What It Actually Means
That definition is wider than most people assume, and the gap causes real problems, because businesses look for an attacker and conclude nothing happened.
An email with client details sent to the wrong recipient is a breach. A lost laptop is a breach. A spreadsheet of customer records shared with a link set to “anyone with the link” is a breach. A departing employee taking a contact list is a breach. Ransomware that encrypts data you can still recover from backup is still a breach, because availability was lost.
What Actually Happens In Practice
The majority of incidents at small and mid-sized businesses are not sophisticated. They are a misdirected email, a reused password, a permission set too widely, or a supplier’s system being compromised and yours being reached through it.
That last one deserves attention, because it is the category most often missed. Your data sitting inside a supplier’s system is still your responsibility to your customers. When a supplier is breached, you have a breach, whatever their status page says.
The First Hour
The order matters and it is worth deciding now rather than during.
Contain before investigating. Revoke the access, disable the account, take the system off the network. The instinct to understand what happened first is natural and it lets the problem continue while you work.
Preserve rather than tidy. Do not delete the suspicious file or wipe the machine. That is evidence, and you may need it both to understand scope and to demonstrate you responded properly.
Write down times. When it was noticed, when each action was taken, who was told. The 72-hour clock under UK GDPR starts when you become aware, and a contemporaneous timeline is what makes that defensible later.
Establish scope before deciding severity. Whose data, what fields, how many people. Whether it is reportable depends on risk to those individuals, and you cannot assess risk without knowing what left.
What To Ask
- How would we even know? Most breaches are discovered by an outsider. Alerting on unusual access and failed logins is what changes that.
- What would an attacker reach with one compromised account? The answer describes your actual exposure, rather than the theoretical one.
- Which suppliers hold our customer data? This list is nearly always longer than expected and it is where the next incident is most likely.
- Who decides whether to report? Deciding during an incident, at speed, without an owner, is how the 72 hours gets missed.
The Cheapest Prevention
Two measures remove the majority of realistic incidents at this size, and neither is a product.
The first is two-factor authentication everywhere it can be turned on, because credential reuse is the most common single route in.
The second is reviewing who can access what, twice a year. Access accumulates. People change roles, projects end, contractors leave, and permissions almost never get removed. A large share of internal incidents are simply someone still being able to reach something they stopped needing two years ago.
More terms are in the glossary.