Skip to main content
Guidance

Small Business Guide: Response & Recovery

Guidance that helps small to medium sized organisations prepare their response to and plan their recovery from a cyber incident.

Page 5 of 7

Step 4: Report the incident to wider stakeholders

A brief guide to your legal and practical obligations following a cyber incident.

Once a cyber security incident has been resolved, formal reporting will often be required to both internal and external stakeholders. There are certain incidents that you're legally obliged to report to the Information Commissioner's Office (ICO), regardless of whether your IT is outsourced. Check the ICO website to find out which incidents require this.  Other regulatory bodies which you belong to may also require you to report a breach. 




Published

Reviewed

Version

1.0