Cyber incident grab bag: Protecting data

Measures to take to mitigate risks to personal and sensitive data.


Alongside the disruptive impacts to your services, cyber incidents can create significant risks to personal and sensitive data that can be compromised as a result of the incident. 

Cyber criminals may attempt to steal and exploit data, including threat of publication to extort payment, or cause harm to individuals.   

A well organised response to a cyber incident will include carefully planned steps to protect data and to mitigate risks that might arise from personal or other sensitive data being published. You also have legal duties relating to personal data under the Data Protection Act (2018) to which you will need to comply. Treat this part of your response as being equally important as the technical recovery work and maintaining business continuity for your services. 

Your key strategic actions 

(Note: these are a strategic guide, not an exhaustive list of every action you should take.) 

To ensure that you are taking appropriate steps to protect data and people whose data might be impacted by the incident you should: 

  • Treat data risk mitigation as an equal priority to other aspects of your response. Do not assume that data has not been compromised simply because there are no other visible signs of an attack (such as encryption).
  • Use advice from the Information Commissioner’s Office (ICO) to help you design your response. Do not delay engaging with the ICO. The 72 hour time limit for reporting applies even if you are still clarifying details. You will be able to update the ICO as your investigations progress.
  • Set up a team focussed on responding to data risks so you can assess risks and develop mitigation measures as rapidly as possible.
  • Work closely with your insurance team to ensure you are managing the risks of potential legal claims effectively. 
  • Plan and test your response for potential publication of stolen data. This will help you to ensure that you, your team and your partners are prepared in the event that this happens.
  • Work proactively with service teams and third party data owners. This will help you to avoid confusion or delay if you need to respond to risks as a result of data being stolen by attackers. 

Key contacts

  • ICO – Helpline: 0303 123 1113
  • Your organisation’s Data Protection Officer
  • Your organisation’s information management / governance lead or team
  • Impacted system owners or Information Asset Owners as per your register

Useful resources and case studies