2. First response
Who owns breach response, and first containment steps
Reporting a breach is everyone's job. Running the response is not. Every organisation should have a defined owner for breach response: a Data Protection Officer where one is appointed, or otherwise a named lead such as an IT manager, compliance manager, or a small incident team. Your role as the person who spotted or caused the incident is to report fast, answer questions honestly, and follow instructions, not to run your own investigation or decide the outcome.
Common containment steps
Containment means stopping the breach from getting worse. What that looks like depends on the incident, and most of these actions will be taken by, or with, IT:
- Recall attempts. For a misdirected email, attempt recall where the system supports it, and contact the recipient promptly to ask them to delete it and confirm they have done so. Be realistic: recall often fails, especially outside your own organisation, so it limits harm but rarely erases it.
- Remote wipe. For a lost or stolen laptop or phone that is enrolled in device management, a remote wipe or lock can remove data before anyone reads it. This is a race against time, which is another reason immediate reporting matters.
- Disabling accounts. For a compromised account, disable it or force a password reset and sign out all sessions, cutting off the attacker's access. Check for things the attacker may have left behind, such as mail forwarding rules.
- Isolating systems. For malware or ransomware, disconnecting affected machines from the network can stop the spread while keeping the machines available for investigation.
Containment is not the end
A contained breach still happened. Recalling the email, wiping the laptop, or disabling the account does not undo the disclosure or loss, and it does not remove the duty to assess and possibly notify. Containment buys safety; assessment and honesty do the rest. Never treat a successful containment step as a reason to skip the report, and never take drastic action alone, such as shutting down a shared system, without the response owner's say-so.
› Course contents
What counts as a breach
First response
Assessing and notifying
Learning and prevention