ICO Breach Reporting — UK Process, Form & PECR Portal Guide
ICO breach reporting in the UK is a structured, mandatory process when Article 33 applies — submitted via the ICO's Personal Data Breach reporting tool (PECR). Errors get notifications rejected and create their own enforcement risk. Our retainer covers end-to-end reporting — from 'breach occurred' through submission, follow-up, and post-incident evidence pack.
PECR portal
ICO submission channel — your account, prior breach history tracked
10 fields
ICO breach report form requires AT LEAST 10 structured fields
Retainer
Gridisys breach response retainer — drafting + submission included
Supplementary
submit updates within 72 hours of change — ongoing disclosure duty
Cybersecurity Consulting + 24/7 SOC Monitoring
Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.
Cybersecurity Consulting
UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.
- Risk assessment + security architecture review
- Conditional access + Entra ID hardening design
- Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
- Incident response planning + tabletop exercises
- Vendor + supply-chain security assessment
- Board / DPO reporting + evidence pack
Managed SOC Monitoring · 24/7
AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.
- 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
- BEC + mailbox-compromise + OAuth grant abuse detection
- Suspicious sign-in + conditional access drift alerting
- Ransomware + lateral-movement detection from EDR + Defender
- Sub-hour triage on critical alerts, monthly ops report
- Optional + integrated with consulting engagements
Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.
Pricing tailored to your needs
Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.
What we cover
Practical, board-ready consulting — no jargon, no surprise invoices.
ICO PECR portal report drafting
ICO's Personal Data Breach report tool requires: name + contact of reporting org, DPO contact, breach type (CINA), affected data subjects + record counts, description of breach, root cause, mitigation, follow-up plan, risk assessment. We draft in ICO's format — accurate, evidence-ready.
Sample ICO breach reports (5 examples)
We can provide sample ICO breach reports (anonymised — ransomware on retail SME, BEC against solicitor firm, mailbox compromise of dental practice, lost laptop with encrypted data, third-party processor breach). Use as scaffolding when drafting your own.
Supplementary updates
Article 33(4) requires updates to the ICO if further information emerges. Common: initial report had limited scope, investigation revealed larger scope, additional data subject categories affected. We submit supplementaries with the right tone + evidence density.
Common rejection reasons
ICO rejects notifications for: vague scope ('we had a breach'), missing data subject categories/numbers, missing contact details, post-event-only measures (not 'future safeguards as Art. 33(3)(d)'), insufficient rationale for self-assessment of risk. We pre-empt each at submission.
ICO follow-up response pack
ICO may make follow-up enquiries post-submission. We document the request — frequently: detail on root cause, evidence of mitigation, organisational impact, employee training response. Drafted as a single 'follow-up response pack' aligned to your initial submission.
Breach record keeping
Article 33(5) requires documentation of all personal data breaches — including those not notified to ICO — with facts, effects, remedial action. Maintain your internal breach register aligned to ICO submissions. We scaffold the register template.
How we work
Awareness + triage (T+0 – T+6)
Phone call. Confirm awareness timestamp. Triage: Art. 4(12) personal data breach? Art. 33 draft reportable? Document the determination in evidence pack.
Draft ICO notification (T+6 – T+24)
Draft ICO PECR report (10+ structured fields). Confirm scope + risk assessment + root cause + measures. Internal review by DPO / legal / manager.
Submit supplementary (T+24 – T+72)
Submit initial to ICO via PECR portal — confirmed receipt. Ongoing: if investigation reveals new scope, submit supplementary within 72 hours of new awareness point.
ICO follow-up + post-incident (T+72 onward)
Handle any ICO enquiries. Document post-incident report + DPIA refresh + breach register entry + training record. Closure.
Sectors we protect
Your ICO breach report drafted and submitted, evidence-ready
Sign the breach response retainer — free consultation on ICO PECR portal reporting, sample reports, and rejections avoided.
RELATED UK CYBERSECURITY SERVICES