
Are staff, clients or directors worried about what happens after a data breach? For many UK SMEs the immediate questions are practical: who to contact, what the insurer expects, when to tell the ICO and how to talk to customers and the media without making the situation worse. This guide explains Data Breach Response & PR in plain British English, focusing on the exact actions an SME can take in the first hours and days to limit regulatory, financial and reputational damage.
Key takeaways: what to know in one minute
- Act fast but follow process: contain first, investigate with evidence preservation, then communicate.
- Notify regulators within GDPR timeframes if required: 72 hours to the ICO unless the breach is unlikely to risk individuals' rights.
- Notify insurer promptly and preserve evidence: insurers expect immediate notification, cooperation and no alteration of logs.
- Clear PR messages protect trust: honest, timely, and targeted communications reduce reputational harm.
- Check policy gaps early: many SME policies have sub-limits or exclusions for PR, social engineering and business interruption.
What your insurer expects after a data breach
Insurers typically expect a prompt notification, full cooperation, and evidence preservation. Notification must usually happen as soon as a breach is discovered or within a policy condition timeframe. Key insurer expectations include:
- Immediate notification of the incident under the policy's reporting condition.
- Preservation of all relevant logs, backups, devices and chain-of-custody evidence for forensic review.
- Limiting changes to systems (no reimaging or deletion) until an appointed forensic team advises—unless containment requires immediate action.
- Providing timely responses to insurer requests and appointing a single point of contact for claims handling.
- Cooperation with appointed experts: many policies permit insurers to select or approve forensic and legal advisers; check whether the insurer must agree to an external adviser chosen by the insured.
Relevant sources: official guidance from the Information Commissioner's Office (ICO) explains data breach definitions and reporting obligations: ICO breach guidance. The NCSC also publishes practical technical advice: NCSC main site.
What counts as reasonable cooperation
Reasonable cooperation usually includes giving insurers access to incident timelines, forensic reports and remediation plans. It does not normally require disclosure of privileged legal advice unless requested, but legal privilege should be discussed with counsel.
Common insurer queries to expect
- When and how was the breach discovered?
- Which systems and data fields were affected?
- What containment steps were taken and by whom?
- Were any third parties or processors involved?
- What notifications have already been made (staff, customers, regulators)?
This checklist is a practical playbook split by timeframe. It assumes no in-house SOC and is tailored to SMEs (1–50 staff). Prioritise containment and evidence preservation; communications can follow as facts are verified.
0–4 hours: contain and preserve
- Isolate affected systems (disconnect from network where possible) but avoid destructive actions that erase logs.
- Preserve logs, timestamps and device images; snap memory if ransomware suspected.
- Record a clear timeline: who found the issue, when, and what was changed.
- Activate the incident response lead or external incident manager.
- Notify insurer as required by policy wording (early notification often required).
4–24 hours: triage and assess
- Commission a forensic triage from an experienced provider (insurer may have preferred panels).
- Identify the data categories affected: personal data, financial data, credentials.
- Evaluate business interruption impact: systems offline, lost sales, payment failures.
- Draft initial holding statements for staff and customers.
- Start a secure communications log for decisions and messages.
24–72 hours: regulatory and stakeholder actions
- Assess GDPR breach notification requirements (see next section).
- Prepare notifications to affected individuals if breach likely to cause high risk to rights.
- Prepare press and customer communications: honest, concise, and next-step oriented.
- Engage legal counsel to review regulatory obligations and privilege strategy.
- Confirm insurer’s acceptance to fund forensic and PR costs where covered.
>72 hours: recovery and review
- Restore services from verified clean backups.
- Implement corrective measures recommended by forensics.
- Begin post-incident communications and offer support to affected clients (credit monitoring, helplines if appropriate).
- Conduct a lessons-learned review and update incident response plans and cyber insurance cover.
| Timeframe |
Immediate actions |
Who to inform |
| 0–4 hours |
Isolate systems, preserve logs, appoint lead |
Internal response team, insurer (per policy) |
| 4–24 hours |
Forensic triage, initial communications |
Forensic provider, legal adviser |
| 24–72 hours |
Regulatory assessment, customer notifications |
ICO (if required), affected individuals |
- System logs, firewall and proxy logs, authentication logs.
- Backup snapshots and last clean backup timestamp.
- Email traces for suspicious phishing messages.
- Device serial numbers and user IDs of impacted accounts.
- Internal communications about the incident.
Handling breach PR: tips to protect reputation
Public communications are a parallel track to technical response. Well-managed PR can materially reduce customer churn and regulatory scrutiny.
Core PR principles
- Be factual, not speculative. Admit what is known and commit to follow up.
- Communicate quickly to those directly affected; wider public announcements can wait until facts are verified.
- Use a centralised communications sign-off to avoid conflicting messages.
- Avoid minimising language: phrases like "no material impact" may be construed as misleading if facts change.
- Provide practical support and clear next steps for affected individuals.
Audience mapping and channels
- Affected customers and clients: personal emails and secure portal notices.
- Staff and contractors: internal memo and FAQs.
- Regulators: formal notifications per GDPR and sector rules.
- Public/media: press release and monitored social channels.
Press release template (editable)
- Headline: concise and factual (one line).
- Lead: what happened, when, what is affected (one sentence).
- Actions: immediate steps taken and how individuals can check if affected.
- Support: contact details and hours for enquiries.
- Quote: brief organisational statement of responsibility and next steps.
- Ends with a short background sentence about the organisation.
Customer email template (editable)
Subject: Important information about your personal data
Dear [Name],
On [date] [organisation] detected [brief description]. The data involved may include [data types]. Immediate steps were taken to [containment]. At this stage, [what action recipients should take]. For help contact [secure link] or call [phone number].
