Ablaufskizze einer Breach-Response in fünf Stufen: Erkennung des Vorfalls, Eindämmung durch Trennen betroffener Systeme, forensische Untersuchung der Protokolldateien, Wiederherstellung aus Sicherungskopien und Schließen der Lücke, abschließend Meldung an Aufsichtsbehörde und Betroffene mit Abschlussbericht.

Breach Response

Breach response refers to the organized process a company follows after unauthorized parties have infiltrated its computer systems or stolen data. This includes stopping the attack, investigating the incident, legally mandated reporting, and notifying those affected.

When outsiders break into a company’s computer systems and copy, alter, or block data there, this is called a security incident. Breach response is everything the company does afterward. The English term “breach” means a break or intrusion, “response” means reaction. This is not a single action, but a defined sequence: stop the attack, contain the damage, find the cause, inform authorities and those affected, close the gap. Almost every larger company has a written plan for this, drawn up long before an actual emergency. Because in an emergency, hours count, and no one has time to think about responsibilities then.

What a poorly managed breach costs

The actual break-in is often not the most expensive part. What becomes costly is what happens afterward - or doesn’t happen. Anyone who leaves a security gap open for days gives attackers time to spread deeper into the network. Studies by major IT corporations have for years put the average cost of a data breach at several million euros per case.

On top of that comes legal pressure. In the European Union, the General Data Protection Regulation, or GDPR, applies. It requires that a company report a breach of personal data protection to the responsible supervisory authority within 72 hours. Anyone who misses this deadline or covers up the incident risks heavy fines. In the USA, separate reporting obligations apply depending on the state and industry, sometimes with even shorter deadlines.

The third cost factor is trust. Customers tend to forgive an attack more readily than a cover-up. A well-known negative example is the ride-hailing service Uber: after a data theft in 2016, the company paid the attackers hush money instead of reporting the incident. When this came to light years later, investigations followed along with a criminal case against the then chief security officer.

The phases from alert to final report

The process is largely standardized within the field. First comes detection: monitoring software, an alert employee, or a ransom note reveals the incident. Then follows containment. Affected computers are disconnected from the network, passwords and access keys are revoked, suspicious accounts are locked.

Then a team investigates the traces. This work is called forensics and functions similarly to evidence collection after a break-in at a building. From log files, experts reconstruct when the attacker entered, what path they took, and which data they touched. It’s important not to overwrite anything in the process. Anyone who cleans up too quickly destroys the evidence they will later need for authorities and insurance.

Only afterward come restoration and communication. Systems are rebuilt from verified backup copies, the exploited gap is closed. In parallel, reports go to authorities and, if there is a high risk, to the affected individuals. In the end, a final report is produced addressing what needs to go better next time.

Breach response in headlines and in AI systems

In business news, the term usually appears in a certain phrasing: a corporation confirms an incident and states that it has “brought in external security experts.” This is breach response in progress. Specialized service providers and cyber insurers make their living from exactly this business. Common triggers are ransomware - malicious software that encrypts data and demands a ransom - as well as stolen employee credentials.

AI providers are affected too, sometimes with new kinds of problems. Chat histories with a language model often contain very personal or business-related information. In 2023, due to a software bug, ChatGPT users could briefly see conversation titles from other users' accounts. The provider shut down the service, fixed the bug, and notified those affected. This exact pattern is the core of every breach response.

A common misconception is that breach response is purely technical. In reality, legal counsel, the press office, and executive management are involved from the very beginning. And the term should not be confused with prevention: firewalls and password rules are meant to prevent the breach. Breach response begins the moment that has failed.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.