If you are in an active incident right now

Skip the reading. Disconnect affected systems from the network (do not wipe or reboot them), and get incident help immediately — our breach response line or your own security provider. Every hour of delay widens the damage and shortens your legal runway.

Hour 0–4: Contain, Don't Destroy

Hour 4–24: Assess Scope

Hour 24–72: Notify — It's the Law

Under Section 22 of POPIA, a responsible party must notify the Information Regulator and affected data subjects "as soon as reasonably possible" after discovering a compromise of personal information — and the Cybercrimes Act adds a 72-hour reporting duty to the SAPS for qualifying offences. In practice: work to 72 hours as your outer limit, and document why if you need longer.

After the Fire: The Part Everyone Skips

The businesses that get breached twice are the ones that patched the symptom and skipped the post-incident review. Close the actual entry point, rotate every credential that could have been exposed, verify your backups actually restore, and write down what changed — that document is gold in any future vetting, insurance, or tender process.

Live Threat Maps & Intelligence Worth Bookmarking

These are the public, real-time platforms security teams actually keep open. They're also the fastest way to make cyber risk feel real to a board or a business partner:

The uncomfortable truth: a 72-hour response is only achievable if the plan existed before the breach. Incident contacts, isolation steps, notification templates, and tested backups are decided calmly in advance or chaotically at 2am. Our Data Breach Response service builds the plan — and answers the 2am call if it's ever needed.

Get a response plan before you need one.

Breach response planning is included in our cybersecurity assessments — containment steps, notification templates, and tested recovery.

Related Reading