Breach / exposure. Updated 2026-09-13. About 6 minutes to read.
Contain the breach without wiping anything, then check the deadline that applies to you: 72 hours in the UK and EU, a 30 day assessment in Australia, state laws in the US.
When a small business finds a breach, the instinct is to wipe the affected computer and move on. That destroys the evidence you need to work out what was taken, who you must notify, and whether your insurer will pay. The right order is contain, preserve, assess, notify, then fix.
The legal clocks are shorter than most owners expect. In the UK and EU, a reportable breach must go to the regulator within 72 hours of becoming aware of it. In Australia you have up to 30 days to assess a suspected breach. In the US, the rules depend on where each affected customer lives.
This is practical guidance, not legal advice. If you have cyber insurance, call the insurer's incident line before anything else, because many policies require it and provide lawyers and forensic help.
Do not contact the attacker, pay a ransom, or post about the incident publicly before you have advice. Early public statements that turn out to be wrong create legal and reputational problems of their own.
The scheme applies to organisations covered by the Privacy Act. Many businesses with annual turnover of 3 million dollars or less are exempt, but not health service providers, businesses that trade in personal information, or others the Act specifically covers, so check before assuming you are out.
If you suspect an eligible data breach, you must take reasonable steps to assess it within 30 days. A breach is eligible when it is likely to result in serious harm to someone and you have not been able to prevent that harm with remedial action. If it is eligible, notify the OAIC using its online form and tell affected individuals as soon as practicable, including what happened, what information was involved and what they should do.
If your business has turnover above 3 million dollars and makes a ransomware or cyber extortion payment, the Cyber Security Act requires you to report the payment to the Australian Signals Directorate within 72 hours. Report cybercrime through cyber.gov.au.
Under UK GDPR and EU GDPR, you must report a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people's rights and freedoms. In the UK that authority is the ICO. You do not need every answer before reporting. You can report what you know and follow up.
If the breach is likely to result in a high risk to individuals, you must also tell them without undue delay. Whether or not you report, you must keep an internal record of every breach and your reasoning. Small businesses unsure whether to report can use the ICO's self assessment tool or call its breach helpline on 0303 123 1113. Report the crime itself to Report Fraud, or to Police Scotland on 101.
Every US state has a breach notification law, and each applies to its own residents wherever your business is based. Most are triggered by Social Security numbers, driver licence numbers, or financial account numbers with the codes needed to use them, and many now include medical data, biometrics and online login credentials. Deadlines vary. Colorado, Florida and Washington, for example, set a 30 day limit, and many states also require notice to the state attorney general above a threshold.
Federal rules add to that. Under the FTC Safeguards Rule, non-bank financial businesses such as tax preparers, car dealers and mortgage brokers must notify the FTC within 30 days when unencrypted data about 500 or more people is involved. Health providers covered by HIPAA have their own rules. Report cybercrime to the FBI at ic3.gov.
In Canada, PIPEDA requires you to report a breach to the Office of the Privacy Commissioner and notify individuals as soon as feasible when there is a real risk of significant harm, and to keep records of all breaches for 24 months.
Often, yes, but it depends on where you and your customers are, what data was involved, and how likely harm is. Australia and the UK use a serious harm or high risk test, and US states use lists of data types. When in doubt, get advice quickly, because the clocks keep running.
UK and EU: 72 hours to the regulator where feasible. Australia: up to 30 days to assess, then notify as soon as practicable. US: set by each state, commonly between 30 and 60 days, plus 30 days to the FTC for businesses under the Safeguards Rule when 500 or more people are affected.
Government cyber agencies in Australia, the UK and the US advise against paying. Payment does not guarantee your data is deleted or your systems are restored, and it can breach sanctions laws. In Australia, businesses with turnover above 3 million dollars must report any payment within 72 hours.
Ask the provider in writing what data of yours was affected and when they found out. If your customers' data was involved, you may still be the one legally required to notify them, even though the provider was breached.
Some US states require it when Social Security numbers are exposed, and the FTC recommends at least a year of free monitoring in that situation. Monitoring is not required in Australia or the UK, but paying for IDCARE style support or explaining how to get a free freeze or ban is good practice.