Data breach response plan 

For FRIAM Limited trading as Practical Leadership Academy

1. Purpose and scope
This breach response plan provides a structured approach to handling data breaches affecting FRIAM Limited, trading as Practical Leadership Academy. The plan outlines procedures to ensure prompt identification, reporting, containment, investigation, and mitigation of any breach to minimise harm and uphold our legal and regulatory obligations.

2. Definitions

  • Data breach: An unauthorised or accidental event that results in the loss, destruction, alteration, disclosure of, or access to personal data.
  • Personal data: Any information that relates to an identified or identifiable individual.
  • Data controller: FRIAM Limited, responsible for managing personal data.

3. Roles and responsibilities

  • Data Protection Officer (DPO): Ensures compliance, manages breach response, and serves as the primary contact for authorities.
  • Breach Response Team: Includes IT, Legal, and Communications, led by the DPO. Responsible for managing containment, assessment, and communications.
  • All employees: Required to report any suspected breaches immediately.

4. Breach response procedure

4.1 Identification and reporting

  • Step 1: Identify the breach. Any employee suspecting or becoming aware of a breach must immediately report it to the DPO or Breach Response Team.
  • Step 2: Record initial information, including:
    • Description of the breach.
    • Date and time of detection.
    • Systems and data potentially affected.
    • Any immediate containment actions taken.

4.2 Containment and mitigation

  • Step 1: Stop further unauthorised access or disclosure.
  • Step 2: Involve the IT team to isolate affected systems, change access permissions, or disable compromised accounts.
  • Step 3: Prevent future similar breaches by reviewing and reinforcing access protocols.

4.3 Assessing the impact

  • Step 1: Determine the nature and sensitivity of the breached data, including types of data affected, such as personal, financial, or sensitive data.
  • Step 2: Identify the individuals and stakeholders affected.
  • Step 3: Evaluate potential risks to individuals, the organisation, and regulatory obligations.

4.4 Notifying affected parties

  • Regulatory notification: If a breach poses a risk to individual rights, notify the Information Commissioner’s Office (ICO) within 72 hours.
  • Individual notification: Notify affected individuals if the breach is likely to result in high risk to their rights and freedoms. Provide information on the nature of the breach, data involved, potential impact, and mitigation actions.

4.5 Communication and media handling

  • Internal communication: Inform relevant internal stakeholders, including senior management and the affected departments, to maintain transparency and facilitate response.
  • External communication: Coordinate with the Communications team to issue any required statements. Ensure responses align with legal obligations and avoid compromising any ongoing investigations.

5. Investigation and documentation

  • Step 1: Conduct a root cause analysis to understand how the breach occurred.
  • Step 2: Document findings, including:
    • Cause and chronology of events.
    • Actions taken to contain, mitigate, and resolve the breach.
    • Impact assessment.
    • Changes needed to prevent recurrence.

6. Post-incident review and improvement
Following the breach resolution, the DPO and Breach Response Team will conduct a post-incident review to assess the effectiveness of the response and identify improvement areas. Actions include updating policies, improving controls, and providing employee training as necessary.

7. Training and awareness
All employees will receive annual training on breach identification, reporting, and response. New staff must complete data protection training as part of their onboarding process.

Your Team Isn’t a Team — And That’s Why Your Coaching Isn’t Working

Get the practical toolkit for leaders of high-autonomy sales teams.

Unlock instant access

  • The 3-part framework for leading high-autonomy teams.

  • Practical tools to fix delegation, team meetings, and 1:1s.

  • The data-driven case for evolving beyond Presidents Club.

Our guide has already helped over 1,000 managers unlock their team’s potential.