Cyber ​​incident management of personal data breaches

6. How to manage a computer security data breach incident

To reduce the damage caused by a potential data breach, an organisation must define procedures and steps for incident response before a data breach or any cybersecurity incident occurs.

Developing an effective plan is the first step toward carrying out a successful response to data breach incidents.

A data breach response plan or data breach response policy provides a framework that defines the roles of employees involved in handling a data breach and the steps they should take if (or when) a breach occurs.

One advantage of having an established incident response capability is that it supports a systematic reaction to incidents by ensuring that appropriate, predefined actions are taken. Incident response helps organisations minimise data loss or theft and reduce service disruptions caused by the incident.

Another benefit of incident response is the ability to use information gathered during incident handling to better prepare for future incidents and ensure stronger protection of data and systems.

Incident response capability also helps address legal issues that may arise during an incident.

The steps that must be taken in the process of managing a cybersecurity data breach incident include:

  1. preparation for a data breach incident,
  2. detecting whether a data breach has actually occurred,
  3. executing emergency incident response actions,
  4. collecting evidence,
  5. analysing the data breach,
  6. implementing containment, eradication, and system recovery measures,
  7. notifying affected parties,
  8. carrying out post‑incident activities.

Accessibility

Background Colour Background Colour

Font Face Font Face

Font Size Font Size

1

Text Colour Text Colour

Font Kerning Font Kerning

Image Visibility Image Visibility

Letter Spacing Letter Spacing

0

Line Height Line Height

1.2

Link Highlight Link Highlight