QUICK DEFINITION
Data Breach Response: The emergency technical procedures executed immediately after a cyber attack or data leak.
Best for: Any organisation facing — or preparing for — a live security incident.
The clock: POPIA requires qualifying breaches to be reported to the Information Regulator without undue delay.
What Data Breach Response Includes
Breach response is what happens in the hours that decide how bad an incident becomes: containment, evidence, and the legally required notifications. We help you isolate affected systems without destroying the evidence, work out what data was actually accessed, and meet your obligations to the Information Regulator and affected people under POPIA and the Cybercrimes Act — where every hour of delay widens the damage and shortens your legal runway.
- Rapid containment guidance — how to stop the spread without wiping the forensic trail you will need later.
- A clear scope of what was accessed, so your notifications are accurate rather than guesswork.
- Support meeting the POPIA breach-notification duty to the Information Regulator and affected data subjects.
Why the First 72 Hours Decide Everything
A breach handled well is a bad week; a breach handled badly is an existential event. The difference is almost always the plan that existed beforehand and the speed of the first response. Under POPIA you must notify the Information Regulator and affected people as soon as reasonably possible, and hiding a breach that later surfaces is worse — legally and reputationally — than the breach itself.
How We Respond
If you are in a live incident, the priority is to contain and preserve — then assess and notify. We help you work the sequence calmly and defensibly, and document the timeline that your insurer, your lawyers and the Regulator will all ask for. Even better, we build the response plan in advance, so the 2am call is a procedure, not a panic.
Common Questions
We think we are being attacked right now — what do we do first?
Disconnect affected machines from the network but do not wipe or reboot them, change critical passwords from a clean device, and get incident help immediately. Preserving evidence and containing spread come before clean-up.
Do we legally have to report a breach in South Africa?
Yes. POPIA requires notification of the Information Regulator and affected data subjects as soon as reasonably possible, and the Cybercrimes Act adds reporting duties for qualifying offences. We help you meet both correctly.
Should we just pay the ransom to make it stop?
The authorities advise against it — payment funds the next attack and guarantees nothing. Tested, isolated backups and a proper response plan are what actually get you operating again.
Authorities & Trusted Sources
Verify the requirements yourself at source — then let us handle them. See our full Trusted Sources directory.