← All insights
Breach response18 April 2026·4 min read

72 hours: a tabletop script for your next personal data breach

A ready-to-run exercise that surfaces the decisions your incident playbook hasn't yet answered.

This script is designed to be run in ninety minutes with your incident response team, and it deliberately targets the decisions that most playbooks leave ambiguous. The scenario is deliberately mundane — most breaches are — because the value of the exercise is in the decision-making, not the drama.

Scenario: at 09:15 on a Tuesday, a support engineer discovers that a database export containing customer contact details and hashed passwords was uploaded to a public storage bucket eight days ago as part of a debugging exercise. The export contains approximately 42,000 records. Access logs show at least three downloads from IP addresses outside the organisation.

Phase one, the first hour. Convene the incident response team and confirm the facts. Who owns the initial triage decision? What does your playbook say about containment when the data is already public? Who has authority to take the affected system offline, and what is the business impact of doing so? Record the decisions and the times they were made. Most teams discover that their playbook names an on-call role but not a decision-maker.

Phase two, hours two to twelve. Assess the personal data involved and the risk to individuals. Hashed passwords — but hashed with what algorithm, and with what salt? Contact details — but combined with what other data that might already be circulating? The severity assessment drives every subsequent decision, and it must be documented. Who signs it off? Your DPO, your CISO, your General Counsel, or all three?

Phase three, hours twelve to seventy-two. The 72-hour clock for ICO notification is running from the point of awareness, not from the start of the incident. Draft the notification. What do you tell the ICO when you do not yet know the full impact? The ICO's own guidance is clear that initial notifications can be updated — but your playbook needs to name the person who signs the notification and the escalation path if they are unavailable.

Phase four, individual notification. Article 34 requires notification to affected individuals where there is a high risk to their rights and freedoms. Is this such a case? If yes, what channel do you use for 42,000 individuals, and what does the message say? If no, what is the documented rationale? The exercise reveals whether your communications team has draft templates, whether your customer support team is briefed, and whether your legal team has reviewed the language in advance.

Debrief. The output of the exercise is not a pass or fail — it is a list of playbook gaps to close. Common gaps: no named decision-maker for containment, no pre-approved notification templates, no escalation path when the DPO is unavailable, no clarity on who briefs the executive team, and no rehearsed process for coordinating with affected third parties. Close two of the top gaps within thirty days, and re-run the exercise in six months.

Companies we've supported

59AThe Compliance EngineersAikenCountry & Town HouseLightbulbGraffic JamSerenefounditAIMEaffiliate.ai59AThe Compliance EngineersAikenCountry & Town HouseLightbulbGraffic JamSerenefounditAIMEaffiliate.ai