First six hours: containment and evidence preservation

Immediately disconnect compromised servers, accounts or devices from the network. Do not power them down; the attacker’s traces remain in RAM. Change access passwords and tokens for all administrators and service accounts that may have been stolen. Enable detailed logging on the firewall, VPN and mail server. In the Czech context a breach often occurs through a vulnerable web application of an external supplier. In that case ask the supplier for immediate closure and handover of access logs.

Hours six to twelve: scope and risk assessment

Assemble the incident team: IT security, legal counsel, the Data Protection Officer if you have one, and management. Determine what data leaked, personal data, health information, payment cards, trade secrets, and how many data subjects are affected. Under the GDPR you assess the risk to the rights and freedoms of natural persons. Identifiers linked to a personal identification number (Czech national ID number) or health status require both notification to the authority and information to the individuals. If the breach involves ransomware, verify whether you have working backups and whether data was exfiltrated before encryption.

Hours twelve to twenty-four: mandatory notification and communication

If a risk to individuals exists, notify the Office for Personal Data Protection (ÚOOÚ), the Czech data protection authority, within 72 hours of discovery, not from the time of the attack. The notification must contain a description of the nature of the breach, categories of data and subjects, likely consequences and remedial measures. At the same time prepare a text for affected persons: what happened, what data, what you are doing, what they should do (change passwords, monitor accounts, enable two-factor authentication). CIAD audits show that companies with pre-prepared templates cut their response time by a full day.

Subsequent days: documentation and remediation

Keeping an incident register is mandatory even for breaches that are not reported to the authority. Store the timeline of steps, screenshots of logs, decisions on whether to notify and communications with suppliers. Carry out a forensic analysis, internally or by an external firm, to find the root cause. This is often an unpatched vulnerability, phishing or misconfigured cloud permissions. Deployment of measures (patches, network segmentation, multi-factor authentication, encryption at rest) must follow before systems return to production.

What this means

The first day decides whether an incident remains a controlled crisis or becomes a wide-ranging scandal with fines. Clear roles, prepared templates and a rehearsed procedure are the only guarantee that you will meet GDPR obligations and protect both people and the organisation.

Frequently asked questions

Must we report a breach even if only email and name leaked without a password?

Yes, if there is a risk of phishing or identity theft, reporting is mandatory. The ÚOOÚ assesses context, not just the type of data.

What if we don't have a DPO (data protection officer)?

Responsibility lies with the data controller (company). You can hire an external advisor, but deadlines and obligations will not lapse for you.

Can we restart the server after a breach to speed up operations?

No. A restart will erase the attacker's memory traces. First create a forensic image of the disk and memory, only then restore from backups.

How quickly must we inform affected individuals?

Without undue delay after reporting to the authority, ideally within a few days. The text must be understandable, without technical jargon, and with concrete steps for protection.

Does the 72-hour deadline apply on weekends or holidays too?

Yes, the deadline runs in calendar days. If you discover the breach on Friday evening, you have until Monday evening.