Hours 0-4: Contain the Breach Immediately
The first four hours are about damage limitation. Your priority is to stop the breach from getting worse while preserving evidence for your investigation and any regulatory proceedings that follow.
Take these containment steps before anything else:
- Stop the breach. Isolate affected systems, revoke any compromised credentials, disable breached email accounts, and block suspicious IP addresses.
- Preserve the evidence. Do not delete anything. Screenshot error messages, save server and access logs, and record the exact time you discovered the breach.
- Assemble your response team. Contact your senior partner or director, your IT support or managed service provider, your Data Protection Officer if one has been appointed, and your cyber insurance provider.
Contact Your Cyber Insurance Provider Immediately
If you have cyber insurance, and as a UK professional handling client data you absolutely should, contact your insurer within the first hour. Most policies include incident response services, access to forensic investigators, legal counsel, and PR support. Using their approved providers is often a condition of your policy. Failing to notify promptly could void your coverage at the exact moment you need it most.
Your insurer will typically assign a breach coach, an experienced lawyer who coordinates the entire response. This takes significant pressure off you and ensures every step is documented correctly for regulatory purposes.
Hours 4-24: Assess the Scope and Severity
Once the breach is contained, you must determine exactly what happened, what data was compromised, and who is affected. This assessment drives every decision that follows, from whether you need to notify the ICO to which clients you must contact.
Start by classifying the data types involved. Passports, driving licences, National Insurance numbers, financial records, bank statements, health records, and legal case files all represent high risk. Names, addresses, and contact details are medium risk. Business information and invoices are lower risk, though still notifiable if combined with personal identifiers. Alongside that, answer five key questions: how many clients are affected; was the data encrypted at rest; was data actually accessed or merely exposed; is there evidence of exfiltration; and how long was the vulnerability open.
ICO notification threshold
Document Everything as You Go
Under GDPR Article 33(5), you must maintain a record of all personal data breaches, regardless of whether they meet the ICO notification threshold. Create a breach log from the moment of discovery and record every action taken, every decision made, and every person involved. This is not optional. The ICO will ask for it, and having a thorough, timestamped record demonstrates accountability and can significantly reduce any penalty.
Hours 24-72: Notify the ICO and Affected Clients
The 72-hour clock runs from the moment you become aware of the breach, not from when you confirm its full scope. You can file an initial report with incomplete information and update it later, so do not delay notification while waiting for forensics.
Your ICO report must include:
- Nature of the breach and data categories. Describe what happened and which categories of personal data were involved.
- Approximate number of individuals affected. Provide your best current estimate; you can refine it in a follow-up submission.
- DPO name and contact details. If you have not appointed a DPO, provide the contact details of the person handling the breach.
- Description of likely consequences. Explain the risks to the individuals whose data was involved.
- Measures taken to address the breach. Detail the containment and remediation steps you have already taken. Report online via the ICO breach reporting tool or by phone on 0303 123 1113. Keep your ICO reference number somewhere safe.
Client Notification: Getting It Right
Under GDPR Article 34, you must notify affected individuals directly if the breach is likely to result in a high risk to their rights and freedoms. For professionals handling identity documents, financial records, or legal files, this is almost always the case.
Your client notification should be clear, honest, and actionable. Resist the temptation to minimise the breach or use vague language. Clients will respect transparency far more than corporate-speak, and the ICO specifically looks for clear communication when assessing your response.
Client Notification Checklist
What to Include
- Plain-English description of what happened
- Exactly what data was compromised
- What you are doing to fix it
- Specific steps the client should take
- A named contact for questions (not a generic inbox)
- Timeline for further updates
What to Avoid
- Vague language like “incident” instead of “breach”
- Minimising the severity or scope
- Blaming third parties without evidence
- Promising it will never happen again
- Delay tactics or drip-feeding information
- Sending notification by unsecured email
Important: Send breach notifications through a secure channel, not the same email system that may have been compromised.
Secure Your Client Document Collection
Most professional data breaches start with insecure document collection. Email attachments, shared drives, and WeTransfer links create permanent copies of sensitive client data. FileSeal's zero-trust encryption means your server never sees plaintext documents, and automatic deletion after download eliminates the data that breaches exploit.
Regulatory Body Notifications: Who Else You Must Tell
The ICO is not the only body you may need to notify. Most UK regulated professionals have additional reporting obligations to their sector regulator. Failing to notify your regulator can result in separate disciplinary proceedings, even if your ICO response is perfect.
