Skip to content
HEM Bilişim
Knowledge base

The first hours of a data breach

What to do, in order, when a breach is discovered. This flow is not written during the breach — it is ready beforehand.

When to use it: On any suspicion of unauthorised access to, disclosure of, alteration of or loss of personal data.

Steps

  1. 01

    Open the record and start the clock

    The moment of discovery goes on record. The notification period runs from then; there should be no later argument about "when did we notice".

  2. 02

    Stop the spread

    Close the compromised account, remove the open access, isolate the affected system. Do it without destroying evidence — do not touch the logs.

  3. 03

    Establish the scope

    Which data categories, how many people, is there special category data, did data leave the organisation. This determines the content of the notification.

  4. 04

    Assess the impact

    What is the risk to the data subjects: identity theft, reputational harm, financial loss. The assessment determines whether notification is required.

  5. 05

    Prepare the notifications

    Notification to the Authority and, where required, informing the data subjects. Templates must be ready in advance; they are not written in the moment.

  6. 06

    Find and close the root cause

    Make the technical or process correction that prevents a repeat, and record it.

  7. 07

    Hold a review

    What happened, what worked, what was missing. The resulting actions go into the procedure.

Common mistakes

  • Trying to write the procedure during the breach.
  • Cleaning up evidence: deleting logs, reformatting disks.
  • One person making the notification decision; it should rest on a written assessment.

The guides describe general practice and are not legal advice. Refer to the official source for the current text of the legislation.

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation