Telappliant
Cyber Security Guide · 15 August 2026

What to do if your data has been compromised

A calm, ordered response for individuals and businesses, including UK reporting duties and the 72-hour rule.

By the Telappliant team

A person checking accounts on a laptop and phone after a data breach

The hours after a breach are where most of the damage is either contained or multiplied. Work through this in order rather than trying to do everything at once.

First hour: contain

  • Reset the password on the affected account and anywhere the password was reused
  • Revoke active sessions and application tokens, not just the password
  • Check and remove mailbox rules, forwarding addresses and added MFA methods
  • Isolate an affected device from the network rather than wiping it
  • Preserve logs; do not tidy up before anyone has looked

First day: assess

Establish what was accessed, when, and by whom. For a business this means sign-in logs, mailbox audit logs, file access records and endpoint telemetry. Decide whether personal data was involved, whose, and how sensitive it is, because that determines your legal duties.

UK reporting duties

Under UK GDPR a personal data breach that poses a risk to individuals must be reported to the ICO within 72 hours of becoming aware of it. Where the risk is high, affected individuals must be told without undue delay. Financial services firms have separate FCA obligations, and Action Fraud should be notified where a crime has occurred.

If it is your own personal data

  • Change the password and enable MFA on the affected service
  • Change the same password anywhere else you used it
  • Watch bank and card statements, and consider a credit reference check
  • Expect targeted phishing that references real details, and slow down on anything urgent
  • Never act on a call claiming to be your bank; hang up and dial the number on your card

Recover and prove it

Restore from a known-good backup, rebuild rather than clean where malware is involved, rotate credentials and API keys broadly, and confirm the entry route is closed before you reconnect anything.

Afterwards

Write the timeline while it is fresh, record what you changed, and fix the control that failed. Insurers, regulators and customers all ask the same question: what is different now?

Next steps

Frequently asked questions

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a UK technology partner

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
UK business team reviewing plans together before a consultation
Call us Book consultation