"The average time to identify a data breach is 194 days. For small businesses, by then — the damage is already done."
No matter how careful your business is, the possibility of a data breach is a risk every organization faces. Understanding what constitutes a breach, what your obligations are, and how to respond quickly can mean the difference between a manageable incident and a business-threatening crisis.
What counts as a data breach?
A data breach is any incident where sensitive, protected, or confidential information is accessed, disclosed, or stolen without authorization. This includes:
- Customer credit card or payment data
- Employee Social Security numbers or personal records
- Protected health information (PHI) under HIPAA
- Login credentials and passwords
- Confidential business or client information
Importantly, a breach doesn't require a hacker. A lost laptop, a misdirected email, or an employee accidentally sharing a file publicly all qualify.
Your legal obligations
Most U.S. states mandate notification of affected individuals within 30–72 hours of discovering a breach. Federal regulations add further requirements depending on your industry:
HIPAA → Healthcare data: notify within 60 days PCI DSS → Payment card data: notify card brands immediately GLBA → Financial data: notify customers promptly State laws → 50 different state timelines (many: 30–72 hours) GDPR → EU customer data: notify within 72 hours
The first 24 hours — your action plan
- Contain - disconnect affected systems from the network. Do not delete anything.
- Document - write down everything you know: what was accessed, when, by whom.
- Notify your IT/security provider - they need to preserve evidence and assess scope.
- Call your cyber insurance carrier - they often provide breach response services.
- Preserve logs - firewall, email, authentication, and system logs are critical evidence.
Build your response plan now
The worst time to figure out your response plan is during an active breach. Even a one-page incident response document dramatically improves outcomes:
- Who to call first (IT provider, insurance, legal)
- How to identify what data was exposed
- Which regulations apply to your business
- Communication templates for customer notifications
- A list of credentials that need immediate rotation
★ Don't wait: Build your incident response checklist this week—before you need it. A single hour of preparation now could save your business during a crisis.