Apologies for the inconvenience. An investigation is underway and further updates will follow.
Regards,
[Incident lead]
- Post short, consistent messages directing people to a central FAQ page.
- Prepare a brief FAQ addressing likely questions: what happened, what was affected, what to do, and contact details.
- Avoid technical jargon; explain impact in plain language.
[Visual] Breach response timeline
Breach response timeline
🔍 Discovery → ⚡ Contain → 🧭 Investigate → 📣 Notify → 🔁 Recover
0–4h
Isolate systems
4–24h
Forensic triage
24–72h
Notify & communicate
72h+
Recover & review
How cyber insurance supports forensic investigation costs
Many SME cyber policies include cover for forensic IT investigations, legal and regulatory costs and crisis PR. Typical points:
- Forensic costs: policies often cover reasonable computer forensics to determine scope and cause. Some policies require insurer agreement before incurring costs.
- Legal and regulatory costs: legal advice on GDPR and regulatory notices is commonly included.
- Public relations and notification costs: many policies offer a sub-limit for PR, communication and notification expenses. The size and scope vary widely.
- Business interruption: some policies cover lost turnover and increased costs of working as a result of a breach, subject to waiting periods and sub-limits.
What insurers rarely cover or limit
- Social engineering and business email compromise losses may be excluded or subject to strict proof requirements.
- Acts of war, state-backed attacks, or sanctions-related incidents may be excluded.
- Voluntary PR beyond an allocated sub-limit may not be recoverable without prior agreement.
Practical steps to secure cover for forensic costs
- Notify the insurer promptly and request written confirmation of cover for forensic work.
- Ask whether the insurer will appoint the forensic firm or consent to an externally chosen provider; clarify who pays while cover is being confirmed.
- Avoid instructing external forensic work without insurer consent if the policy requires it, unless immediate action is necessary to stop ongoing harm.
GDPR breach notification: deadlines and practical steps
Under the GDPR a personal data breach must be reported to the ICO when it is likely to result in a risk to individuals' rights and freedoms. Key points:
- Report to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. ICO guidance.
- If notification is not made within 72 hours, include reasons for the delay.
- Where the breach is likely to result in a high risk to individuals, the data controller must also communicate the breach to the affected data subjects without undue delay.
- Notifications should include nature of the breach, categories of personal data affected, likely consequences, measures taken and contact details for further information.
Practical drafting tips for ICO notifications
- Use factual, concise language and include held evidence such as forensic initial findings.
- Record internally a full timeline and rationale for decisions to notify or not notify data subjects.
- Keep regulatory counsel involved when drafting submissions to preserve legal privilege where relevant.
Policy gaps to watch in breach response cover
SME buyers frequently misunderstand or overlook policy limitations. Common gaps include:
- PR and reputational damage sub-limits that are too small for an effective campaign.
- Exclusions for social engineering and payment fraud.
- Requirement for insurer consent before commissioning forensic work, which can delay urgent action.
- Retroactive date or prior incident exclusions.
- Aggregation clauses or single-occurrence limits which reduce payouts for repeated attacks.
- Failure to maintain minimum security standards (warranty clauses) that can void cover if not met.
How to check for these gaps
- Request policy wordings and read the definitions of "incident", "breach" and "computer forensic services".
- Check sub-limits and separate limits for PR, notification and business interruption.
- Confirm whether the insurer will step in to manage PR and forensic appointments.
- Where necessary, ask a regulated insurance adviser or broker to explain policy terms (this is not legal or financial advice).
Analysis: advantages, risks and common mistakes
✅ Benefits / when this approach helps
- Rapid, coordinated action reduces data exposure and prevents further loss.
- Early insurer engagement can accelerate access to expert forensics and PR support.
- Clear, empathetic communications preserve customer trust and limit brand damage.
⚠️ Errors to avoid / common pitfalls
- Delaying insurer notification or forensic preservation risks claim denial.
- Publicly speculating about causes before forensic confirmation.
- Overlooking small datasets that are nevertheless personal and trigger GDPR notification.
- Assuming PR costs are unlimited under a cyber policy; many policies have modest sub-limits.
Preguntas frecuentes
What should be included in the initial notification to the insurer?
Provide a concise timeline, systems affected, suspected data types, containment steps already taken and whether law enforcement or the ICO has been informed.
How soon must the ICO be told about a data breach?
The ICO should be informed without undue delay and, when feasible, within 72 hours of becoming aware of the breach if it risks individuals' rights and freedoms.
Can an SME instruct its own forensic provider if the insurer has a panel?
Some policies allow the insured to instruct an independent provider but typically require insurer consent or offer to appoint their panel; check policy wording and seek written confirmation.
Will cyber insurance pay for crisis PR?
Many policies include PR and notification costs but often with sub-limits; review the policy schedule for limits and prior consent requirements.
What to tell customers in the first message after a breach?
A short, factual message: what happened, what is known, what steps are being taken, and how customers can get support or updates.
Are ransom payments usually covered?
Ransom payments may be covered by some policies under cyber extortion cover, but this varies and often requires insurer approval and strict conditions.
Does a report to the ICO mean automatic enforcement or fines?
A notification does not automatically trigger a fine. The ICO assesses the incident, the controller's response and mitigation before any enforcement action.
Your next step:
- Contact the insurer or broker named in the policy immediately and confirm the claims notification process.
- Preserve all logs and evidence, and avoid system changes until a forensic triage is completed (unless necessary to stop ongoing harm).
- Draft short, factual communications for staff, affected customers and regulators; keep messages consistent and centralised.