A brief guide to your legal and practical obligations following a cyber incident.
Once a cyber security incident has been resolved, formal reporting will often be required to both internal and external stakeholders. There are certain incidents that you're legally obliged to reportto the Information Commissioner's Office (ICO), regardless of whether your IT is outsourced. Check the ICO website to find out which incidents require this. Other regulatory bodies which you belong to may also require you to report a breach.
Report to law enforcement
Always remember that a cyber attack is a crime. Report to police via Report Fraud by calling 0300 123 2040 or through Police Scotland’s 101 call centre. The NCSC strongly encourage the reporting of a cyber incident; many go unreported because of personal embarrassment. However, if a cyber incident has been committed against you, someone else may have suffered a similar crime. The more individuals report, the more likely it is that perpetrators will be arrested, charged and convicted.
Keep everyone informed
It’s important to keep your staff and customers informed of anything that might affect them (for example, if their personal data has been compromised by a breach). Make staff aware of any incidents at a time that is proportionate to the effect of the incident. So, if you have experience a minor incident out of hours, is it proportionate to contact staff in the middle of the night? If relevant, contact your customers as soon as possible through the most appropriate channels.
Consider legal advice
You might want to consider seeking legal advice if the incident has had a significant impact on your business and/or customers. If you have a cyber insurance policy, they will be able to provide you with more advice.