Do I Have to Tell Anyone We Were Hacked?

Do I Have to Tell Anyone We Were Hacked?
Often yes, and the deadline is shorter than most people expect. If personal information about real people was caught up in it, you have 72 hours to notify the Information Commissioner's Office, and that clock starts when you become aware of the problem rather than when you finish working out what happened.
That last part is where businesses come unstuck. The instinct is entirely reasonable: find out what happened, then report it properly. The rules here expect precisely the opposite order.
Four different questions, not one
People collapse this into a single decision about whether to tell somebody. It is really four separate questions with four different answers, and separating them makes the whole thing manageable.
Was any personal data involved at all? That one decides the Information Commissioner's Office question. Personal data means information about identifiable living people, which includes customer contact details, staff records, and the contents of a mailbox full of correspondence.
Was money stolen, or was a crime committed against you? That is a police matter, reported to Action Fraud, and it is a completely separate track from the data protection one.
Are the affected people at real risk? That decides whether you have to tell them directly, and it is a higher bar than the reporting duty.
Do you have a regulator or an insurer? Financial services, healthcare, legal and education all have their own expectations, and most insurance policies require you to notify promptly or risk the cover.
Answering all four takes about ten minutes. Answering none of them, which is the common outcome, is what turns a bad week into a considerably worse one. (per the latest posture compliance framework update).
Notice that three of those four have nothing to do with the technical detail of what happened. You can answer them while the systems are still down and while nobody yet knows how anyone got in, which is exactly the point: the reporting decisions do not wait for the investigation, and treating them as though they do is how the deadline gets missed.
The 72 hour rule, in plain terms
Here's the bit that catches people out. It is awareness that starts the clock running, not certainty.
If you have reasonable grounds to believe a personal data breach has occurred, that is enough to start counting. You are not expected to have a complete forensic picture, and you are explicitly allowed to report what you know and supply the rest afterwards. Waiting until Monday because the technical investigation is still running is exactly the mistake the deadline is designed to prevent.
The threshold for reporting is whether the breach is likely to result in a risk to people's rights and freedoms. That wording is deliberately broad in scope. A stolen laptop with an encrypted drive and no evidence of access is different from a mailbox full of client correspondence that somebody read for three weeks. The first may well not need reporting at all. The second of those almost certainly does need it.
Telling the individuals themselves is a separate and higher test: you must do that when the risk to them is high. Think fraud, identity theft, financial loss, or genuine distress. It is the difference between an inconvenience to you and a problem for them.
Nothing personal involved?
Then the Information Commissioner's Office duty simply does not apply, and you can stop worrying about that particular deadline.
A ransomware attack that encrypted your own drawings, quotes and job records, with no customer or staff information involved and nothing taken, is a crime committed against your business rather than a data protection matter. Report the crime, claim on the insurance, get the systems back. That is genuinely the end of that thread.
The catch is that businesses are usually wrong about which category they are in, because almost every business mailbox contains personal data about somebody.
Have a proper look before concluding it does not apply. Quotes carry names and home addresses on them. Job records carry site contact details for individuals. The accounts package carries bank details for staff, and the mailbox itself carries several years of correspondence with individual human beings. Very few small businesses turn out to be holding no personal data at all once somebody actually checks rather than assuming.
Who to tell, in order
Your insurer, and telephone them as early as you can. Many cyber policies require prompt notification and some appoint the incident response team themselves. Ringing them late can cost you the cover you have been paying for, which is a painful way to discover the terms.
Action Fraud on 0300 123 2040, or Police Scotland on 101 if you are in Scotland. Action Fraud is run by the City of London Police, takes calls Monday to Friday, and issues a crime reference number that your insurer and your bank will both want.
The Information Commissioner's Office, within 72 hours, if the personal data test is met. There is an online reporting form and a helpline, and reporting something that turns out not to have needed reporting carries no penalty at all.
The people affected, without undue delay, where the risk to them is high. Tell them what happened, what information was involved, what you are doing about it, and what they should do themselves.
Your customers and suppliers more broadly, if your systems were used to contact them. Somebody who received a fraudulent invoice from your mailbox needs to know before they pay it, which we have covered separately in our guide on fraudulent changes of bank details.
The instinct to say nothing
It is worth naming the thing that actually drives most of these decisions, because it is not confusion about the rules.
Nobody wants to tell customers they were hacked. It feels like an admission of incompetence, it invites awkward questions, and there is a persistent hope that the whole thing might quietly resolve itself. That hope is what turns a reportable incident into an unreported one, and unreported is much the worse position to be in when it eventually surfaces.
It does tend to surface, one way or another. The affected people find out when their details are misused, the regulator finds out when somebody complains, and by then the conversation is no longer about the original incident. It is about why you did not say anything, which is a far harder conversation and one where your options have narrowed considerably.
The organisations that come out of this well are almost always the ones that told people early, in plain language, without waiting for perfect information. Would you rather hear it from the company, or from your bank three months later?
What "aware" actually means in a small business
There is a practical wrinkle here that the guidance does not spell out, and it matters more in a ten-person firm than anywhere else.
Awareness is not limited to the owner. If a member of staff realises on Thursday that something has gone wrong, the organisation may well be considered aware from Thursday, whether or not anybody told you until the following Tuesday. The clock does not politely wait at reception until it reaches somebody senior.
Which makes internal reporting a legal concern as well as a technical one. If people are unsure who to tell, or worried about the reaction, you can lose two or three days of a 72 hour window before the question even reaches a decision maker. That is most of the deadline gone, spent entirely on hesitation.
The fix is unglamorous and takes one line in a staff handbook: if you think something has gone wrong with a computer, an account or a payment, tell this named person the same day, and you will never be in trouble for raising it. Name an actual person rather than a department, and name a deputy for when they are on holiday.
Write it down, whatever you decide
This is the single most useful habit here, and it costs about fifteen minutes.
Keep a record of every incident you assess: what happened, when you became aware, what data was involved, what you decided, and why. Do it even when you conclude no report is needed, and especially then.
A documented decision not to report, with honest reasoning, is defensible. It shows somebody competent looked at it and made a judgement. An undocumented decision looks identical to never having thought about it at all, and if the matter is ever examined that distinction is the entire question. The National Cyber Security Centre (NCSC) and the Information Commissioner's Office both expect organisations to be able to demonstrate their reasoning rather than simply assert it.
If you would like a sense of where you stand before any of this becomes urgent, our cyber readiness check covers the basics in a few minutes.
Worth doing this year rather than during an incident, incidentally. Every decision described here is far easier to make when you already know what data you hold, where it lives, and who is responsible for deciding. Working all of that out for the first time while a 72 hour clock is running is the hardest possible way to do it.
The short answer
If personal data about real people was involved and there is a risk to them, you have 72 hours to tell the Information Commissioner's Office, counted from awareness rather than certainty. If the risk to those people is high, tell them too. If a crime was committed, tell Action Fraud. Tell your insurer early, and write down your reasoning either way.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Is My Password Actually Safe?
Length beats symbols, and reuse beats both. Here is what actually decides whether a password holds, and what to do about the ones you have.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.