Data Breach Response Guide: What Individuals and Small Businesses Should Do First
A data breach creates two urgent questions: what information was exposed, and what should happen next? The answer depends on whether you are the organization that experienced the breach or an individual whose information was exposed. A small business may need to contain systems, preserve evidence, investigate the scope and review notification obligations. An individual may need to change passwords, freeze credit, watch financial accounts or follow a recovery plan based on the type of information involved.

The worst response is usually panic followed by random action. Turning off every machine can destroy volatile evidence. Sending a vague public statement before the facts are known can mislead customers. Changing one password is not enough if the same password was reused elsewhere. A useful breach response is structured, documented and proportional to what was actually compromised.
This guide provides general defensive information based on current U.S. Federal Trade Commission resources. Legal notification duties vary by jurisdiction, industry and data type, so organizations should consult qualified legal counsel for requirements that apply to their specific incident.
First, Understand What “Data Breach” Means
A data breach is an incident in which information is accessed, exposed, stolen or disclosed without authorization. It can result from an external attacker, malicious insider, lost device, cloud-storage mistake, compromised vendor or simple publishing error.
Information commonly involved includes
- Email addresses and usernames.
- Passwords or password hashes.
- Names, addresses and phone numbers.
- Payment-card information.
- Bank details.
- Social Security numbers or government identifiers.
- Health information.
- Employee records.
- Customer contracts or private business information.
- Authentication tokens or API credentials.
The response should be based on the information type, how it was exposed and whether there is evidence it was actually accessed or misused.
For Businesses: Secure Operations and Stop Additional Loss
The FTC’s current Data Breach Response: A Guide for Business recommends moving quickly to secure systems, mobilize the breach-response team and stop additional data loss. The exact containment action depends on the incident.
Initial business actions
- Activate the incident-response team.
- Identify affected systems and accounts.
- Restrict or isolate compromised access where appropriate.
- Preserve evidence before destructive remediation.
- Engage forensic expertise when needed.
- Update credentials that may be compromised.
- Fix the vulnerability or exposure that caused the breach.
- Document every significant action and time.
If information was accidentally published on a website or cloud share, remove public access quickly while preserving enough evidence to understand what happened.
Do Not Destroy Evidence While Trying to Clean Up

A rushed recovery can erase logs, memory or system state that investigators need to determine how the breach happened. The FTC specifically advises businesses not to destroy forensic evidence during investigation and remediation.
Potential evidence sources
- Authentication logs.
- Cloud audit logs.
- Firewall and VPN records.
- Endpoint security alerts.
- Email-security logs.
- Database access records.
- Web-server logs.
- System images or memory captures where appropriate.
- Vendor alerts and notifications.
Small businesses without internal forensic capability should consider bringing in a qualified incident-response provider. Evidence collection is not the place to learn by experimentation on the only affected system.
Determine What Information Was Actually Compromised
Good breach response depends on scope. A database containing only public newsletter email addresses requires a different response from one containing passwords, bank information or Social Security numbers.
Build an exposure inventory
| Question | Why it matters |
|---|---|
| Which systems were accessed? | Defines technical scope |
| Which records were present? | Identifies potentially affected people |
| Was data encrypted? | May affect risk and legal analysis |
| Were credentials exposed? | May require resets and session revocation |
| Was data downloaded or only viewable? | Helps assess exposure |
| How long was access available? | Helps define the affected period |
| Which customers/employees are affected? | Drives communication and notification |
Do not claim “no data was stolen” simply because the business has not yet found proof of download. Use careful language that matches the evidence available.
Reset Credentials in the Right Order

If credentials or authentication tokens were compromised, removing malware or closing a vulnerable server is not enough. The attacker may still be able to log back in.
Prioritize high-impact credentials
- Identity-provider and domain administrators.
- Email administrators.
- Cloud and hosting accounts.
- Backup administrators.
- Database credentials.
- API keys and service tokens.
- VPN and remote-access accounts.
- Normal user credentials affected by the breach.
Reset credentials from clean trusted devices where possible and revoke existing sessions. If a password was reused across services, change it everywhere it was reused.
Our guides to multi-factor authentication and passkeys explain stronger authentication options for preventing credential reuse after recovery.
Investigate Vendors and Connected Systems
A breach may start with a third-party provider or move through integrations. If a compromised vendor account has access to your systems, the business should verify whether that access was abused and whether the vendor has fixed the problem.
The FTC’s Cybersecurity for Small Business guidance recommends limiting vendor access to what is needed and investigating whether a vendor breach provided unauthorized access to the business network.
Review
- OAuth and application integrations.
- Vendor administrator accounts.
- API tokens.
- Remote support tools.
- Shared file access.
- Contractor accounts.
- Data-processing vendors.
Disable unnecessary access until the scope is understood.
Legal and Notification Requirements Need Specific Review
The FTC notes that breach notification requirements vary. In the United States, states and territories have breach-notification laws, and sector-specific rules may also apply depending on the information involved.
Organizations should determine
- Which jurisdictions apply to affected individuals.
- What types of information trigger notification.
- Required timing.
- Required notice content.
- Whether regulators or law enforcement must be notified.
- Whether contractual customers or partners must be notified.
- Whether health, financial or other sector-specific rules apply.
This is an area for legal counsel. Do not copy another company’s breach letter and assume it satisfies your obligations.
Communicate Clearly Without Overstating the Facts

