ICO BREACH NOTIFICATION · United Kingdom

ICO Breach Notification Consulting — UK

If you've had a data breach in the UK, the ICO clock is ticking. UK GDPR Article 33 requires notification within 72 hours of awareness — and the decision on whether you must report is rarely simple. Gridisys helps you assess the risk, decide, and (if required) draft and submit a defensible ICO notification.

72-hour decision framework UK GDPR Article 33/34 ICO notification drafting DPA 2018 aligned Risk-assessment documentation Incident-aware consulting

72 hours

Article 33 deadline from the moment you become aware

£17.5m / 4%

maximum UK GDPR fine for notification failures or breach mishandling

Fixed

Gridisys breach risk assessment — fixed-price emergency engagement

<4 hrs

typical time-to-triage for live breach engagements

Cybersecurity Consulting + 24/7 SOC Monitoring

Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.

Cybersecurity Consulting

UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.

  • Risk assessment + security architecture review
  • Conditional access + Entra ID hardening design
  • Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
  • Incident response planning + tabletop exercises
  • Vendor + supply-chain security assessment
  • Board / DPO reporting + evidence pack

Managed SOC Monitoring · 24/7

AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.

  • 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
  • BEC + mailbox-compromise + OAuth grant abuse detection
  • Suspicious sign-in + conditional access drift alerting
  • Ransomware + lateral-movement detection from EDR + Defender
  • Sub-hour triage on critical alerts, monthly ops report
  • Optional + integrated with consulting engagements

Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.

GET A QUOTE

Pricing tailored to your needs

Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.

What we cover

Practical, board-ready consulting — no jargon, no surprise invoices.

Breached risk assessment

We assess whether the incident meets the ICO's 'risk to individuals' threshold for mandatory notification — documented reasoning either way, defensible if challenged.

ICO notification drafting

If notification is required, we draft the ICO submission: description of breach, categories of data, approximate number affected, likely consequences, mitigation, and DPO contact details — ready to file.

Communication to data subjects (Article 34)

Where the breach is 'high risk to individuals', the ICO requires direct communication. We help you draft that letter and document whether the high-risk threshold is met.

Breach register maintenance

Every notifiable AND non-notifiable breach must be logged in your register. We scaffold the register entry with all required fields for your records.

Concurrent incident response

Notification shouldn't pause the response. We run containment and evidence preservation in parallel with the ICO decision — your cyber root-cause statement strengthens the submission.

Post-incident regulatory follow-up

If the ICO requests more information, we stand behind the submission as technical authors — answering questions from your ICO case officer with sound evidence.

How we work

1

Triage (Hours 0-4)

Confirm the incident is real and within scope. Preserve evidence. Assign Gridisys + client incident commander. Begin ICO clock documentation.

2

Risk assessment (Hours 4-24)

Identify categories of data affected, records count, potential harm to individuals. Document the risk-assessment reasoning chain.

3

Decision & drafting (Hours 24-48)

Make the notification decision. If required, draft ICO submission. Get client sign-off. If Article 34 high-risk: draft data subject communication.

4

Submit & log (Hours 48-72)

File via the ICO online service. Confirm receipt. Add full entry to breach register. Begin post-incident remediation tracking.

Sectors we protect

Solicitors & law firms Wealth managers & IFAs Healthcare & dental practices Estate agents & property Accountants & bookkeepers SaaS & e-commerce Recruitment agencies Education providers
FREE CONSULTATION

ICO 72-hour clock running?

Free 15-minute triage. We'll confirm whether you're in scope, what we can do inside the remaining hours, and what it costs.

Frequently asked questions

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.