4. Learning and prevention
Common causes, and testing your response
Know your enemy: the ordinary mistakes
If you ask people to picture a data breach, most imagine sophisticated hackers. The reality of reported breaches is far more mundane. Data sent to the wrong recipient, and misdirected email in particular, is consistently among the most common causes of breaches reported to the ICO, alongside phishing, loss and theft of devices and paperwork, and failures to redact or to use Bcc.
This matters for prevention because it tells you where the effort pays off. Glamorous defences against exotic attacks are worth little if the organisation has no external-recipient warning on its email and no habit of checking attachments. The unglamorous controls that target everyday mistakes prevent the largest share of incidents.
Practise before it is real
The first time your organisation walks through its breach response should not be during a real breach. Scenario exercises, sometimes called tabletop exercises, take an hour or two and pay for themselves many times over. A facilitator presents a realistic scenario, for example "a director's laptop was stolen last night and it turns out disk encryption was switched off", and the team talks through the response in real time.
Good exercises quickly surface the gaps that only appear under pressure:
- Nobody is sure who the response owner is when the usual person is on leave
- The out-of-hours reporting route exists on paper but nobody knows the number
- Nobody can say quickly what data was actually on the laptop
- The 72-hour clock is half spent before anyone drafts an ICO notification
Each gap found in an exercise is a gap that will not be found for the first time during a genuine incident.
Vary the scenarios
Rotate through the common causes: a misdirected email with a sensitive attachment, a phished mailbox, ransomware on a shared server, paper files left on a train. Each exercises different containment steps, different assessment questions, and different notification decisions. Afterwards, treat the exercise like a real incident: capture lessons, assign actions, and check they happen.
› Course contents
What counts as a breach
First response
Assessing and notifying
Learning and prevention