This is a broad UK-specific framework for how a business might respond to a cyber incident, including relevant steps for compliance and legal considerations. Each business will have its own considerations that will refine this further on top.
It’s worth noting that:
- Much of what is described below will be well beyond the capabilities of most company internal IT teams and even generalist outsource IT support firms
- However, many cyber insurance products available now include coverage that will arrange, implement, support and pay for the required activities outlined below
Detection and Identification
- Confirm and monitor the Attack: Validate the breach to determine whether it’s a cyber incident, insider threat, or other security event.
Incident Response Team Activation
- Activate Your Incident Response Plan: Assemble your internal team, including the IT security team, legal advisor, and public relations support (if required). If necessary, hire a third-party cybersecurity firm.
- Cyber Insurance: If your organisation has cyber insurance, inform your insurer promptly. Many policies include a cyber response service, not just paying for but arranging and implementing a full outsourced incident response team.
- Documentation: Document all steps taken during the response, which will be essential for any investigation and reporting to the ICO and possibly the NCA.
Containment
- Isolate Affected Systems: Disconnect systems or networks that are compromised to limit the attack’s spread, keeping in mind that a ransomware attack might require isolating backups as well.
- Contain Data Leaks: If personally identifiable information (PII) is involved, prepare to notify affected individuals in compliance with GDPR’s 72-hour reporting window (more on this below).
Eradication
- Remove Malware and Backdoors: If malicious software is detected, work with cybersecurity experts to remove it.
- Patch Vulnerabilities: Ensure that any vulnerabilities that were exploited are patched to prevent further incidents.
Communication
- Internal Communication: Keep senior management, the IT team, and key stakeholders informed about the breach. If necessary, activate a Crisis Communications Plan.
- External Communication: You may need to communicate with external partners, vendors, and customers. Be transparent about the breach and its potential impact.
- Notify the ICO (Information Commissioner’s Office): Under GDPR, you must notify the ICO of a data breach within 72 hours if it involves personal data that could result in harm to individuals.
Investigation and Analysis
- Forensic Investigation: If the breach is severe, consider engaging a forensic investigator to determine the scope of the attack, the method used, and the nature of the data impacted.
- Assess the Type of Attack: Whether it’s phishing, ransomware, DDoS, or an insider threat, understanding the type of attack will guide your recovery efforts.
- Impact Assessment: Identify which data has been accessed, stolen, or compromised. If it involves PII or special category data (e.g., health data), it triggers strict GDPR notification rules.
Recovery
- Restore from Backups: If your backup systems are unaffected, restore operations from clean backups. Ensure these backups are free from any malware or backdoor implants.
- Patch Security Flaws: Ensure all vulnerabilities, including those in software, network devices, or user access, are addressed before bringing systems back online.
- Monitor for Recurrence: After systems are restored, continue to monitor for unusual activity to ensure the attacker hasn’t maintained persistence in your environment.
Post-Incident Activities
- Notify the ICO: If the attack has impacted personal data (e.g., email addresses, credit card details, health records), notify the ICO within 72 hours. You may also need to notify affected individuals if their rights and freedoms could be at risk.
- Report to Law Enforcement: If the breach involves a criminal activity, report it to the National Crime Agency (NCA), especially if it involves significant financial loss or fraud.
Legal and Compliance Considerations
- Data Breach Notification under GDPR: In addition to notifying the ICO, you are required to inform affected individuals when the breach poses a high risk to their rights and freedoms (e.g., identity theft, fraud, etc.).
- GDPR Articles 33 and 34: Article 33 outlines the timing and contents of your report to the ICO, while Article 34 covers your notification to affected individuals.
Communication with Customers and Clients
- Customer Transparency: Following a cyber incident, communicate clearly with customers about what information was compromised, how it might affect them, and what you are doing to address the breach.
- Provide Resources for Affected Customers: If personal data such as credit card details or identity information was exposed, consider offering affected individuals free credit monitoring or identity theft protection.
- Public Relations Strategy: In cases of large-scale breaches, a well-crafted public statement is essential. Work with PR professionals to manage the narrative.
Training and Prevention Moving Forward
- Employee Cybersecurity Awareness: Regularly train employees on spotting phishing attempts, using strong passwords, and following company security protocols. Ensure employees understand the NCSC Cyber Essentials framework.
- Penetration Testing and Vulnerability Assessments: Schedule regular vulnerability assessments and penetration testing to proactively identify weaknesses.
- Improve Your Incident Response Plan: Use lessons learned from the breach to update your incident response protocols. This might involve testing your plans with tabletop exercises and ensuring that your staff is regularly trained.
As you can see, there are many activities you need to undertake in order to successfully recover from a cyber incident from a commercial, legal and regulatory perspective, whist all the time continuing to run your business. Having cyber insurance in place can simplify this process and mitigate the time and costs associated with doing so.
If you wish to discuss your cyber risks and your cyber insurance needs, please do not hesitate to contact Anderson Smith.







