The average cost of a data breach reached $4.44 million in 2025. Most of that cost is not the breach itself. It is the hours lost to disorganised response, the regulatory fines from missed notification windows, and the customer trust destroyed by poor communication. A documented response plan changes all three.
Having a data breach response plan before a breach occurs is the single most cost-effective investment in cybersecurity a business can make. The IBM Cost of a Data Breach Report consistently shows that organisations with an incident response plan and a trained response team contain breaches faster and at lower total cost than those improvising their way through an incident.
This guide covers the full 24-hour data breach response window from detection through initial notification, including the GDPR 72-hour regulatory requirement.
How to Detect a Data Breach Early
The average time to identify a data breach in 2025 was 194 days. Most organisations do not discover breaches from their own monitoring. They discover them from external notifications: a vendor report, a law enforcement notification, or a customer flagging suspicious activity involving their account.
The detection signals worth monitoring proactively include: unusual outbound data traffic volumes, failed login attempts at scale, unexpected privilege escalation events in access logs, alerts from endpoint detection tools about unusual process behaviour, and anomalous database query patterns. Each of these is detectable before data leaves your environment if monitoring is in place.
SIEM alerts: Security Information and Event Management systems aggregate log data from across your infrastructure and flag pattern anomalies. A SIEM is not a guaranteed breach detector, but it is the most practical tool available for identifying suspicious behaviour before it becomes a confirmed breach.
Dark web monitoring: Services that scan dark web forums and marketplaces for credentials or data matching your domain can provide early warning that data from your systems is circulating externally. This is often how organisations discover breaches they had not yet detected internally.
User behaviour analytics: Tools that baseline normal user behaviour and flag deviations. A finance employee suddenly accessing HR records at 2 AM is anomalous. Behaviour analytics surface these patterns for human investigation.
Hour 0 to 4: Confirm and Contain
- Confirm the breach is real. Not every security alert is a confirmed breach. Distinguish between an indicator of compromise and a confirmed incident before activating your full response plan. A suspicious log entry warrants investigation. A confirmed data exfiltration warrants immediate escalation.
- Assemble the incident response team. Your IR team should be pre-defined: typically a technical lead, a legal representative, a communications lead, and a senior decision-maker with authority to approve significant actions. Do not make personnel decisions mid-incident.
- Preserve evidence. Before taking any containment action, capture log files, screenshots, and system states. Forensic evidence captured before systems are shut down or wiped is irreplaceable. Destroying evidence through hasty containment actions is a common and expensive mistake.
- Contain the spread. Isolate affected systems without shutting down the entire network unless the situation demands it. Change compromised credentials immediately. Revoke access for any accounts that appear to have been used in the attack. If cloud infrastructure is involved, snapshot affected instances before termination.
Hour 4 to 12: Assess and Notify Internally
- Assess the scope. What data was accessed or exfiltrated? Whose data is it? How sensitive is it? What systems were affected? This assessment determines notification obligations and the severity of your regulatory exposure.
- Identify notification obligations. The notification requirements depend on the jurisdiction and the type of data involved. GDPR requires notification to the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals’ rights and freedoms. Most US states require notification to affected individuals within 30 to 90 days. Some states require notification within 30 days.
- Notify leadership and legal. Your CEO and legal counsel need to know about any breach that may require regulatory notification or that could result in material business impact. Do not filter bad news. Give them the facts as known at this stage with explicit acknowledgement of what is still unknown.
- Document everything. From this point forward, maintain a written timeline of every action taken, every decision made, and every communication sent. This documentation is essential for regulatory responses, legal proceedings, and post-incident review.
Hour 12 to 24: Regulatory Notification and External Communication
GDPR’s 72-hour notification clock begins when you become aware of a breach that is likely to result in a risk to individuals. You do not need to wait until the full picture is clear. Notify the supervisory authority with the information available at the time, and update as more information is confirmed.
The GDPR notification should include: the nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed to address the breach.
Notifying affected individuals: If the breach is likely to result in high risk to the rights and freedoms of individuals, you must also notify those individuals directly, without undue delay. This notification should describe the nature of the breach in plain language, the likely consequences, the steps taken to address it, and who to contact with questions.
Public communication: For breaches affecting significant numbers of individuals, a public statement is often appropriate to prevent rumour and speculation from creating reputational damage worse than the breach itself. The statement should be factual, avoid speculation about attribution, and confirm what steps are being taken.
Notifying partners and vendors: If affected data belongs to or is shared with third parties, notify them promptly. Failure to notify business partners in a timely way can expose you to contractual liability in addition to regulatory liability.
| Timeline | Action | Owner | Deadline |
| 0-1 hour | Confirm breach, assemble IR team | Security lead | Immediate |
| 1-4 hours | Preserve evidence, contain affected systems | Technical team | 4 hours |
| 4-8 hours | Scope assessment, document affected data types | IR team | 8 hours |
| 8-12 hours | Notify CEO, legal counsel, board if material | CISO / legal | 12 hours |
| 12-24 hours | Begin regulatory notification if GDPR applies | Legal + DPO | 72 hours from awareness |
| 24-72 hours | Individual notification if high risk confirmed | Legal + comms | Per jurisdiction |
| The Most Expensive Mistake in Breach Response
Announcing more certainty than you have. Saying ‘no customer data was accessed’ in the first 24 hours and then needing to retract that statement 48 hours later is far more damaging than saying ‘we are still assessing the scope and will provide an update within 24 hours.’ Never state what did not happen until you are certain. |
Frequently Asked Questions About Data Breach Response
How long do you have to report a data breach under GDPR?
You have 72 hours from becoming aware of a breach that poses a risk to individuals to notify your supervisory authority. You do not need the full picture before notifying. Submit what is known and update as information is confirmed. Missing the 72-hour window is a separate regulatory violation from the breach itself.
What is the first thing to do when you discover a data breach?
Preserve evidence first, then contain. Do not shut down affected systems or wipe logs before capturing forensic evidence. Change compromised credentials, isolate affected network segments, and assemble your pre-defined incident response team simultaneously.
Do small businesses need a data breach response plan?
Yes. Small businesses are frequent targets precisely because they tend to have weaker defences and less formalised response processes. A one-page documented plan covering who does what, how to assess scope, and which authorities to notify is enough to avoid the most costly improvised response mistakes.
How do you notify customers about a data breach?
Notify in plain language describing the nature of the breach, what data was involved, the likely consequences, what steps are being taken, and a contact for questions. Avoid technical jargon. Do not downplay the severity or speculate about causes before the investigation is complete.
What is the average cost of a data breach in 2025?
The IBM Cost of a Data Breach Report 2025 found the global average cost of a data breach was $4.44 million. This includes detection and escalation costs, notification costs, lost business, and post-breach response. Organisations with a tested incident response plan averaged $1.49 million less than those without.
How do most organisations discover a data breach?
The majority of breaches are discovered externally rather than through internal monitoring. Common sources include law enforcement notifications, vendor alerts, and customers reporting suspicious activity. SIEM tools and dark web monitoring improve early internal detection significantly.
Build the Plan Before You Need It
The time to write a data breach response plan is before the breach happens. Under the pressure of an active incident, clear thinking is compromised, people forget their responsibilities, and decisions get made without proper authority. A tested, documented plan removes all three problems.
Conduct a tabletop exercise annually: walk your team through a simulated breach scenario and test the plan against it. The gaps in your plan reveal themselves in exercises rather than in real incidents.