What Should a Company Do After a Data Breach?
July 9, 2024
Last Modified On: August 6, 2026
The first thing to do after a data breach is contain it, then assess whether the law requires you to notify the National Privacy Commission (NPC) within 72 hours.
Under the Philippines’ Data Privacy Act (RA 10173), you must notify both the NPC and affected individuals within that window whenever a breach involves sensitive personal information and creates a real risk of serious harm.
Because the clock starts the moment you have reasonable belief a breach occurred, not once you’ve confirmed every detail, speed matters more than certainty in those first hours.
What is a data breach?
A data breach happens when someone accesses, discloses, or uses protected data without authorization. It’s worth distinguishing three related terms, since companies often use them loosely:
| Term | What It Means |
|---|---|
| Cyber attack | Any deliberate attempt to exploit systems, networks, or devices for malicious purposes |
| Data breach | A specific type of cyber attack where sensitive or confidential information is accessed, stolen, or exposed |
| Push bombing | A flood of unsolicited messages meant to overwhelm systems or distract security teams, often used alongside a breach attempt |
Is your company legally required to report It?
In the Philippines, the answer depends on what was exposed. According to IAPP’s summary of the Data Privacy Act and its implementing regulations, notification becomes mandatory once three conditions line up: the breach involves sensitive personal information or identity-fraud data, an unauthorized party has acquired it, and the exposure creates a real risk of serious harm.
When those conditions apply, you must notify the NPC and affected data subjects within 72 hours, then follow up with a full written report within five days.
Because delay is only excused while you’re actively determining the breach’s scope, waiting simply to avoid bad news is not a valid reason and can itself trigger penalties.
If you’d rather not manage that 72-hour clock alone, CloudConsole’s managed cybersecurity solutions include NPC-compliant breach response as part of ongoing coverage.
Are companies liable for data breaches?
Yes, companies can face liability, though it depends on the circumstances. According to Respicio & Co.’s overview of data privacy remedies, affected individuals can claim damages through civil action or NPC proceedings if they can show the breach caused them harm.
Consequently, transparency actually works in your favor here: notifying customers promptly and demonstrating that you took reasonable security measures both factor into how regulators and courts assess liability.
What a data breach actually costs
The financial case for acting fast is stronger than most companies assume. IBM’s 2025 Cost of a Data Breach Report puts the global average cost at $4.44 million, and organizations that contain a breach within 200 days spend $1.14 million less on average than those that take longer. In other words, the speed of your first response directly affects the final bill, not just your regulatory standing.
7 steps to take after a data breach
Once you confirm a breach, work through these steps in order:
1. Notify IT and legal immediately. Your IT team secures affected systems while legal assesses notification obligations and liability exposure.
2. Secure affected systems and data. Isolate compromised systems, restore from backups where needed, and tighten access controls to stop further exposure.
3. Communicate with customers and stakeholders. Give regular, honest updates on what happened and what you’re doing about it, since transparency protects trust even when the news is bad.
4. Contact law enforcement and the NPC if required. Report the breach within 72 hours if it meets the notification threshold above, and involve law enforcement for unlawful access.
5. Add security measures to prevent a repeat. Patch known vulnerabilities, roll out multi-factor authentication, and run a security audit to catch what let the breach happen.
6. Support affected individuals. Offer credit monitoring or identity-theft guidance so people know how to protect themselves.
7. Keep monitoring for further exposure. Watch for unusual logins or file activity for weeks after the initial incident, since attackers sometimes return through the same weakness.
Because many breaches trace back to gaps a routine security review would have caught, our guide on why computer system maintenance matters covers the preventive habits that reduce your odds of needing this checklist at all.
How CloudConsole Can Help
If your team lacks the bandwidth to manage incident response internally, the same managed cybersecurity solutions linked above also cover ongoing monitoring and threat response, so you’re not building a plan from scratch during an active incident.
For businesses weighing whether to build this capability in-house or bring in outside help, our guide to managed IT services covers that broader decision.
Frequently Asked Questions
What should a company do immediately after a data breach?
First, notify your IT and legal teams so they can secure affected systems and assess notification obligations. From there, work through containment, communication, and, if the breach meets the legal threshold, formal notification to regulators and affected individuals.
Is a company required to report a data breach to the NPC?
Yes, whenever the breach involves sensitive personal information or identity-fraud data, unauthorized acquisition occurred, and there’s a real risk of serious harm. In that case, the Data Privacy Act requires notification to both the NPC and affected data subjects within 72 hours.
How long do companies have to notify customers of a data breach in the Philippines?
Companies must notify affected data subjects within 72 hours of knowing, or reasonably believing, that a notifiable breach occurred, then submit a full written report to the NPC within five days.
What is the difference between a cyber attack and a data breach?
A cyber attack is any deliberate attempt to exploit a system, while a data breach is a specific outcome, unauthorized access to or exposure of sensitive data. Every data breach involves a cyber attack, but not every cyber attack results in a breach.
Can a company be held liable for a data breach?
Yes. Affected individuals can pursue damages through civil action or NPC proceedings if they can show the breach caused them harm, though prompt notification and reasonable security measures both factor into how liability gets assessed.