Cyber incident management of personal data breaches
1. Introduction
Cyber incident – an event that compromises the availability, authenticity, integrity, or confidentiality of stored, transmitted, or processed data, or of the services that network and information systems provide or enable access to. (National Taxonomy of Computer Security Incidents)
A data breach is a cyber incident that results in the exposure of confidential, sensitive, or otherwise protected information to unauthorised individuals.
Attackers often target organisations to gain access to employee and client personal data or to corporate information (intellectual property, financial data).
Data breaches can result from various cybersecurity‑related events, such as malicious insider activity, social engineering attacks, and the exploitation of software vulnerabilities. At the same time, the impact of a data breach can involve severe and far‑reaching consequences.
Organisations of all sizes, especially educational institutions, face risks such as data breaches, ransomware attacks, identity theft (phishing), and other forms of cyber incidents. Without clearly defined and well‑practiced procedures (policies) for managing such incidents, even minor security failures can lead to serious consequences — from financial losses and operational disruptions to damage to reputation and user trust.
This is why establishing procedures for managing cyber incidents is essential for timely detection, effective response, and limiting the damage. A well‑designed cyber incident management plan enables an organisation to respond more quickly, reduce negative impacts, and meet legal and regulatory requirements related to data security and protection.

Figure 6: Personal data breach security incident management
Background Colour
Font Face
Font Size
Text Colour
Font Kerning
Image Visibility
Letter Spacing
Line Height
Link Highlight