
A data breach puts pressure on a business from the moment it is discovered, and the quickest way to steady the situation is to assess its scope.
Scoping involves:
These early findings support technical recovery and guide your decisions under UK GDPR. The UK’s National Cyber Security Centre notes that no security system is perfect, and cyber incidents will occur. Its incident management guidance explains how to plan, build, and maintain an effective response capability, and why good preparation matters, as fraud and cybercrime cost organisations many millions of pounds each year [1].
Should you need it, the Information Commissioner’s Office (ICO) also offers practical personal data breach advice. These include the first 72-hour actions, risk assessment and prevention tools for small organisations [2]. However, our team also provide IT Security to help organisations recover in challenging situations.
Our guide helps you identify compromised data, find the cause, assess the impact, and make informed decisions about containment, reporting, and long-term resilience.
The first step in assessing a data breach is to identify which parts of your network or cloud environment exhibit anomalous activity. This often includes shared folders, email accounts or core systems such as finance tools and CRMs. Focusing on these areas gives you a clear starting point and prevents the investigation from becoming too broad.
To make this easier, it helps to have a single, joined-up view of your IT estate. Our IT Services support businesses that want centralised oversight of devices, connectivity, and systems. Simply put, our involvement makes it easier to spot when something looks out of place.
Next, review the types of information held in the affected systems. Many small and medium-sized businesses store a mix of:
The ICO advises organisations to assess whether a breach involves personal data and whether it puts people at risk, even if it is not reportable. Their risk assessment guidance explains how to think through likelihood and severity in practical terms [3].
Finally, use available logs and built-in tools to pinpoint suspicious access. In Microsoft 365, for example, account sign-in history can reveal unexpected locations or times of access. If you use Microsoft 365 and want help reviewing these signals, our Microsoft 365 Support service explains how a partner can assist with configuration, monitoring and incident review.
Keep notes as you go. A simple record of which folders, mailboxes and devices were in scope will help later when you assess impact and decide what to report.
Once you know which systems and data are affected, the next step is understanding how the data breach occurred. This helps you close the entry point and prevent recurrence.
Start by reviewing recent activity in your systems, and focus on:
Many breaches begin with weak or stolen passwords, unpatched software, or phishing emails. A basic timeline of events makes it easier to see whether the breach was a single incident or part of a longer pattern of access.
At the same time, move to contain the breach. Reset compromised passwords, remove affected devices from the network and end suspicious sessions in cloud platforms. Preserve logs and key files while you do this so you can continue to investigate what happened.
If you would like ongoing help monitoring and managing your environment, our Small Business IT Services provide steady, local support for day-to-day IT and security issues.
The next focus is impact. This is where you bring together what you know about compromised data, affected systems and how the breach happened.
Start with a simple impact review:
This information feeds into your legal duties. The ICO explains that you need to weigh the likelihood of people suffering harm and the seriousness of that harm. For example, exposed financial details or login credentials may create a higher risk of fraud than basic contact information. If the risk is likely, you must report the breach to the ICO within 72 hours; if the risk is high, you must also inform the individuals affected.
A short incident record is helpful here, so note:
This makes it easier to answer follow-up questions from regulators or affected individuals and gives you a helpful reference point when you review your approach afterwards. If you need help stabilising systems or restoring regular operation while you work through this process, our Business IT Support service is designed to keep local organisations running smoothly.
Once you have contained the incident and fulfilled your reporting obligations, take time to strengthen your security position. The aim is to reduce the likelihood of another data breach and to make recovery easier if one occurs again.
Start by reviewing how people use your systems day to day. Many incidents begin with a rushed click on a convincing email or a file shared more widely than intended. Clear policies, practical user training, and simple reporting routes for suspicious activity can all make it easier for staff to spot and raise concerns before they escalate into larger problems.
Then create or improve your response plan. A short, practical checklist covering who to contact, which systems to review first and how to record key decisions can reduce confusion in the early stages of a new incident. Testing this plan with a simple exercise or walkthrough can also highlight gaps before you need to use it for real.
Finally, build in regular reviews. Periodic checks of user access, backup-restore tests, and basic security health checks can flag issues before they escalate into incidents. If you want long-term support in this area, our team offers a reliable Data Backup service to support continuity and recovery.
Scoping a data breach gives your business a clear picture of what has happened, so you can respond in a measured way and focus resources where they matter most. By identifying compromised data, understanding how the incident occurred, and reviewing the impact, you build a solid foundation for containment, compliance, and honest communication with those affected.
Remember, a simple, repeatable process turns each incident into a chance to improve how your organisation manages digital risk.
Town & Country Communications supports local businesses that want calm, practical IT guidance. From everyday support to longer-term security improvements, we can help keep systems stable while strengthening your ability to deal with data breaches and other incidents.
Call 01202 514444 or arrange a free consultation to review your current setup and implement a clear, workable data breach response plan.
[1] GOV.UK, “National Cyber Security Centre”: https://www.ncsc.gov.uk/collection/incident-management
[2] Information Commissioner’s Office (ICO): https://ico.org.uk/for-organisations/advice-for-small-organisations/personal-data-breaches/
[3] Information Commissioner’s Office (ICO), “risk assessment guidance”: https://ico.org.uk/for-organisations/advice-for-small-organisations/personal-data-breaches/understanding-and-assessing-risk-in-personal-data-breaches/