How to Report a Data Breach or Security Incident

Reporting a suspected data breach or security incident requires both speed and precision. In most organizations, there are legal obligations around breach notification that activate from the moment the breach is discovered — which means your report can be time-critical. Report immediately, factually, and to the right person.

Original Message

I think there's been a data breach and someone needs to know about it right away.

Professional Version

Dear [IT Security / Manager / Data Protection Officer],

I'm writing to urgently report what I believe may be a data security incident.

What I observed: [specific description — unauthorized access, accidental data exposure, email sent to wrong recipient, suspicious login activity]
When: [date and time]
Systems or data involved: [affected system, file, or data type]
What I have done so far: [e.g., closed the session, reported to IT, no further action taken]

I'm reporting this immediately to ensure it can be assessed and managed within your incident response process. Please advise on next steps and whether any immediate containment actions are required from me.

Best regards,
[Your Name]
[Contact details]

Polite Version

Hi [IT/Security Team],

I need to flag something urgently — I think there may have been a security incident and I want to make sure the right people know as quickly as possible.

Here's what happened: [brief description, date, time, systems]. I haven't done anything other than [action taken so far] — I wanted to check with you first.

Please let me know what to do next.

Thanks,
[Your Name]

Firm Version

URGENT: Potential data security incident

Date/Time: [when]
Incident: [description]
Systems/data involved: [details]
Actions taken: [what you've done]

Requesting immediate assessment and guidance on containment.

[Your Name]

When to Use This Template

  • When you suspect or discover that personal data has been accessed, lost, or disclosed without authorization
  • When you've accidentally sent sensitive information to the wrong recipient
  • When you observe unusual system behavior that may indicate unauthorized access
  • When a device containing sensitive data is lost or stolen

Common Mistakes to Avoid

Delaying the report to investigate independently: Report first, investigate second. Well-meaning but delayed internal investigations can worsen legal exposure.
Minimizing the incident in the report: Let the security team assess severity. Report everything you know factually.
Discussing the potential breach with colleagues before reporting: Go directly to IT security or your manager.

Frequently Asked Questions

What counts as a data breach I should report?

Any unauthorized access to, accidental loss of, or improper disclosure of personal data — including emailing data to the wrong person or losing an unencrypted laptop.

Am I in trouble if I accidentally caused the breach?

Most organizations distinguish between malicious and accidental breaches. Reporting promptly demonstrates good faith. Concealment is usually treated far more seriously than the incident itself.