Whether your company was directly breached or a third-party vendor holding your data was, the response steps are broadly similar and time-sensitive.
Immediate steps
- Confirm the scope: what data, how many records, which systems
- Contain it: revoke compromised credentials, patch the exploited vulnerability, isolate affected systems
- Check legal notification requirements — many jurisdictions require notifying affected individuals and/or regulators within a specific window (e.g. 72 hours under GDPR)
- Notify affected users with clear, specific guidance (what was exposed, what to do, e.g. reset passwords)
- Force password resets for affected accounts, and review for related compromised credentials reused elsewhere
Longer term
Conduct a post-mortem, and consider ongoing breach-monitoring so future exposures (including via third-party vendors) are caught quickly rather than discovered externally.
FAQ
Do I have to notify users even if the breach was a third-party vendor’s fault?
In most regulatory frameworks, yes — the obligation generally follows the data controller, not just whoever directly caused the breach.