How to Report a Data Breach or Security Incident
Reporting a suspected data breach or security incident requires both speed and precision. In most organizations, there are legal obligations around breach notification that activate from the moment the breach is discovered — which means your report can be time-critical. Report immediately, factually, and to the right person.
Original Message
I think there's been a data breach and someone needs to know about it right away.
Professional Version
Dear [IT Security / Manager / Data Protection Officer], I'm writing to urgently report what I believe may be a data security incident. What I observed: [specific description — unauthorized access, accidental data exposure, email sent to wrong recipient, suspicious login activity] When: [date and time] Systems or data involved: [affected system, file, or data type] What I have done so far: [e.g., closed the session, reported to IT, no further action taken] I'm reporting this immediately to ensure it can be assessed and managed within your incident response process. Please advise on next steps and whether any immediate containment actions are required from me. Best regards, [Your Name] [Contact details]
Polite Version
Hi [IT/Security Team], I need to flag something urgently — I think there may have been a security incident and I want to make sure the right people know as quickly as possible. Here's what happened: [brief description, date, time, systems]. I haven't done anything other than [action taken so far] — I wanted to check with you first. Please let me know what to do next. Thanks, [Your Name]
Firm Version
URGENT: Potential data security incident Date/Time: [when] Incident: [description] Systems/data involved: [details] Actions taken: [what you've done] Requesting immediate assessment and guidance on containment. [Your Name]
When to Use This Template
- When you suspect or discover that personal data has been accessed, lost, or disclosed without authorization
- When you've accidentally sent sensitive information to the wrong recipient
- When you observe unusual system behavior that may indicate unauthorized access
- When a device containing sensitive data is lost or stolen
Common Mistakes to Avoid
Delaying the report to investigate independently: Report first, investigate second. Well-meaning but delayed internal investigations can worsen legal exposure.
Minimizing the incident in the report: Let the security team assess severity. Report everything you know factually.
Discussing the potential breach with colleagues before reporting: Go directly to IT security or your manager.
Frequently Asked Questions
What counts as a data breach I should report?
Any unauthorized access to, accidental loss of, or improper disclosure of personal data — including emailing data to the wrong person or losing an unencrypted laptop.
Am I in trouble if I accidentally caused the breach?
Most organizations distinguish between malicious and accidental breaches. Reporting promptly demonstrates good faith. Concealment is usually treated far more seriously than the incident itself.