2. First response
Report it immediately, even if it was you
The single most important action in breach response is the first one: telling someone. The moment you spot, suspect, or cause a possible breach, report it internally through your organisation's incident route. Not at the end of the day, not after you have tried to quietly fix it, and not after you have worked out whether it "really counts". Immediately.
Why speed beats embarrassment
There are two clocks running the moment a breach happens, and neither one waits for you to feel ready.
The first is the harm clock. Every hour that passes is an hour in which a wrong recipient can forward an email, a stolen laptop can be browsed, or an attacker can move deeper into a system. Early containment, recalling a message, wiping a device, disabling an account, is dramatically more effective in the first hour than the tenth. Delay converts fixable incidents into serious ones.
The second is the legal clock. As you will see in Section 3, once your organisation becomes aware of a breach it may have as little as 72 hours to assess it and notify the ICO. Every hour a breach sits unreported inside someone's head is an hour stolen from the people who have to do that assessment.
Against those two clocks, weigh what delay actually buys you: the temporary comfort of not having an awkward conversation. That is the whole trade. Speed beats embarrassment every time.
The mistake is human, the cover-up is a choice
Well-run organisations understand that misdirected emails and lost devices are a cost of employing humans. What they cannot tolerate is discovering an incident weeks later, after the harm has compounded and the notification deadline is long gone. A prompt, honest report is evidence of professionalism, not failure. If your organisation punishes honest, prompt reporting, that is a culture problem worth raising, because it directly increases the chance of a serious unmanaged breach.
If you are unsure whether something qualifies, report it anyway and say you are unsure. Let the people trained to assess it decide.
› Course contents
What counts as a breach
First response
Assessing and notifying
Learning and prevention