· Vimal Hari · Cybersecurity & UK Compliance · 7 min read
UK SME Data Breach: First Hour & 72-Hour ICO Guide
A practical guide to the first hour after a data breach and the 72-hour ICO reporting deadline for UK SMEs.

TL;DR: If you suspect a data breach, isolate affected systems immediately, gather facts fast, and assess risk to individuals within hours, not days. The ICO must be told within 72 hours of you becoming aware, if there’s a risk to people’s rights and freedoms. Only 25% of UK SMEs have a plan for this moment — build yours before you need it.
Introduction
A UK small business data breach now costs more than embarrassment. It costs time you don’t have, decisions you’re not trained to make, and potentially a fine that could sink the company. In the 2025/2026 survey period, 43% of UK businesses — an estimated 612,000 organisations — reported a cyber breach or attack, according to PrivacyEngine’s UK cybersecurity statistics. For small businesses with 10-49 employees, that figure rises to 46%, and two-thirds of firms with 10-250 employees were hit in 2025.
The uncomfortable truth is that most owners will face this moment unprepared. Only a quarter of UK businesses have a formal incident response plan, which means the other three-quarters are making it up as they go, under pressure, with a legal clock already ticking. This guide is not a compliance lecture. It’s a decision-support tool for the person who has to act in the next 60 minutes and report within 72 hours — covering what to do, what it costs to get this right in advance, and how to judge whether your current setup is fit for purpose.
What Should a UK SME Do in the First Hour of a Data Breach?
In the first hour, your job is containment and fact-gathering, not full investigation. Disconnect affected systems from the network to stop the breach spreading — this is the single most time-sensitive action you can take. Next, establish what happened, what data is involved, and how many people are affected, even if the picture is incomplete.
Assess whether the breach is likely to risk individuals’ rights and freedoms; this determines whether you must notify the ICO at all. Document everything as you go, including timestamps, because you’ll need this record regardless of whether the breach turns out to be reportable. ComplyOne’s ICO breach notification guide confirms that the 72-hour clock starts from reasonable certainty a breach has occurred, not from the moment your investigation concludes.
What Does 72-Hour ICO Reporting Actually Require?
The 72-hour deadline is widely misunderstood. It doesn’t mean you need a complete forensic report within three days — it means you need to notify the ICO once you have reasonable certainty that personal data has been compromised and the breach poses a risk. Partial notifications are entirely acceptable, provided you follow up with detail as your investigation develops.
Lunyb’s guide to reporting a data breach to the ICO sets out what the initial notification needs to cover: a description of the breach, the likely consequences, the categories and approximate number of individuals affected, and the measures taken or proposed to address it. If you genuinely cannot provide all of this within 72 hours, say so and commit to a timeline for the rest.
Here’s the framework most SMEs get wrong:
| Situation | Action required | Timeframe |
|---|---|---|
| Breach with risk to individuals | Notify ICO | Within 72 hours of awareness |
| Breach with high risk to individuals | Notify ICO AND affected individuals | Without undue delay |
| Breach with no meaningful risk | Document internally, no notification needed | Ongoing record-keeping |
| Uncertain risk level | Notify ICO to be safe, update as facts emerge | Within 72 hours |
Pro tip: When in doubt about risk level, notify. A late or absent report is far more damaging than an early, partial one that gets updated later.
The consequence of getting this wrong is severe. Jerait’s guidance on failure to notify the ICO notes that penalties can reach £17.5 million or 4% of annual global turnover, on top of reputational fallout that often outlasts the fine itself.
What Does a Proper Incident Response Plan Cost — and What Do Good Providers Look Like?
Most SMEs assume incident response planning is expensive specialist consultancy. In reality, the NCSC’s small business guidance recommends something far simpler: a document covering who to contact, your IT provider’s details, where backups are stored, and a clear escalation path. This can be drafted in-house for the cost of a few hours’ time, or built into a managed IT support contract at little additional cost if your provider already handles your infrastructure.
Where costs rise is in ongoing monitoring, breach detection tooling, and having a provider on retainer who can act within the first hour rather than the first working day. This is the difference between a plan that exists on paper and one that actually gets executed at 11pm on a Friday. Many UK SMEs bundle this into broader managed security and compliance support, which covers monitoring, incident response, and ongoing GDPR alignment under one arrangement rather than as a one-off emergency callout.
When comparing providers, ask these questions directly:
- Do you provide 24/7 incident response, or only during business hours?
- What is your guaranteed response time once a breach is reported?
- Will you help draft the ICO notification, or only fix the technical issue?
- How do you handle evidence preservation and documentation for non-reportable breaches?
- What’s included in your retainer versus billed as an emergency callout?
When you should NOT buy a full incident response retainer: if you’re a two-person business with no customer personal data beyond basic invoicing, a simple documented plan and a good relationship with your existing IT support may be sufficient. Don’t let a provider sell you enterprise-grade monitoring for a business that genuinely has minimal exposure. Match spend to actual risk, not fear.
What This Means for Cybersecurity & UK Compliance in 2026
The direction of travel is clear: attack volumes are rising, phishing remains the dominant threat method — affecting 38% of UK businesses and rated most disruptive by 69% of those breached, per PrivacyEngine’s 2026 statistics — and regulatory scrutiny isn’t softening. SMEs that treat incident response as a one-off document rather than a live capability will keep losing the first-hour race. Businesses growing across the Thames Valley, including those investing in website development in Staines-upon-Thames, are increasingly folding breach readiness into their digital projects from day one rather than bolting it on afterwards.
Expect more SMEs to formalise plans in 2026, partly driven by insurer requirements and partly by client due diligence questionnaires that now routinely ask about incident response maturity. The businesses that get ahead of this will find compliance cheaper and calmer than those reacting under fine-driven pressure.
Key Takeaways
- Contain first, investigate second — disconnect affected systems within minutes, not hours.
- The 72-hour ICO clock starts at reasonable certainty of a breach, not full investigation completion; partial notifications are acceptable.
- Document every incident, even non-reportable ones — the ICO can ask for records later.
- Match your incident response spend to genuine risk; not every SME needs 24/7 monitoring.
- Ask providers about guaranteed response times and whether ICO notification support is included, not just technical remediation.
Conclusion
A data breach is not a hypothetical for UK SMEs — it’s a near-certainty over a long enough timeline, given that 43% of businesses were hit in the last survey period alone. What separates a manageable incident from a business-ending one is preparation: a simple written plan, a provider who can act within the first hour, and clarity on what the 72-hour ICO deadline actually demands. If your current setup leaves these questions unanswered, it’s worth scoping managed security and compliance support before the next attempt lands, not after.



