How to Assess a Data Breach: A Step-by-Step Guide to Scoping

A data breach puts pressure on a business from the moment it is discovered, and the quickest way to steady the situation is to assess its scope.

Scoping involves:

  • Determining which systems were affected
  • What information was accessed
  • Whether the breach is still ongoing

These early findings support technical recovery and guide your decisions under UK GDPR. The UK’s National Cyber Security Centre notes that no security system is perfect, and cyber incidents will occur. Its incident management guidance explains how to plan, build, and maintain an effective response capability, and why good preparation matters, as fraud and cybercrime cost organisations many millions of pounds each year [1].

Should you need it, the Information Commissioner’s Office (ICO) also offers practical personal data breach advice. These include the first 72-hour actions, risk assessment and prevention tools for small organisations [2]. However, our team also provide IT Security to help organisations recover in challenging situations.

Our guide helps you identify compromised data, find the cause, assess the impact, and make informed decisions about containment, reporting, and long-term resilience.

Step 1: Identify What Has Been Compromised

The first step in assessing a data breach is to identify which parts of your network or cloud environment exhibit anomalous activity. This often includes shared folders, email accounts or core systems such as finance tools and CRMs. Focusing on these areas gives you a clear starting point and prevents the investigation from becoming too broad.

To make this easier, it helps to have a single, joined-up view of your IT estate. Our IT Services support businesses that want centralised oversight of devices, connectivity, and systems. Simply put, our involvement makes it easier to spot when something looks out of place.

Next, review the types of information held in the affected systems. Many small and medium-sized businesses store a mix of:

  • Personal data, such as customer or employee details
  • Financial information, including invoices and payment records
  • Login credentials or access tokens
  • Operational files, such as contracts, plans or internal reports

The ICO advises organisations to assess whether a breach involves personal data and whether it puts people at risk, even if it is not reportable. Their risk assessment guidance explains how to think through likelihood and severity in practical terms [3].

Finally, use available logs and built-in tools to pinpoint suspicious access. In Microsoft 365, for example, account sign-in history can reveal unexpected locations or times of access. If you use Microsoft 365 and want help reviewing these signals, our Microsoft 365 Support service explains how a partner can assist with configuration, monitoring and incident review.

Keep notes as you go. A simple record of which folders, mailboxes and devices were in scope will help later when you assess impact and decide what to report.

Step 2: Trace the Data Breach & Revoke Access

Once you know which systems and data are affected, the next step is understanding how the data breach occurred. This helps you close the entry point and prevent recurrence.

Start by reviewing recent activity in your systems, and focus on:

  • Login attempts, especially from unusual locations or times
  • New or changed user accounts and permissions
  • Alerts from antivirus, firewalls or email security tools

Many breaches begin with weak or stolen passwords, unpatched software, or phishing emails. A basic timeline of events makes it easier to see whether the breach was a single incident or part of a longer pattern of access.

At the same time, move to contain the breach. Reset compromised passwords, remove affected devices from the network and end suspicious sessions in cloud platforms. Preserve logs and key files while you do this so you can continue to investigate what happened.

If you would like ongoing help monitoring and managing your environment, our Small Business IT Services provide steady, local support for day-to-day IT and security issues.

Step 3: Assess the Impact & Meet Your Breach Duties

The next focus is impact. This is where you bring together what you know about compromised data, affected systems and how the breach happened.

Start with a simple impact review:

  • Estimate how many records or files were accessed
  • Note whether they include personal, financial or confidential information
  • Consider which customers, employees or partners could be affected

This information feeds into your legal duties. The ICO explains that you need to weigh the likelihood of people suffering harm and the seriousness of that harm. For example, exposed financial details or login credentials may create a higher risk of fraud than basic contact information. If the risk is likely, you must report the breach to the ICO within 72 hours; if the risk is high, you must also inform the individuals affected.

A short incident record is helpful here, so note:

  • What you discovered
  • When you took key actions
  • Who was involved in the response

This makes it easier to answer follow-up questions from regulators or affected individuals and gives you a helpful reference point when you review your approach afterwards. If you need help stabilising systems or restoring regular operation while you work through this process, our Business IT Support service is designed to keep local organisations running smoothly.

Turn a Data Breach into Stronger Security

Once you have contained the incident and fulfilled your reporting obligations, take time to strengthen your security position. The aim is to reduce the likelihood of another data breach and to make recovery easier if one occurs again.

Start by reviewing how people use your systems day to day. Many incidents begin with a rushed click on a convincing email or a file shared more widely than intended. Clear policies, practical user training, and simple reporting routes for suspicious activity can all make it easier for staff to spot and raise concerns before they escalate into larger problems.

Then create or improve your response plan. A short, practical checklist covering who to contact, which systems to review first and how to record key decisions can reduce confusion in the early stages of a new incident. Testing this plan with a simple exercise or walkthrough can also highlight gaps before you need to use it for real.

Finally, build in regular reviews. Periodic checks of user access, backup-restore tests, and basic security health checks can flag issues before they escalate into incidents. If you want long-term support in this area, our team offers a reliable Data Backup service to support continuity and recovery.

Bring Your Data Breach Under Control

Scoping a data breach gives your business a clear picture of what has happened, so you can respond in a measured way and focus resources where they matter most. By identifying compromised data, understanding how the incident occurred, and reviewing the impact, you build a solid foundation for containment, compliance, and honest communication with those affected.

Remember, a simple, repeatable process turns each incident into a chance to improve how your organisation manages digital risk.

Town & Country Communications supports local businesses that want calm, practical IT guidance. From everyday support to longer-term security improvements, we can help keep systems stable while strengthening your ability to deal with data breaches and other incidents.

Call 01202 514444 or arrange a free consultation to review your current setup and implement a clear, workable data breach response plan.

External Sources

[1] GOV.UK, “National Cyber Security Centre”: https://www.ncsc.gov.uk/collection/incident-management

[2] Information Commissioner’s Office (ICO): https://ico.org.uk/for-organisations/advice-for-small-organisations/personal-data-breaches/

[3] Information Commissioner’s Office (ICO), “risk assessment guidance”: https://ico.org.uk/for-organisations/advice-for-small-organisations/personal-data-breaches/understanding-and-assessing-risk-in-personal-data-breaches/

Share this post

Other recent posts