What to Do After a Cyber Breach: UK Business Guide
If your business has experienced a cyber breach, act quickly. Contain the threat, preserve evidence, assess what data was affected, notify the ICO within 72 hours if personal data was involved, and engage professional incident response support.
Quick answer
After a cyber breach, move fast and in order: isolate affected systems without powering them off, preserve the logs and evidence, work out what data was hit, report to the ICO within 72 hours if personal data was involved, then bring in professional incident response. The first 24 hours decide how much damage you contain.
Step-by-Step: After a Cyber Breach
Follow these steps in order after discovering a breach.
1. Contain the Threat
Isolate affected systems from the network immediately. Do not shut them down — this may destroy evidence. Disconnect from the internet if necessary.
2. Preserve Evidence
Do not delete, modify, or rebuild affected systems. Logs, malware samples, and system states are critical for investigation and may be needed for legal proceedings.
3. Assess the Impact
Determine what data was accessed, stolen, or encrypted. Identify which systems were affected and whether the threat is still active.
4. Notify the ICO
If personal data was compromised, you must report to the ICO within 72 hours. Use the ICO's self-assessment tool to determine whether your breach meets the reporting threshold.
5. Notify Affected Parties
If the breach poses a high risk to individuals' rights and freedoms, you must notify them directly and without undue delay.
6. Get Professional Help
Engage an incident response provider to investigate the breach, eradicate the threat, and guide recovery. AMVIA provides emergency IR support to UK businesses.
Breach Response: DIY vs Professional IR
Comparing outcomes when handling a breach internally versus engaging professional support.
| Feature | DIY ResponseInternal staff only | Professional IR£5K–£30KRecommended |
|---|---|---|
| Threat fully eradicated | Uncertain | Verified |
| Evidence preserved for legal | Often lost | |
| Root cause identified | Rarely | |
| ICO-compliant documentation | Unlikely | |
| Recovery time | Weeks | Days |
| Prevents recurrence | Uncertain |
The hours after you discover a breach are chaotic, and the wrong instinct — wiping a machine, rebuilding a server, quietly hoping it goes away — destroys the evidence you need and can put you on the wrong side of the law. This guide sets out the exact sequence we run for clients, why each step matters, and where your legal clock is already ticking. It sits under our managed cybersecurity practice, where detection, response and recovery are handled by one accountable provider.
What counts as a cyber breach you must act on?
A cyber breach is any incident where an attacker gains unauthorised access to your systems or data — ransomware, a compromised email account, stolen credentials, data exfiltration, or a successful phishing attack. If personal data may have been accessed, altered, or stolen, it becomes a reportable event under UK GDPR and the clock starts the moment you become aware.
Not every alert is a breach, but treat anything that touches personal or financial data as one until you can prove otherwise. The cost is real: the government's Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach for UK businesses at £3,550 (gov.uk), and that figure excludes the reputational and legal fallout that follows a mishandled response.
What should you do in the first 24 hours after a cyber breach?
In the first 24 hours, contain the threat, preserve evidence, assess the impact, and start your reporting obligations. Speed limits the blast radius and protects your legal position. Do not rebuild, do not pay anyone, and do not communicate externally until you understand what happened. Follow this sequence.
1. Contain the threat. Isolate affected systems from the network — pull the network cable or disable the NIC. Do not power machines off; that wipes volatile memory evidence. 2. Preserve evidence. Leave logs, system images, and any malware samples intact for forensic capture. 3. Assess the impact. Establish what data was accessed, stolen, or encrypted, and whether the attacker still has access. 4. Report to the ICO. If personal data was compromised, the 72-hour clock applies (see below). 5. Notify affected individuals. Required where there is a high risk to their rights and freedoms. 6. Engage professional incident response. Bring in a team to eradicate the threat, verify it is gone, and guide recovery. 7. Report the crime. Report to Action Fraud, and to the NCSC if the incident is nationally significant.
The NCSC's incident management guidance is the authoritative UK reference for working through these stages under pressure.
How do you contain a breach and preserve evidence at the same time?
Containment and evidence preservation pull in opposite directions, so do them in the right order: isolate first by cutting network access, then capture forensic images before you change anything. Disconnecting a machine stops lateral movement; powering it down or rebuilding it destroys the logs, memory, and artefacts an investigator needs to find the root cause.
Preserve these as a minimum:
- Firewall and VPN logs
- Email server and mailbox audit logs
- Endpoint detection and response (EDR) alerts and telemetry
- Full disk images of affected machines
- Any malware samples or suspicious files
This evidence underpins three things at once: root-cause analysis, a defensible ICO report, and any future legal or insurance claim. If you are not confident capturing forensic images cleanly, stop and call an incident response team before you touch the machine.
When must you report a cyber breach to the ICO?
If a breach involves personal data and poses a risk to individuals' rights and freedoms, you must report it to the ICO within 72 hours of becoming aware. Miss the deadline or get the assessment wrong and the maximum penalty under UK GDPR is fines of up to £17.5 million or 4% of annual turnover, whichever is higher.
The 72 hours runs from awareness, not from when you finish investigating — so notify even if your picture is incomplete, then follow up. Use the ICO's self-assessment and reporting tool to decide whether your breach meets the threshold and to file. If the breach poses a *high* risk to individuals, you must also tell those people directly and without undue delay.
Should you pay a ransomware demand after a breach?
No. The NCSC and UK law enforcement strongly advise against paying ransoms. Payment does not guarantee you get your data back, it marks you as a business that pays, and it funds further criminal activity. There is no legal protection in paying, and it does not discharge your ICO obligations.
Recovery from clean, tested backups is the route the NCSC recommends — see its ransomware guidance. The headline cost figures understate ransomware specifically: the average most-disruptive-breach cost across all UK businesses is £3,550 (Cyber Security Breaches Survey 2025), but ransomware recovery routinely runs far higher once downtime, rebuild, and lost revenue are counted. If you want the full picture, read our ransomware guide.
DIY response vs professional incident response — which do you need?
For anything beyond a single contained mailbox compromise, use professional incident response. Internal IT can isolate a machine, but verifying full eradication, preserving court-grade evidence, and producing ICO-ready documentation is specialist work. The table below shows where DIY response tends to fall down.
| Outcome | DIY response (internal staff only) | Professional IR (£5K–£30K, typical UK 2026 range) |
|---|---|---|
| Threat fully eradicated | Uncertain | Verified |
| Evidence preserved for legal/insurance | Often lost | Yes |
| Root cause identified | Rarely | Yes |
| ICO-compliant documentation | Unlikely | Yes |
| Typical recovery time | Weeks | Days |
| Recurrence prevented | Uncertain | Yes |
The hidden risk with DIY is the breach you *think* you cleaned. Attackers leave persistence — extra accounts, scheduled tasks, web shells — and without a thorough sweep they walk straight back in. Our managed detection and response service exists to catch exactly that, with Microsoft Defender for Endpoint monitored by AMVIA's in-house 24/7 SOC.
How do you prevent a repeat breach after recovering?
Run a structured post-incident review to find the root cause, then close the specific gap that let the attacker in — not a generic shopping list. Most repeat breaches happen because the original entry point was never fixed. Tie every remediation step back to how this attacker actually got in.
Common, high-value remediations:
- Enforce multi-factor authentication on every account, with no exceptions
- Tighten Microsoft 365 Conditional Access policies
- Strengthen email filtering and anti-phishing controls
- Deploy endpoint detection and response across all devices
- Run targeted staff awareness and phishing-simulation training
That last point matters most: with 85% of breaches originating from phishing (Cyber Security Breaches Survey 2025), the human layer is where most repeat incidents start. A clean rebuild with the same untrained staff and the same weak email controls just resets the clock until the next one. Cyber insurers increasingly demand evidence of these controls too — see our guide to cyber insurance in the UK.
Frequently Asked Questions
You must report a personal data breach to the ICO within 72 hours of becoming aware of it, where it poses a risk to individuals' rights and freedoms. The clock starts at awareness, not at the end of your investigation, so report even with partial information. Failure to report can attract fines of up to £17.5 million or 4% of annual turnover under UK GDPR.
No. The NCSC and UK law enforcement strongly advise against paying ransoms. Payment does not guarantee data recovery, it marks you as a soft target, and it funds further crime. It also does not remove your legal obligation to report. Focus on restoring from clean, tested backups and engaging professional incident response to verify the threat is gone.
Preserve firewall and VPN logs, email and mailbox audit logs, endpoint detection alerts, full disk images, and any malware samples. Do not rebuild, wipe, or power down affected machines until forensic imaging is complete. This evidence is critical for root-cause analysis, your ICO report, insurance claims, and any legal proceedings. A professional IR team will guide you through correct collection.
You must notify affected individuals directly and without undue delay where the breach poses a high risk to their rights and freedoms. Below that threshold, direct notification is not legally required, but you must still document the breach internally. The ICO's self-assessment tool helps you judge the risk level and your notification duties.
Beyond the ICO, report cyber crime to Action Fraud, the UK's national reporting centre, and to the NCSC if the incident is nationally significant or affects critical services. If financial fraud occurred, tell your bank immediately. Your cyber insurer also usually requires notification within a set window — check your policy, as late notice can void cover.
With professional incident response, most SME breaches are contained and recovered within days; DIY recovery often stretches to weeks because eradication is rarely verified the first time. The variable is whether you have clean, tested backups and a documented response plan ready before the incident — preparation, not luck, is what shortens recovery.
Need Emergency Breach Support?
Call our incident response team immediately. Available 24/7 for UK businesses.
Related Resources
Managed Cybersecurity
Detection, response, and recovery as part of managed cybersecurity.
Incident Response Service
Professional incident response for UK businesses.
Ransomware Guide
Understanding and preventing ransomware.
Cyber Insurance UK
Getting and keeping cyber insurance coverage.
Protect your business → Get Cybersecurity Assessment