Notification requirements by profession:
- Solicitors: SRA (Solicitors Regulation Authority). Report under SRA Principle 2 (public trust) within 10 business days, including the remedial actions you have taken.
- Accountants: ICAEW, ACCA, or AAT depending on your membership.Report under your body’s professional conduct rules, demonstrating your compliance procedures and remediation steps.
- Financial advisors: FCA (Financial Conduct Authority). Report as a material incident via the FCA Connect portal. Ongoing reporting may be required as your investigation progresses.
- Recruiters and others. If you are an REC member, notify the REC under its conduct rules. Notify your professional indemnity insurer, any other industry body you belong to, and consider informing affected employers if candidate data was compromised.
Secure Your Documents Today
AES-256 encrypted upload links. Documents auto-delete after download.
Managing the PR and Client Relationship Fallout
A data breach does not just threaten your regulatory standing. It threatens the client relationships you have spent years building. How you communicate during and after a breach will determine whether clients stay or leave. Research consistently shows that organisations which respond transparently and quickly retain significantly more clients than those that delay or minimise.
The First 48 Hours of Communications
Appoint a single spokesperson for all breach communications. Mixed messages from different partners or staff members create confusion and erode trust. Your spokesperson should be senior enough to make decisions and empathetic enough to handle distressed clients. Prepare a Q&A document that covers the most likely questions, and ensure everyone in your practice knows to direct enquiries to the nominated person.
If you have a website or client portal, publish a brief, factual statement. Do not wait for the press to contact you. Controlling the narrative from day one is significantly more effective than reacting to speculation.
Post-Breach: Strengthening Your Defences
A breach is painful, but it is also an opportunity to rebuild your security posture from the ground up. The ICO will look at what you do after the breach as much as what you did before it. Demonstrating genuine improvement can significantly mitigate any penalty.
Post-breach security improvements to implement:
- Eliminate email-based document collection. Replace it with zero-trust encrypted file sharing so that client documents are never stored in plaintext on your servers.
- Enable multi-factor authentication everywhere. Review and restrict access permissions so that staff can only reach the data they need for their role.
- Encrypt all stored client data at rest. Any data that cannot be deleted immediately should be encrypted so that a future access breach cannot be read.
- Commit to annual staff security awareness training. Human error remains the leading cause of professional data breaches, and training significantly reduces that risk.
- Schedule quarterly penetration testing and regular data retention reviews. Combine these with incident response plan rehearsals and work towards Cyber Essentials Plus certification.
The ICO has stated that demonstrable improvements after a breach are considered a mitigating factor when determining penalties. Investment in better security now can directly reduce your financial exposure.
The Financial Impact of Getting It Wrong
The costs of a data breach extend far beyond ICO fines. For a mid-sized professional practice, the total financial impact typically includes forensic investigation costs, legal fees, regulatory fines, client compensation, increased insurance premiums, and lost business. Studies from the UK Cyber Security Breaches Survey indicate the average cost for a professional services breach now exceeds £15,000 for small firms and significantly more for larger practices.
The headline penalty figures are well known: the ICO can fine up to £17.5 million or 4% of annual turnover for serious breaches. Individual clients can also bring compensation claims, each carrying its own legal costs regardless of outcome.
The good news is that a well-executed breach response, prompt notification, transparent communication, and genuine security improvements, consistently appears in ICO published enforcement decisions as a mitigating factor that reduces the eventual penalty. The published fining guidance treats the controller’s cooperation and remediation as part of the calculation.
Prevention Is Better Than Response
The best breach response plan is one you never have to use. Most professional data breaches originate from the same weak points: email attachments containing client documents, shared drives with excessive access permissions, and file sharing services that retain copies indefinitely.
The single most effective change you can make is eliminating email as a document collection channel. When client documents are encrypted before transmission, automatically deleted after download, and never stored in plaintext on your server, you eliminate the data that breaches exploit. Even if an attacker gains access to your systems, there is nothing for them to steal.
This is exactly the approach that professionals across the UK are adopting. Solicitors, accountants, financial advisors, and recruiters are switching to zero-trust document collection because the alternative is the 72-hour nightmare described in this guide.
Stop Emailing Sensitive Documents
AES-256 encryption. Auto-delete after download. No client accounts needed. GDPR compliant.
Written by the FileSeal security and compliance team. We specialise in document security, GDPR compliance, and data protection for UK professionals. Our guides are reviewed by industry practitioners and updated regularly.
