What Should I Do If My Company Is Part of a Data Breach?

Whether your company was directly breached or a third-party vendor holding your data was, the response steps are broadly similar and time-sensitive.

Immediate steps

  1. Confirm the scope: what data, how many records, which systems
  2. Contain it: revoke compromised credentials, patch the exploited vulnerability, isolate affected systems
  3. Check legal notification requirements — many jurisdictions require notifying affected individuals and/or regulators within a specific window (e.g. 72 hours under GDPR)
  4. Notify affected users with clear, specific guidance (what was exposed, what to do, e.g. reset passwords)
  5. Force password resets for affected accounts, and review for related compromised credentials reused elsewhere

Longer term

Conduct a post-mortem, and consider ongoing breach-monitoring so future exposures (including via third-party vendors) are caught quickly rather than discovered externally.

FAQ

Do I have to notify users even if the breach was a third-party vendor’s fault?

In most regulatory frameworks, yes — the obligation generally follows the data controller, not just whoever directly caused the breach.

Updated at: .