What to Do After a Cyber Breach: UK Business Guide

If your business has experienced a cyber breach, act quickly. Contain the threat, preserve evidence, assess what data was affected, notify the ICO within 72 hours if personal data was involved, and engage professional incident response support.

Quick answer

After a cyber breach, move fast and in order: isolate affected systems without powering them off, preserve the logs and evidence, work out what data was hit, report to the ICO within 72 hours if personal data was involved, then bring in professional incident response. The first 24 hours decide how much damage you contain.

Step-by-Step: After a Cyber Breach

Follow these steps in order after discovering a breach.

1. Contain the Threat

Isolate affected systems from the network immediately. Do not shut them down — this may destroy evidence. Disconnect from the internet if necessary.

2. Preserve Evidence

Do not delete, modify, or rebuild affected systems. Logs, malware samples, and system states are critical for investigation and may be needed for legal proceedings.

3. Assess the Impact

Determine what data was accessed, stolen, or encrypted. Identify which systems were affected and whether the threat is still active.

4. Notify the ICO

If personal data was compromised, you must report to the ICO within 72 hours. Use the ICO's self-assessment tool to determine whether your breach meets the reporting threshold.

5. Notify Affected Parties

If the breach poses a high risk to individuals' rights and freedoms, you must notify them directly and without undue delay.

6. Get Professional Help

Engage an incident response provider to investigate the breach, eradicate the threat, and guide recovery. AMVIA provides emergency IR support to UK businesses.

Breach Response: DIY vs Professional IR

Comparing outcomes when handling a breach internally versus engaging professional support.

Feature
DIY ResponseInternal staff only
Professional IR£5K–£30KRecommended
Threat fully eradicatedUncertainVerified
Evidence preserved for legalOften lost
Root cause identifiedRarely
ICO-compliant documentationUnlikely
Recovery timeWeeksDays
Prevents recurrenceUncertain

The hours after you discover a breach are chaotic, and the wrong instinct — wiping a machine, rebuilding a server, quietly hoping it goes away — destroys the evidence you need and can put you on the wrong side of the law. This guide sets out the exact sequence we run for clients, why each step matters, and where your legal clock is already ticking. It sits under our managed cybersecurity practice, where detection, response and recovery are handled by one accountable provider.

What counts as a cyber breach you must act on?

A cyber breach is any incident where an attacker gains unauthorised access to your systems or data — ransomware, a compromised email account, stolen credentials, data exfiltration, or a successful phishing attack. If personal data may have been accessed, altered, or stolen, it becomes a reportable event under UK GDPR and the clock starts the moment you become aware.

Not every alert is a breach, but treat anything that touches personal or financial data as one until you can prove otherwise. The cost is real: the government's Cyber Security Breaches Survey 2025 puts the average cost of the most disruptive breach for UK businesses at £3,550 (gov.uk), and that figure excludes the reputational and legal fallout that follows a mishandled response.

What should you do in the first 24 hours after a cyber breach?

In the first 24 hours, contain the threat, preserve evidence, assess the impact, and start your reporting obligations. Speed limits the blast radius and protects your legal position. Do not rebuild, do not pay anyone, and do not communicate externally until you understand what happened. Follow this sequence.

1. Contain the threat. Isolate affected systems from the network — pull the network cable or disable the NIC. Do not power machines off; that wipes volatile memory evidence. 2. Preserve evidence. Leave logs, system images, and any malware samples intact for forensic capture. 3. Assess the impact. Establish what data was accessed, stolen, or encrypted, and whether the attacker still has access. 4. Report to the ICO. If personal data was compromised, the 72-hour clock applies (see below). 5. Notify affected individuals. Required where there is a high risk to their rights and freedoms. 6. Engage professional incident response. Bring in a team to eradicate the threat, verify it is gone, and guide recovery. 7. Report the crime. Report to Action Fraud, and to the NCSC if the incident is nationally significant.

The NCSC's incident management guidance is the authoritative UK reference for working through these stages under pressure.

