Small business data breach response: what to do in the first 72 hours

Breach / exposure. Updated 2026-09-13. About 6 minutes to read.

Contain the breach without wiping anything, then check the deadline that applies to you: 72 hours in the UK and EU, a 30 day assessment in Australia, state laws in the US.

When a small business finds a breach, the instinct is to wipe the affected computer and move on. That destroys the evidence you need to work out what was taken, who you must notify, and whether your insurer will pay. The right order is contain, preserve, assess, notify, then fix.

The legal clocks are shorter than most owners expect. In the UK and EU, a reportable breach must go to the regulator within 72 hours of becoming aware of it. In Australia you have up to 30 days to assess a suspected breach. In the US, the rules depend on where each affected customer lives.

This is practical guidance, not legal advice. If you have cyber insurance, call the insurer's incident line before anything else, because many policies require it and provide lawyers and forensic help.

Hour one: contain it without destroying evidence

  1. Disconnect affected computers from the network, but do not switch them off or wipe them. Memory and logs can show what the attacker did.
  2. Reset passwords for every administrator account, email account and cloud service involved, from a device you trust.
  3. Revoke active sessions and rotate API keys, shared passwords and remote access credentials.
  4. Turn on multi factor authentication anywhere it is missing, starting with email and admin accounts.
  5. In Microsoft 365 or Google Workspace, check every affected mailbox for new forwarding rules, inbox rules and connected apps. Attackers use them to keep reading mail after a password change.
  6. Start a written log: what you found, when, who you told, and every action taken.

Hours 2 to 24: work out what was touched

  • Which data was involved: names and contact details, dates of birth, government ID numbers, bank or card details, health information, login credentials.
  • Roughly how many people are affected, and which states or countries they live in. That decides which laws apply.
  • Whether data was actually accessed or copied, or only exposed. Audit logs, file access logs and your IT provider can help.
  • Whether the breach happened at a supplier, such as your accounting software, payroll provider or website host. You may still be responsible for notifying your customers.
  • Whether the data was encrypted, and whether the encryption keys were also taken.

Do not contact the attacker, pay a ransom, or post about the incident publicly before you have advice. Early public statements that turn out to be wrong create legal and reputational problems of their own.

Australia: the Notifiable Data Breaches scheme

The scheme applies to organisations covered by the Privacy Act. Many businesses with annual turnover of 3 million dollars or less are exempt, but not health service providers, businesses that trade in personal information, or others the Act specifically covers, so check before assuming you are out.

If you suspect an eligible data breach, you must take reasonable steps to assess it within 30 days. A breach is eligible when it is likely to result in serious harm to someone and you have not been able to prevent that harm with remedial action. If it is eligible, notify the OAIC using its online form and tell affected individuals as soon as practicable, including what happened, what information was involved and what they should do.

If your business has turnover above 3 million dollars and makes a ransomware or cyber extortion payment, the Cyber Security Act requires you to report the payment to the Australian Signals Directorate within 72 hours. Report cybercrime through cyber.gov.au.

United Kingdom and EU: 72 hours to the regulator

Under UK GDPR and EU GDPR, you must report a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people's rights and freedoms. In the UK that authority is the ICO. You do not need every answer before reporting. You can report what you know and follow up.

If the breach is likely to result in a high risk to individuals, you must also tell them without undue delay. Whether or not you report, you must keep an internal record of every breach and your reasoning. Small businesses unsure whether to report can use the ICO's self assessment tool or call its breach helpline on 0303 123 1113. Report the crime itself to Report Fraud, or to Police Scotland on 101.

United States and Canada: many laws, one approach

Every US state has a breach notification law, and each applies to its own residents wherever your business is based. Most are triggered by Social Security numbers, driver licence numbers, or financial account numbers with the codes needed to use them, and many now include medical data, biometrics and online login credentials. Deadlines vary. Colorado, Florida and Washington, for example, set a 30 day limit, and many states also require notice to the state attorney general above a threshold.

Federal rules add to that. Under the FTC Safeguards Rule, non-bank financial businesses such as tax preparers, car dealers and mortgage brokers must notify the FTC within 30 days when unencrypted data about 500 or more people is involved. Health providers covered by HIPAA have their own rules. Report cybercrime to the FBI at ic3.gov.

In Canada, PIPEDA requires you to report a breach to the Office of the Privacy Commissioner and notify individuals as soon as feasible when there is a real risk of significant harm, and to keep records of all breaches for 24 months.

Write a notice people will actually read

  1. Say plainly what happened and when, in two or three sentences.
  2. List exactly which types of information were involved, and which were not.
  3. Explain what you have done to stop it and protect people.
  4. Tell people what to do: change a password, watch statements, place a credit freeze, and ignore messages claiming to be from you that ask for payment or codes.
  5. Give a phone number and a monitored email address, and do not put links in the notice, so customers are not trained to click links in breach emails.
  6. Where Social Security numbers were exposed, the FTC recommends offering at least a year of free credit monitoring.

Close the gap that let them in

  • Require multi factor authentication on email, admin, banking and remote access, using authenticator apps, passkeys or security keys for administrators.
  • Move staff to a business password manager and remove accounts for anyone who has left.
  • Keep software, firewalls and remote access tools patched, and remove remote desktop access exposed to the internet.
  • Keep offline or immutable backups and test a restore.
  • Publish SPF, DKIM and DMARC records for your domain so criminals cannot easily send invoice fraud in your name.

Frequently asked questions

Do I legally have to tell customers about a data breach?

Often, yes, but it depends on where you and your customers are, what data was involved, and how likely harm is. Australia and the UK use a serious harm or high risk test, and US states use lists of data types. When in doubt, get advice quickly, because the clocks keep running.

How long do I have to report a data breach?

UK and EU: 72 hours to the regulator where feasible. Australia: up to 30 days to assess, then notify as soon as practicable. US: set by each state, commonly between 30 and 60 days, plus 30 days to the FTC for businesses under the Safeguards Rule when 500 or more people are affected.

Should I pay the ransom?

Government cyber agencies in Australia, the UK and the US advise against paying. Payment does not guarantee your data is deleted or your systems are restored, and it can breach sanctions laws. In Australia, businesses with turnover above 3 million dollars must report any payment within 72 hours.

What if the breach happened at my software provider?

Ask the provider in writing what data of yours was affected and when they found out. If your customers' data was involved, you may still be the one legally required to notify them, even though the provider was breached.

Do I have to offer customers credit monitoring?

Some US states require it when Social Security numbers are exposed, and the FTC recommends at least a year of free monitoring in that situation. Monitoring is not required in Australia or the UK, but paying for IDCARE style support or explaining how to get a free freeze or ban is good practice.

Tools that help

Related guides

Sources