# My business has had a data breach, what next?
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2017-08-24
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Key Steps to Managing a Data Breach Incident in Your
Meta Description: Learn the importance of swift and effective communication in the event of a data breach, and the legal obligations to notify the ICO and affected individuals.
Tags: featured
Tag URLs: featured (https://financedigest.com/tag/featured)
URL: https://financedigest.com/my-business-has-had-a-data-breach-what-nexthtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd240817-6-1736843577157-compressed.jpg)

_By **Emma Roe**,_ _Partner and Head of Commercial at Shulmans LLP_

Any type of data breach, whether due to an external hacking incident or an internal staff error, is a significant issue that needs immediate attention.  A key aspect of the legal requirements surrounding a data breach is to demonstrate that your business or organisation takes the issue very seriously and is proactively seeking to not only protect any individuals who may be affected, but is also taking active steps to improve systems and processes quickly to prevent a similar issue occurring again.

Communications following a [data breach](https://www.financedigest.com/amazons-twitch-blames-configuration-error-for-data-breach.html "Amazon’s Twitch blames configuration error for data breach"), both internally and externally, need to be carefully managed to convey these key messages effectively.

In the immediate aftermath of a [breach the most important](https://www.financedigest.com/when-not-if-why-a-data-breach-response-plan-is-more-important-now-than-ever.html "When not if: why a data breach response plan is more important now than ever") thing to establish, as quickly as possible, is exactly what data has been compromised and the number of individuals affected.

You [need to focus on confirming exactly what has happened and how any risks](https://www.financedigest.com/21690.html "BRIGHTON, England (Reuters) – Britain needs to be more “clear-eyed” about the risks") created can be mitigated, prepare your statement and reassure your customers and employees that you are in control of the situation.  [Knowing precisely what you are dealing](https://www.financedigest.com/eu-wants-to-know-if-microsoft-will-block-rivals-after-activision-deal.html "EU wants to know if Microsoft will block rivals after Activision deal") with is key in the early stages to allow you to manage the next steps around communication.  Whilst it is [important to act without delay](https://www.financedigest.com/britain-delays-full-post-brexit-import-checks-until-late-2023-2.html "Britain delays full post-Brexit import checks until late 2023"), don’t feel that you need to rush to make available information about a data breach incident until you have been able to verify it. Internally, communications need to take a structured approach to support a swift investigation and establish exactly what data has been compromised and to what extent.

Under current laws there is no mandatory requirement to notify the regulator, the Information Commissioner’s Office (ICO), or the individuals affected. However changes to the data protection laws, which will come into effect within the next 12 months, will require any [business that experiences a data](https://www.financedigest.com/how-can-financial-institutions-make-the-most-of-data-for-their-business.html "HOW CAN FINANCIAL INSTITUTIONS MAKE THE MOST OF DATA FOR THEIR BUSINESS?  ") breach to report it to the ICO within 72 hours of becoming aware of it, and then to notify affected individuals if the breach is likely to impact on their rights and/or freedoms. In turn, this will mean that having a rapid response approach to breaches will become even more critical in the near future.

Once you’ve determined which legal requirements you are required to fulfil regarding notifying the ICO and affected individuals, and whilst ensuring you are not disclosing any confidential information, key messages to be relayed publicly should be kept short and aim to include:

- any reassurances you can give regarding how [serious the breach](https://www.financedigest.com/pwc-hit-with-8-9-million-penalty-for-serious-breaches-on-babcock-audits.html "PwC hit with .9 million penalty for ‘serious breaches’ on Babcock audits") is
- general information you can [give about what type of data](https://www.financedigest.com/german-bond-yields-give-up-rise-after-u-s-price-data.html "German bond yields give up rise after U.S. price data") is affected
- advice to individuals on how to prevent identity fraud which could occur as a result of using the information which may have been compromised

This [information should only be issued in a manner which does not impact on any ongoing investigation into the incident itself or any attempts to further protect systems](https://www.financedigest.com/the-cardiovascular-information-systems-market-is-expected-to-grow-on-a-persistent-note-in-the-future.html "The Cardiovascular Information Systems Market is expected to grow on a persistent note in the future") and data following the breach.  However, if you are able to confirm that no payment related data, or [medical or health related data](https://www.financedigest.com/interoperability-of-data-to-accelerate-the-medical-tapes-market.html "Interoperability of data to accelerate the Medical Tapes Market") is involved, this can be a useful message to begin reassuring the public.

You should also provide information regarding the [communication that the affected individuals can expect from your business](https://www.financedigest.com/business-texting-an-essential-communication-tool.html "Business Texting: An Essential Communication Tool") following the breach.  Where possible, [share security](https://www.financedigest.com/demand-for-liquid-cargo-barge-is-expected-to-secure-notable-revenue-share-during-2027.html "Demand for Liquid Cargo Barge Is Expected to Secure Notable Revenue Share During 2027") assurances such as confirming that you won’t be contacting any of your employees or customers via email or phone asking for passwords or account details in the coming weeks.  This will provide reassurance to your community; it shows that you care about their individual [safety and that you are working towards](https://www.financedigest.com/rising-concerns-towards-safety-of-child-are-expected-to-drive-demand-for-baby-car-seat-market.html "Rising Concerns Towards Safety Of Child Are Expected To Drive Demand For Baby Car Seat Market") a solution.  If personal passwords have been compromised, [sharing details](https://www.financedigest.com/intravascular-ultrasound-devices-market-trends-and-opportunities-by-2031-details-shared-in-report.html "Intravascular Ultrasound Devices Market Trends and Opportunities by 2031 Details Shared in Report") of how users can change their passwords is also a good place to start.

Finally, it’s worth bearing in mind that it’s not just the breach that needs your attention during the immediate incident response phase, but also the channels of communication you use to contact the affected individuals to educate and inform them about the situation.  It’s important to think about how best you can ensure that any messages surrounding the data breach efficiently reach those who may be affected.  In addition to a press statement, you should also consider issuing information to your customers and employees either via an email newsletter, by post, or even a banner and news article on your website homepage.  This will ensure that the message [reaches anyone affected as quickly and as transparently](https://www.financedigest.com/laser-plastic-welding-market-is-expected-to-reach-us-1-5-bn-by-2025-transparency-market-research.html "Laser Plastic Welding Market Is Expected To Reach ~US$ 1.5 Bn by 2025: Transparency Market Research") as possible.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

