Data Breach Response
Data breach response for European businesses: contain the incident, scope what was exposed, and meet the GDPR 72-hour notification deadline. 24/7.
If you have just found unauthorised access to your systems, a fast and evidence-led data breach response decides how much this costs you: contained early, scoped honestly, and notified correctly before the clock runs out. Our European incident team works with you and your legal counsel to establish what happened, what data was touched, and exactly what the regulator and your customers need to hear.
A breach is not a single event, it is a window of time. Someone had access they should not have had, and the questions that matter are how they got in, how long they were inside, and what they could reach while they were there. Guessing at those answers is how organisations either over-notify and cause needless alarm or under-notify and face a far larger penalty later. We answer them from the evidence.
What data breach response actually covers
Breach response is part forensics, part damage control, and part regulatory work against a deadline. The technical job is to stop the access, preserve what the logs still hold, and reconstruct the intruder’s path. The business job is to translate that into a defensible decision about who must be told. We do the first and give your decision-makers the facts they need for the second.
Our data breach response process, phase by phase
We run every engagement through the same sequence so nothing important gets skipped in the rush. Speed matters, but so does not trampling the evidence you will need to prove you handled the incident properly. The two goals are compatible when the work is done in order.
Triage
The first call is short and practical. We establish what you have seen, what systems are involved, whether the access appears to be ongoing, and what personal data those systems hold. From that we set an initial scope and decide what to preserve before anyone starts changing things. If the intrusion is live, containment and evidence capture happen almost together.
Establishing “awareness”
Under GDPR the 72-hour notification window starts when you become aware of a breach with reasonable certainty, not when the investigation finishes. Part of triage is fixing that moment honestly and documenting it, because the regulator will ask when you knew and what you did next.
Contain
Containment stops the bleeding: revoking the credentials or sessions in use, isolating affected hosts, closing the exposed service, and blocking the attacker’s route back in. We do this in a way that keeps memory, logs and disk artefacts intact. Pulling the plug on a server can wipe exactly the volatile evidence that tells you whether data left the building, so containment is deliberate, not panicked.
Eradicate
Once access is cut, we hunt for everything the intruder left behind. That means web shells, backdoor accounts, scheduled tasks, altered configuration, and any persistence that would let them walk back in after you think it is over. A breach is not resolved because you changed one password. It is resolved when the foothold and every copy of it is gone.
Recover
Recovery brings systems back to a known-good state and confirms they are clean before they return to production. Where data was altered or destroyed we work from verified backups. Where accounts were compromised we reset credentials and rebuild trust in your identity systems. Recovery is also when the notification work reaches its decisions, because by now the scope is understood.
Harden
The last phase closes the door that let this happen. If a stolen password got in, that points at multi-factor authentication and password policy. If an unpatched service was the way in, it points at patch cadence and exposure management. We give you a prioritised remediation list tied to the specific failure, not a generic checklist.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
How they got in, and whether data actually left
Two findings drive everything else: the entry vector and the exfiltration question. Most breaches we investigate trace back to a small set of causes, and confirming which one applies tells you both how to close it and how far the exposure spread.
Finding the entry vector
Common routes are stolen or reused credentials, an exposed and unpatched service, a phishing email that handed over a session, a misconfigured cloud bucket or database left open, and a vulnerable web application. We work from authentication logs, web server logs, cloud audit trails and endpoint telemetry to place the first unauthorised action and trace it forward.
Accessed versus exfiltrated
This distinction changes the risk assessment completely. Being able to read a database is not the same as having copied it out, and the notification decision often turns on which one you can prove. We look for egress evidence: large outbound transfers, staging of data into archives, connections to unusual destinations, and query patterns that look like bulk extraction. Where the logs are silent we say so plainly rather than assuming the best case.
When the evidence is incomplete
Sometimes retention was too short and the answer is genuinely unknowable from what remains. That itself is a finding. A regulator would rather see an honest “we cannot rule out exfiltration because logging did not cover this” than a confident claim the evidence does not support. We help you position that correctly.
GDPR breach notification: the 72-hour duty
For any organisation handling the personal data of people in Europe, the notification rules are the sharpest part of a breach. SafetyBis is not a law firm, and we work alongside your data protection officer and legal counsel. What we provide is the technical ground truth their decisions rest on, delivered fast enough to act on.
Article 33: notifying the supervisory authority
Article 33 requires notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms. The clock is short and it does not pause for weekends. Getting scoping under way in the first hours is what makes a timely, accurate submission possible.
What the notification has to contain
The submission describes the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed to address it. Where you cannot provide everything at once, the regulation allows information in phases. We supply the categories, record estimates and remediation facts so your DPO can complete the form with confidence.
Article 34: telling the affected people
Where a breach is likely to result in a high risk to individuals, Article 34 requires you to communicate it to them without undue delay, in clear language, with advice on how to protect themselves. The risk assessment behind that decision draws directly on the forensic scope: what data, how sensitive, how many people, and whether it was exposed to a party likely to misuse it. We give you the inputs; your counsel makes the call.
Documenting even the breaches you do not report
Article 33(5) requires you to document every personal data breach, including the facts, its effects and the remedial action, whether or not it was notifiable. Our report is written to serve that record. If the authority ever asks why you decided a breach was not reportable, you have a dated, evidence-based rationale on file instead of a memory.
What you receive
You get more than a verbal all-clear. The deliverable is written to stand up to a regulator, a board and an insurer at the same time.
The incident report
An executive summary in plain language and a technical body with the timeline, the entry vector, the affected data, the exfiltration finding, and the evidence behind each conclusion. Every claim is traceable to a log line or artefact, so nothing rests on our word alone.
Notification-ready facts
A structured breakdown of data categories, approximate record and data-subject counts, and the remediation status, mapped to what Article 33 asks for. Your DPO can lift this straight into the submission.
Remediation plan and free retest
A prioritised list of fixes tied to the actual failure, and a free retest once you have applied them so you can show the hole is genuinely closed.
Pricing
Breach response is priced by urgency and scope: how many systems are involved, how much data is in play, and whether you need us on the clock immediately or on a standing arrangement. Here is the shape of a typical European engagement.
| Package | What’s included | Response time | Price |
|---|---|---|---|
| Rapid breach response | Emergency triage, containment and forensic scoping for a single confirmed incident, with Article 33 notification facts | Same day, 24/7 | from €900 |
| Forensic investigation (hourly) | Deep-dive analysis where scope is uncertain: log reconstruction, exfiltration analysis, timeline building | Started within hours | from €180/hr |
| Single-system compromise repair | Clean-up and recovery of one compromised server or site after the forensic scope is agreed | 1–3 working days | from €450 |
| Incident response retainer | Pre-agreed SLA, a team who already knows your environment, discounted hourly and priority activation | Guaranteed by SLA | from €800/month |
| Breach readiness & DR planning | Response plan, notification playbook and recovery testing built before an incident | Scheduled | from €1,200 |
| Custom / large breach | Multi-system incidents, cloud estates or regulated environments, scoped to your situation | On scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Start emergency response
FAQ
Do we have to notify under GDPR, and when do the 72 hours start?
How do you tell if data was actually stolen or just accessed?
How did the breach happen in the first place?
How much do data breach response services cost?
Will you talk to the regulator for us?
Do we have to notify affected customers?
What do we get to prove we handled it properly?
Can you also help us prevent the next one?
Related services
Any European organisation that has just discovered unauthorised access, exposed personal data, or a suspected leak and needs the incident contained, scoped and its GDPR notification duties handled correctly against the 72-hour deadline.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.