No small business expects to experience a data breach. They prepare a barebones “plan” which proceeds to sit quietly in a drawer, falling further and further out of date. And then one day, a breach actually occurs. The business, caught completely off-guard, flounders.
This ugly scenario can be prevented. But in order to do so you’ll need a thorough understanding of why data breach response plans are so crucial, and how to build one that will make a real difference when that fabled worst-case becomes reality. That’s the knowledge this article will arm you with.
What is a Data Breach?
First, a brief reminder of the danger your business faces. A data breach is when sensitive information or systems are accessed by an unauthorised third party. This can include:
- A ransomware attack that encrypts or exposes client records
- An employee emailing sensitive files to the wrong recipient
- A lost or stolen device containing unencrypted personal information
- Unauthorised access to your systems through compromised credentials
- A third-party vendor suffering a breach that affects data they hold on your behalf
Data breaches can have devastating consequences. Hours of downtime, financial losses, data loss, and reputational damage can all ensue. You could even be on the hook for legal issues.
Debunking the “It Won’t Happen to Me” Myth
Too many small businesses make the mistake of assuming they will never experience a data breach. The reality is much more frightening. Breaches occur almost every day, with the average cost reaching 4.99 million USD in 2026.
Historically, small businesses in Australia relied on their size to save them, assuming that large enterprises were more likely to become a target. Unfortunately, this is no longer the case. Today’s small businesses collect more than enough sensitive data to make them a valuable target, and to make matters worse, their security measures often haven’t kept pace. You can no longer assume a breach won’t happen.
Your Legal Obligations: The Notifiable Data Breaches Scheme
There is one more important topic to touch upon before moving on: your legal obligations in the event of a breach. In an effort to clamp down on the rising threat of cyber-attacks, the Australian government made the Notifiable Data Breaches (NDB) Scheme mandatory in 2018.
In short, the scheme requires that all eligible data breaches must be reported to the Office of the Australian Information Commissioner (OAIC), as well as any affected individuals. A breach is considered “eligible” if:
- Your business is subject to the Privacy Act (1998)
- Personal information of individuals has been stolen or lost
- The breach is likely to cause harm to said individuals
Failure to report an eligible breach can result in severe penalties. It’s important to keep the NDB Scheme in mind as you build your data breach recovery plan.
The Step-by-Step Data Breach Response Plan Template
If you’re developing a data breach response plan for the very first time, this template will help ensure that all the basic building blocks are in place.
Step 1: Contain the Breach
Your first priority when a breach occurs is containment. The longer you wait, the worse the situation will get. Depending on the nature of the breach, containment measures might include:
- Isolating affected systems from the network to prevent further spread
- Disabling compromised user accounts or resetting credentials
- Revoking third-party access that may have been involved
- Recovering or remotely wiping lost or stolen devices
Be sure to document any important evidence of the breach before completing actions that might erase it.
Step 2: Assess the Scope and Severity
Once you have ensured that the breach can’t spread any further, your next step is to determine how much damage has already been done. Conduct a structured audit to establish:
- What information was involved (categories, sensitivity, and volume)
- Whose information was affected (individuals, clients, employees, or third parties)
- How the breach occurred (the root cause and any contributing factors)
- Whether the breach is ongoing or has been contained
- Whether the breach is likely to cause serious harm to affected individuals
Step 3: Notify the Relevant Parties
Report the breach to all relevant parties in the following order:
- Internal: Ensure leadership and relevant staff are informed promptly so decisions can be made at the appropriate level.
- Legal and Insurance: Engage legal counsel and notify your cyber insurer early.
- OAIC (If Breach is Eligible): Submit a notification to the Office of the Australian Information Commissioner using the prescribed form, as quickly as practicable.
- Affected Individuals: Notify the people whose information was involved, providing a clear description of the breach, what information was affected, and what steps have been taken.
Use clear, honest language, and provide a way for individuals to contact you if needed.
Step 4: Investigate and Document
While carrying out the notification process, conduct a thorough investigation to identify the cause of the breach. Your goal here is to understand what happened well enough that you can remove all traces of the threat and prevent similar incidents from occurring in the future.
As you perform the investigation, document everything. This serves two purposes: it provides the evidence needed for accurate remediation, supports any insurance claims you might need to make, and demonstrates due process to the authorities.
Step 5: Remediate and Recover
Now that you’ve collected all the information needed, it’s time to remove the threat and restore normal operations. Move slowly and systematically. If at any point you notice concerning signs that a threat may still be present, stop and go back to the beginning. When you are absolutely certain that your IT is safe, you may then restore data from your backups and begin returning to regular operations.
Step 6: Review and Update the Plan
After the dust has settled, conduct a post-incident review. Your focus this time is on improving and refining your data breach response plan. Questions to ask include:
- Was the breach response plan followed? If not, why not?
- Were the response timelines achievable? Where did delays occur?
- Was communication with affected individuals and regulators clear and timely?
- What changes to process, technology, or training would reduce the likelihood of recurrence?
Adjust the plan accordingly. Ideally, test and review your plan at least once per year, in addition to updating your data breach policy, to ensure that both remain relevant and effective.
An important note: the template provided here is only intended as a starting point. Depending on the unique circumstances your business operates within, you may need to make alterations.
Data Breaches Happen. Make Sure You’re Ready for Them.
You can’t guarantee that your business will never experience a data breach. But you can reduce the risk of serious harm if one does occur. Data breach readiness can be as simple as maintaining strong backups, understanding your legal obligations, and having a clear plan in mind. By doing these things, you can ensure your business survives the breach and comes out stronger on the other side.
Data protection is complicated. You don’t need to handle it alone. Our experts design tailored solutions that keep sensitive information secure and fully compliant with relevant regulations. Learn how we can protect your data today.
FAQs
A data breach response plan outlines how your business will minimise the impact of a data breach and restore normal operations afterwards.
You need a data breach management plan to ensure that your business and clients don’t experience more harm than absolutely necessary in the event of an incident. Depending on your industry, it may also be necessary to comply with your legal obligations.
The Notifiable Data Breach Scheme requires that the OAIC be notified of a breach if your business is covered by the Privacy Act and if the breach is likely to cause harm to individuals.
A data breach policy is related, but slightly different from a data breach response plan. The former is specifically your internal guidelines for how incidents should be handled, while the latter refers to your overall strategy.
If you experienced a data breach and aren’t sure what to do next, reach out to a managed service provider (MSP). They can offer guidance on next steps.