Knowledgebase

Handling a Security Breach as a Provider Print

  • security, troubleshooting, guide, howto, solution, zillionkinghost, hosting, support
  • 0

When customer data is exposed.

WHAT TO DO FIRST

Contain it: stop the access, before anything else.

WHAT TO PRESERVE

Logs and evidence, before changing systems.

WHAT TO ESTABLISH

What was accessed Whose data Over what period How it happened

WHY SCOPE MATTERS BEFORE NOTIFICATION

Notifying inaccurately, then correcting, is worse than notifying slightly later with accuracy.

WHAT OBLIGATIONS TYPICALLY APPLY

Notification of affected customers within a defined period Notification of regulators, where required Assistance to customers meeting their own obligations

WHY THAT LAST ONE

They are accountable to their own users and regulators, and they depend on you.

WHAT TO TELL CUSTOMERS

What happened What data was involved What you have done What they should do How you will update them

WHAT NOT TO DO

Delay hoping it resolves Minimise the scope Blame a third party Go quiet

WHY CONCEALMENT IS FATAL

It is discovered, and it converts an incident into a scandal.

WHAT TO DO AFTERWARDS

Fix the cause Verify the fix across everything Publish what changed

WHAT TO PREPARE NOW

The plan, the contacts, and the notification templates.

WHY NOW

There is no time to write them during an incident.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot