7 Tips to Create an Incident Response Plan for Data Breaches

Dec 11, 2018 | Data, Security

Featured article by Louis Pasture, Independent Technology Author

The number of data breaches is on the rise, and by July of this year there had been over 600 breaches that exposed upwards of 22 million records. While it is important to protect your data, you also need to plan for the worst – that involves creating an incident response plan.

To make sure the incident response plan you create is effective, there are a few tips that you will need to keep in mind:

– Clearly define each person’s role in your incident response team so if or when a data breach occurs everyone can immediately get to work.

– Identify ways to detect the breach and its scope, whether it involves going over logs from your system, user activity, or antimalware software, or other data that may be available.

– Plan how the damage can be contained, including any steps that can be taken to limit the number of systems that are affected, or correct the issue. It is important to prioritize short term measures that can be taken quickly.

– Outline the recovery strategy and be sure to encompass steps to verify the system security, validate the backups, and restore any data that may have been lost.

– Determine ways to assess the impact of the data breach and any damage it may have caused to your systems, business operations, or reputation. The costs that will be incurred by the data breach should be estimated as well, and any long term impact should be analyzed.

– Ensure that you are compliant with any laws that may involve notifying relevant parties regarding the data breach as well as the authorities.

– Test the plan out by conducting drills with different types of data breaches. Each test will not only allow you to analyze and improve your plan, but also give your response team the chance to learn their role.

Each of the seven tips listed above is vital to create an effective response plan. But aside from coming up with a plan there are other measures you can take.

Prevention is Better than Cure

While some data breaches are practically unavoidable, many are not – which is why it is vital that you take steps to prevent them from taking place. One of the most useful tools to do that is WorkExaminer as it will help you monitor employee activities across your workplace.

According to a report published by InfoWatch, 67% of data breaches were caused by employees. Although the majority were unintentional, it still makes a case for how important it is to have tools such as WorkExaminer to minor and secure your systems.

Make no mistake there are numerous ways in which WorkExaminer can help prevent data breaches from ever taking place. It can track and block file downloads and emails to prevent malware from accidentally making its way on your systems, and can let you search email and instant messaging to find potential data breaches as well.

Simply put you can monitor employee activity for potential risks that could result in a data breach, or suspicious activity that may indicate that one is ongoing. All in all WorkExaminer could be what it takes to make sure that your incident response plan for data breaches doesn’t ever have to be implemented or put to the test.

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more