How do you contain a breach and preserve evidence at the same time?

Containment and evidence preservation pull in opposite directions, so do them in the right order: isolate first by cutting network access, then capture forensic images before you change anything. Disconnecting a machine stops lateral movement; powering it down or rebuilding it destroys the logs, memory, and artefacts an investigator needs to find the root cause.

Preserve these as a minimum:

  • Firewall and VPN logs
  • Email server and mailbox audit logs
  • Endpoint detection and response (EDR) alerts and telemetry
  • Full disk images of affected machines
  • Any malware samples or suspicious files

This evidence underpins three things at once: root-cause analysis, a defensible ICO report, and any future legal or insurance claim. If you are not confident capturing forensic images cleanly, stop and call an incident response team before you touch the machine.

When must you report a cyber breach to the ICO?

If a breach involves personal data and poses a risk to individuals' rights and freedoms, you must report it to the ICO within 72 hours of becoming aware. Miss the deadline or get the assessment wrong and the maximum penalty under UK GDPR is fines of up to £17.5 million or 4% of annual turnover, whichever is higher.

The 72 hours runs from awareness, not from when you finish investigating — so notify even if your picture is incomplete, then follow up. Use the ICO's self-assessment and reporting tool to decide whether your breach meets the threshold and to file. If the breach poses a *high* risk to individuals, you must also tell those people directly and without undue delay.

Should you pay a ransomware demand after a breach?

No. The NCSC and UK law enforcement strongly advise against paying ransoms. Payment does not guarantee you get your data back, it marks you as a business that pays, and it funds further criminal activity. There is no legal protection in paying, and it does not discharge your ICO obligations.

Recovery from clean, tested backups is the route the NCSC recommends — see its ransomware guidance. The headline cost figures understate ransomware specifically: the average most-disruptive-breach cost across all UK businesses is £3,550 (Cyber Security Breaches Survey 2025), but ransomware recovery routinely runs far higher once downtime, rebuild, and lost revenue are counted. If you want the full picture, read our ransomware guide.

DIY response vs professional incident response — which do you need?

For anything beyond a single contained mailbox compromise, use professional incident response. Internal IT can isolate a machine, but verifying full eradication, preserving court-grade evidence, and producing ICO-ready documentation is specialist work. The table below shows where DIY response tends to fall down.

OutcomeDIY response (internal staff only)Professional IR (£5K–£30K, typical UK 2026 range)
Threat fully eradicatedUncertainVerified
Evidence preserved for legal/insuranceOften lostYes
Root cause identifiedRarelyYes
ICO-compliant documentationUnlikelyYes
Typical recovery timeWeeksDays
Recurrence preventedUncertainYes

The hidden risk with DIY is the breach you *think* you cleaned. Attackers leave persistence — extra accounts, scheduled tasks, web shells — and without a thorough sweep they walk straight back in. Our managed detection and response service exists to catch exactly that, with Microsoft Defender for Endpoint monitored by AMVIA's in-house 24/7 SOC.

How do you prevent a repeat breach after recovering?

Run a structured post-incident review to find the root cause, then close the specific gap that let the attacker in — not a generic shopping list. Most repeat breaches happen because the original entry point was never fixed. Tie every remediation step back to how this attacker actually got in.

Common, high-value remediations:

  • Enforce multi-factor authentication on every account, with no exceptions
  • Tighten Microsoft 365 Conditional Access policies
  • Strengthen email filtering and anti-phishing controls
  • Deploy endpoint detection and response across all devices
  • Run targeted staff awareness and phishing-simulation training

That last point matters most: with 85% of breaches originating from phishing (Cyber Security Breaches Survey 2025), the human layer is where most repeat incidents start. A clean rebuild with the same untrained staff and the same weak email controls just resets the clock until the next one. Cyber insurers increasingly demand evidence of these controls too — see our guide to cyber insurance in the UK.

Frequently Asked Questions

Need Emergency Breach Support?

Call our incident response team immediately. Available 24/7 for UK businesses.