional access + Entra ID hardening design
- Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
- Incident response planning + tabletop exercises
- Vendor + supply-chain security assessment
- Board / DPO reporting + evidence pack
Managed SOC Monitoring · 24/7
AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.
- 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
- BEC + mailbox-compromise + OAuth grant abuse detection
- Suspicious sign-in + conditional access drift alerting
- Ransomware + lateral-movement detection from EDR + Defender
- Sub-hour triage on critical alerts, monthly ops report
- Optional + integrated with consulting engagements
Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.
Pricing tailored to your needs
Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.
What we cover
Practical, board-ready consulting — no jargon, no surprise invoices.
Breached risk assessment
We assess whether the incident meets the ICO's 'risk to individuals' threshold for mandatory notification — documented reasoning either way, defensible if challenged.
ICO notification drafting
If notification is required, we draft the ICO submission: description of breach, categories of data, approximate number affected, likely consequences, mitigation, and DPO contact details — ready to file.
Communication to data subjects (Article 34)
Where the breach is 'high risk to individuals', the ICO requires direct communication. We help you draft that letter and document whether the high-risk threshold is met.
Breach register maintenance
Every notifiable AND non-notifiable breach must be logged in your register. We scaffold the register entry with all required fields for your records.
Concurrent incident response
Notification shouldn't pause the response. We run containment and evidence preservation in parallel with the ICO decision — your cyber root-cause statement strengthens the submission.
Post-incident regulatory follow-up
If the ICO requests more information, we stand behind the submission as technical authors — answering questions from your ICO case officer with sound evidence.
How we work
Triage (Hours 0-4)
Confirm the incident is real and within scope. Preserve evidence. Assign Gridisys + client incident commander. Begin ICO clock documentation.
Risk assessment (Hours 4-24)
Identify categories of data affected, records count, potential harm to individuals. Document the risk-assessment reasoning chain.
Decision & drafting (Hours 24-48)
Make the notification decision. If required, draft ICO submission. Get client sign-off. If Article 34 high-risk: draft data subject communication.
Submit & log (Hours 48-72)
File via the ICO online service. Confirm receipt. Add full entry to breach register. Begin post-incident remediation tracking.
Sectors we protect
ICO 72-hour clock running?
Free 15-minute triage. We'll confirm whether you're in scope, what we can do inside the remaining hours, and what it costs.
RELATED UK CYBERSECURITY SERVICES