LinkedInInstagramXTikTok

Building a cyber incident response plan: legal duties every business should know

Why a plan beats improvisation

A serious cyber incident is not the moment to work out who to call, what the law requires or where the backups are. Yet many businesses discover a ransomware note or a data leak with no plan in place, and lose critical hours to confusion. A cyber incident response plan converts a chaotic emergency into a sequence of decisions you have already rehearsed – and it is increasingly a legal expectation, not just good practice.

This guide sets out the legal drivers behind incident response and the practical elements every plan should contain, whether you are a small company or a regulated operator.

The legal drivers behind incident response

The GDPR’s 72-hour clock

If personal data is breached, the GDPR requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. Where the risk to those individuals is high, they must be told too. Meeting that clock is impossible without a plan that tells you how to assess and escalate fast.

NIS2 and sector rules

For essential and important entities within its scope, the NIS2 Directive requires risk-management measures and layered incident reporting, including an early warning within 24 hours of a significant incident. Financial firms face parallel obligations under DORA. Even outside these regimes, contractual security commitments to customers often impose their own notification timelines.

The general duty of security

Article 32 of the GDPR requires appropriate technical and organisational measures, and the ability to restore availability and access after an incident. A tested response plan is part of how you demonstrate that you have met this standard.

What a good plan contains

A workable plan defines the phases of response and assigns clear ownership for each. It should cover preparation, detection and analysis, containment, eradication and recovery, and a post-incident review. Crucially, it names people and deputies, lists contact details for authorities, insurers, external forensics and legal counsel, and sets decision thresholds – who can authorise taking systems offline, and who signs off a regulatory notification.

It should also include ready-to-use templates: a breach assessment form, a regulator notification draft, and holding statements for staff, customers and, if needed, the public. Under pressure, filling in a template beats writing from scratch.

Praktiskt exempel

A mid-sized Swedish e-commerce company detects unusual data transfers late on a Friday. Because it has a plan, the on-call lead isolates the affected server, the pre-named response team convenes, and within hours they have assessed that customer contact details were exposed. The 72-hour assessment is already under way, the supervisory authority notification template is being completed, and a customer holding statement is ready. The same incident without a plan would likely have blown the deadline and amplified the damage.

Vanliga misstag som företag gör

The most common is having a plan on paper that no one has ever tested; the first real run reveals gaps that a tabletop exercise would have caught. Others store the plan only on systems that an attacker may have encrypted, keep contact lists that are out of date, or fail to define who has authority to decide. Many also forget to involve legal early, which matters for preserving privilege and getting notifications right.

Rekommenderade åtgärder

Write a concise plan mapped to your real systems and obligations, and keep an offline copy. Assign named roles with deputies and rehearse the plan at least annually with a tabletop exercise. Pre-agree external forensics, legal and PR support so you are not negotiating contracts mid-crisis. Prepare notification and communication templates in advance, and check that your logging is good enough to reconstruct what happened. Finally, review and update after every incident and every significant system change.

Vanliga frågor

Do small companies really need a written plan?

Yes. The GDPR duties apply regardless of size, and small teams have less slack to absorb a crisis. A short, practical plan is enough – it does not need to be a hundred pages.

Should we pay a ransom?

Paying carries legal, sanctions and practical risks and offers no guarantee of recovery. It is a decision to take with legal counsel and authorities, and your plan should flag it as such rather than assume payment.

When does the 72-hour clock start?

From when you become aware of a personal-data breach with reasonable certainty, not from when the attack began. Your plan should define how awareness is established and escalated.

Slutsats

Cyber incidents are now a question of when, not if, and the law increasingly judges companies on how they respond. A clear, tested incident response plan lets you meet tight notification deadlines, contain damage and show regulators that you took security seriously. Lawgent helps businesses build incident response plans that map directly to their GDPR, NIS2 and contractual duties – so that when the worst happens, you act instead of freeze.

0Varukorg0,00 

Inga produkter i varukorgen.

Gå tillbaka till butiken