Home/Services/Data Breach Response
security service

Data Breach Response

Data breach response for European businesses: contain the incident, scope what was exposed, and meet the GDPR 72-hour notification deadline. 24/7.

Manual, expert-ledEvidence-based findingsFree remediation retest

If you have just found unauthorised access to your systems, a fast and evidence-led data breach response decides how much this costs you: contained early, scoped honestly, and notified correctly before the clock runs out. Our European incident team works with you and your legal counsel to establish what happened, what data was touched, and exactly what the regulator and your customers need to hear.

A breach is not a single event, it is a window of time. Someone had access they should not have had, and the questions that matter are how they got in, how long they were inside, and what they could reach while they were there. Guessing at those answers is how organisations either over-notify and cause needless alarm or under-notify and face a far larger penalty later. We answer them from the evidence.

What data breach response actually covers

Breach response is part forensics, part damage control, and part regulatory work against a deadline. The technical job is to stop the access, preserve what the logs still hold, and reconstruct the intruder’s path. The business job is to translate that into a defensible decision about who must be told. We do the first and give your decision-makers the facts they need for the second.

Emergency containment to cut off the attacker’s access without destroying evidence
Forensic scoping of which data categories and how many records were exposed
A clear finding on whether data was merely accessed or actually exfiltrated
A defensible timeline: entry point, dwell time, and what was reachable
Article 33 notification support with the technical facts your submission needs
Data-subject impact assessment to decide Article 34 communication
Evidence preserved to chain-of-custody standard for the supervisory authority

Our data breach response process, phase by phase

We run every engagement through the same sequence so nothing important gets skipped in the rush. Speed matters, but so does not trampling the evidence you will need to prove you handled the incident properly. The two goals are compatible when the work is done in order.

Triage

The first call is short and practical. We establish what you have seen, what systems are involved, whether the access appears to be ongoing, and what personal data those systems hold. From that we set an initial scope and decide what to preserve before anyone starts changing things. If the intrusion is live, containment and evidence capture happen almost together.

Establishing “awareness”

Under GDPR the 72-hour notification window starts when you become aware of a breach with reasonable certainty, not when the investigation finishes. Part of triage is fixing that moment honestly and documenting it, because the regulator will ask when you knew and what you did next.

Contain

Containment stops the bleeding: revoking the credentials or sessions in use, isolating affected hosts, closing the exposed service, and blocking the attacker’s route back in. We do this in a way that keeps memory, logs and disk artefacts intact. Pulling the plug on a server can wipe exactly the volatile evidence that tells you whether data left the building, so containment is deliberate, not panicked.

Eradicate

Once access is cut, we hunt for everything the intruder left behind. That means web shells, backdoor accounts, scheduled tasks, altered configuration, and any persistence that would let them walk back in after you think it is over. A breach is not resolved because you changed one password. It is resolved when the foothold and every copy of it is gone.

Recover

Recovery brings systems back to a known-good state and confirms they are clean before they return to production. Where data was altered or destroyed we work from verified backups. Where accounts were compromised we reset credentials and rebuild trust in your identity systems. Recovery is also when the notification work reaches its decisions, because by now the scope is understood.

Harden

The last phase closes the door that let this happen. If a stolen password got in, that points at multi-factor authentication and password policy. If an unpatched service was the way in, it points at patch cadence and exposure management. We give you a prioritised remediation list tied to the specific failure, not a generic checklist.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

How they got in, and whether data actually left

Two findings drive everything else: the entry vector and the exfiltration question. Most breaches we investigate trace back to a small set of causes, and confirming which one applies tells you both how to close it and how far the exposure spread.

Finding the entry vector

Common routes are stolen or reused credentials, an exposed and unpatched service, a phishing email that handed over a session, a misconfigured cloud bucket or database left open, and a vulnerable web application. We work from authentication logs, web server logs, cloud audit trails and endpoint telemetry to place the first unauthorised action and trace it forward.

Accessed versus exfiltrated

This distinction changes the risk assessment completely. Being able to read a database is not the same as having copied it out, and the notification decision often turns on which one you can prove. We look for egress evidence: large outbound transfers, staging of data into archives, connections to unusual destinations, and query patterns that look like bulk extraction. Where the logs are silent we say so plainly rather than assuming the best case.

When the evidence is incomplete

Sometimes retention was too short and the answer is genuinely unknowable from what remains. That itself is a finding. A regulator would rather see an honest “we cannot rule out exfiltration because logging did not cover this” than a confident claim the evidence does not support. We help you position that correctly.

GDPR breach notification: the 72-hour duty

For any organisation handling the personal data of people in Europe, the notification rules are the sharpest part of a breach. SafetyBis is not a law firm, and we work alongside your data protection officer and legal counsel. What we provide is the technical ground truth their decisions rest on, delivered fast enough to act on.

Article 33: notifying the supervisory authority

Article 33 requires notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. The clock is short and it does not pause for weekends. Getting scoping under way in the first hours is what makes a timely, accurate submission possible.