A breach notice should help affected people protect themselves. The FTC recommends clear communications that describe what is known, what information was involved, what the organization is doing and what people can do next.
Good communication principles
- Use plain language.
- State confirmed facts separately from ongoing investigation.
- Explain what information was affected.
- Explain what the organization has done to contain the issue.
- Provide a legitimate contact channel.
- Explain protective steps relevant to the exposed data.
- Warn customers about likely breach-themed phishing scams.
Attackers may impersonate the breached company afterward. Tell customers how official communications will look and avoid asking them to click unexpected login links.
For Individuals: Read the Breach Notice Carefully
If you receive a legitimate data-breach notice, identify exactly what information the company says was exposed. Do not assume that every breach requires the same response.
Examples
- Password exposed: change it and any reused versions immediately.
- Email address exposed: expect more targeted phishing.
- Payment card exposed: monitor transactions and follow card issuer guidance.
- Bank account information exposed: contact the financial institution and monitor activity.
- Social Security number exposed: consider credit freezes and monitor credit reports.
- Identity documents exposed: follow guidance appropriate to the document and jurisdiction.
The FTC directs consumers to IdentityTheft.gov guidance for lost or exposed information, which provides steps based on the information involved.
Change Exposed or Reused Passwords Quickly
If a breach included passwords or authentication data, change the affected password immediately. More importantly, change it anywhere else you reused the same or a similar password.
The FTC warns that attackers use breached passwords on other services. Unique passwords prevent one breach from becoming several account takeovers.
After changing the password
- Sign out of other active sessions.
- Enable MFA or a passkey if supported.
- Review recovery email and phone numbers.
- Check for unfamiliar devices.
- Review email forwarding rules on important accounts.
If your email account was compromised, secure it first because email is often used to reset passwords for other services.
Credit Freeze and Monitoring Are Different Tools

If sensitive identity information such as a Social Security number is exposed, a credit freeze can make it harder for someone to open new credit accounts in your name. Credit monitoring watches for changes but does not itself prevent new-account activity.
The FTC’s current credit guidance explains that credit freezes are free and remain until the consumer removes them. IdentityTheft.gov also provides breach-specific steps.
Consider
- Reviewing credit reports for unknown accounts.
- Placing a credit freeze if sensitive identity data was exposed.
- Using free monitoring offered by the breached organization when appropriate.
- Watching bank and card transactions independently of credit monitoring.
Credit monitoring cannot detect every type of identity misuse, so match the protective action to the information exposed.
Watch for Secondary Phishing After a Breach
Breaches create excellent material for scammers. A criminal can send a message that says, “We’re contacting you about the recent breach—click here to secure your account.” The message feels credible because the breach really happened.
Safer response
- Do not use links in unexpected breach messages.
- Go directly to the company’s official site or app.
- Verify phone numbers independently.
- Never provide one-time MFA codes to someone who contacts you.
- Be suspicious of requests to pay for “breach recovery.”
Our phishing defense article provides more detailed warning signs.
If Identity Theft Has Already Happened
If someone used your information to open an account, make a purchase, file for benefits or commit another form of identity theft, the response moves beyond preventive monitoring.
The FTC’s identity theft guidance directs consumers to IdentityTheft.gov, where they can report identity theft and receive a recovery plan with steps and forms.
Possible actions may include
- Reporting fraudulent accounts to the affected company.
- Disputing fraudulent credit information.
- Freezing credit.
- Reporting identity theft.
- Replacing compromised documents where appropriate.
- Keeping records of every communication.
The exact steps depend on what was misused.
Businesses Should Learn From the Breach, Not Just Reopen Systems
After operations are stable, conduct a post-incident review.
Ask
- How did the incident begin?
- Why did existing controls not stop it?
- How quickly was it detected?
- Were backups and logs useful?
- Were access rights too broad?
- Did vendors increase exposure?
- Were communications prepared?
- What will be measured to confirm remediation?
Update the incident-response plan, employee training and technical controls from evidence rather than simply buying another security product.
Data Breach Response Checklist for Small Businesses
| Phase | Key action |
|---|---|
| Contain | Stop additional unauthorized access |
| Preserve | Protect forensic evidence and logs |
| Investigate | Determine systems, data and people affected |
| Remediate | Fix vulnerabilities and compromised credentials |
| Legal review | Determine applicable notification duties |
| Communicate | Provide accurate useful information |
| Recover | Restore clean systems and monitor |
| Improve | Update controls and response plan |
Data Breach Checklist for Individuals
- Verify that the breach notice is legitimate.
- Identify exactly what information was exposed.
- Change exposed or reused passwords.
- Enable MFA/passkeys.
- Review account recovery settings.
- Monitor financial accounts.
- Review credit reports when identity data is involved.
- Freeze credit when appropriate.
- Expect breach-themed phishing.
- Use IdentityTheft.gov if information is misused.
Frequently Asked Questions
Does every data breach require a password change?
Not necessarily. If passwords or authentication credentials were not exposed, other actions may be more important. If a password was exposed—or reused on the affected service—change it promptly.
Should a business shut down every computer after a breach?
Not automatically. Containment is important, but destructive actions can remove evidence or disrupt unaffected systems. Follow an incident-response plan and coordinate with qualified forensic responders.
Does a credit freeze stop all identity theft?
No. It helps prevent new credit accounts from being opened in your name, but it does not stop misuse of existing bank accounts, medical information, tax identity or other exposed data.
How quickly must a business notify customers?
Requirements vary by jurisdiction, data type and industry. Businesses should obtain legal guidance and review applicable breach-notification laws rather than relying on a generic timeline.
Conclusion
A data breach response should begin with facts: what systems were affected, what information was exposed and whether the attacker still has access. Businesses should contain the incident, preserve evidence, reset compromised credentials, fix the root cause and review notification requirements with appropriate experts.
Individuals should focus on the information that was exposed. Change compromised passwords, strengthen important accounts, monitor financial activity and use credit freezes or IdentityTheft.gov guidance when sensitive identity information is involved. Both organizations and consumers should expect phishing after a public breach. A structured response cannot undo the exposure, but it can significantly reduce the chance that one incident creates a second wave of harm.
