Skip to main content

Security and Risk

Data Breach

A breach is not only an attack. Most are ordinary mistakes, and the first hour matters more than the technology involved.

Definition

A personal data breach is any security failure that leads to personal data being destroyed, lost, altered, disclosed or accessed without authorisation. Accidental counts. Internal counts.

What It Actually Means

That definition is wider than most people assume, and the gap causes real problems, because businesses look for an attacker and conclude nothing happened.

An email with client details sent to the wrong recipient is a breach. A lost laptop is a breach. A spreadsheet of customer records shared with a link set to “anyone with the link” is a breach. A departing employee taking a contact list is a breach. Ransomware that encrypts data you can still recover from backup is still a breach, because availability was lost.

What Actually Happens In Practice

The majority of incidents at small and mid-sized businesses are not sophisticated. They are a misdirected email, a reused password, a permission set too widely, or a supplier’s system being compromised and yours being reached through it.

That last one deserves attention, because it is the category most often missed. Your data sitting inside a supplier’s system is still your responsibility to your customers. When a supplier is breached, you have a breach, whatever their status page says.

The First Hour

The order matters and it is worth deciding now rather than during.

Contain before investigating. Revoke the access, disable the account, take the system off the network. The instinct to understand what happened first is natural and it lets the problem continue while you work.

Preserve rather than tidy. Do not delete the suspicious file or wipe the machine. That is evidence, and you may need it both to understand scope and to demonstrate you responded properly.

Write down times. When it was noticed, when each action was taken, who was told. The 72-hour clock under UK GDPR starts when you become aware, and a contemporaneous timeline is what makes that defensible later.

Establish scope before deciding severity. Whose data, what fields, how many people. Whether it is reportable depends on risk to those individuals, and you cannot assess risk without knowing what left.

What To Ask

  • How would we even know? Most breaches are discovered by an outsider. Alerting on unusual access and failed logins is what changes that.
  • What would an attacker reach with one compromised account? The answer describes your actual exposure, rather than the theoretical one.
  • Which suppliers hold our customer data? This list is nearly always longer than expected and it is where the next incident is most likely.
  • Who decides whether to report? Deciding during an incident, at speed, without an owner, is how the 72 hours gets missed.

The Cheapest Prevention

Two measures remove the majority of realistic incidents at this size, and neither is a product.

The first is two-factor authentication everywhere it can be turned on, because credential reuse is the most common single route in.

The second is reviewing who can access what, twice a year. Access accumulates. People change roles, projects end, contractors leave, and permissions almost never get removed. A large share of internal incidents are simply someone still being able to reach something they stopped needing two years ago.

More terms are in the glossary.

Portrait of Alexander De Sousa, founder of Digital Royalty
Founder-led
“I’ve put everything I know into how this company works — the standards, the method, the care on every project. It runs through the whole team, and I hold us all to it.”

Alexander De Sousa · Founder LinkedIn

Featured on BBC Radio Solent

Get started

Tell us what you need

A few quick questions, then a straight answer from a real person — usually within a few hours.

Tell us what you're working on

Whether it's a new site, a platform, or a process that shouldn't be manual any more — we'll tell you honestly if we can help.