What the notification has to contain

The submission describes the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed to address it. Where you cannot provide everything at once, the regulation allows information in phases. We supply the categories, record estimates and remediation facts so your DPO can complete the form with confidence.

Article 34: telling the affected people

Where a breach is likely to result in a high risk to individuals, Article 34 requires you to communicate it to them without undue delay, in clear language, with advice on how to protect themselves. The risk assessment behind that decision draws directly on the forensic scope: what data, how sensitive, how many people, and whether it was exposed to a party likely to misuse it. We give you the inputs; your counsel makes the call.

Documenting even the breaches you do not report

Article 33(5) requires you to document every personal data breach, including the facts, its effects and the remedial action, whether or not it was notifiable. Our report is written to serve that record. If the authority ever asks why you decided a breach was not reportable, you have a dated, evidence-based rationale on file instead of a memory.

24/7
emergency response, any hour
72h
the GDPR clock we help you beat
100%
findings from evidence, not assumption

What you receive

You get more than a verbal all-clear. The deliverable is written to stand up to a regulator, a board and an insurer at the same time.

The incident report

An executive summary in plain language and a technical body with the timeline, the entry vector, the affected data, the exfiltration finding, and the evidence behind each conclusion. Every claim is traceable to a log line or artefact, so nothing rests on our word alone.

Notification-ready facts

A structured breakdown of data categories, approximate record and data-subject counts, and the remediation status, mapped to what Article 33 asks for. Your DPO can lift this straight into the submission.

Remediation plan and free retest

A prioritised list of fixes tied to the actual failure, and a free retest once you have applied them so you can show the hole is genuinely closed.

Pricing

Breach response is priced by urgency and scope: how many systems are involved, how much data is in play, and whether you need us on the clock immediately or on a standing arrangement. Here is the shape of a typical European engagement.

Package What’s included Response time Price
Rapid breach response Emergency triage, containment and forensic scoping for a single confirmed incident, with Article 33 notification facts Same day, 24/7 from €900
Forensic investigation (hourly) Deep-dive analysis where scope is uncertain: log reconstruction, exfiltration analysis, timeline building Started within hours from €180/hr
Single-system compromise repair Clean-up and recovery of one compromised server or site after the forensic scope is agreed 1–3 working days from €450
Incident response retainer Pre-agreed SLA, a team who already knows your environment, discounted hourly and priority activation Guaranteed by SLA from €800/month
Breach readiness & DR planning Response plan, notification playbook and recovery testing built before an incident Scheduled from €1,200
Custom / large breach Multi-system incidents, cloud estates or regulated environments, scoped to your situation On scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Start emergency response

FAQ

Do we have to notify under GDPR, and when do the 72 hours start?
If the breach is likely to risk people’s rights, yes, and the 72-hour Article 33 clock starts when you become aware of it with reasonable certainty, not when the investigation ends. We help you fix that moment honestly and get the scoping facts ready in time to submit.
How do you tell if data was actually stolen or just accessed?
We look for egress evidence: bulk outbound transfers, data staged into archives, connections to unfamiliar destinations, and query patterns that look like extraction. Where retention is too short to prove either way, we say that clearly, because “cannot be ruled out” is itself a finding a regulator will accept.
How did the breach happen in the first place?
Most cases trace to stolen or reused credentials, an exposed unpatched service, a phishing session, or a misconfigured cloud store. We reconstruct the entry point from authentication, web and cloud logs so you close the exact door, not a guessed one.
How much do data breach response services cost?
Rapid response starts from €900 for a single confirmed incident, with deeper forensic work from €180 per hour. You get a fixed quote after a free scoping call, and many organisations move onto a retainer from €800 a month so the price and the response time are agreed before the next incident.
Will you talk to the regulator for us?
We are not a law firm, so the submission is made by you, your data protection officer or your counsel. We supply the technical facts the notification requires and can join calls to explain the forensic findings directly. Many clients use us as the bridge between their legal team and the evidence.
Do we have to notify affected customers?
Only where the breach is likely to result in a high risk to them, under Article 34. That assessment depends on what data was exposed and how sensitive it is, which is exactly what the forensic scope establishes. We give your counsel the inputs to make and defend that decision.
What do we get to prove we handled it properly?
A written report with an evidence-backed timeline, the affected-data breakdown mapped to Article 33, and a remediation plan. It doubles as your Article 33(5) record, so if the authority ever asks, you have a dated, defensible account instead of recollection.
Can you also help us prevent the next one?
Yes. Every engagement ends with a prioritised hardening plan tied to the real failure, and a free retest once you have applied the fixes. Data breach response best practices are as much about closing the gap as cleaning up the incident.

Related services

Who needs this

Any European organisation that has just discovered unauthorised access, exposed personal data, or a suspected leak and needs the incident contained, scoped and its GDPR notification duties handled correctly against the 72-hour deadline.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Data Breach Response"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.