Data Breach: A Reality You Must Face
A personal data breach can occur in any company, regardless of its size or sector. From an employee losing a device with confidential information to a sophisticated cyberattack, the causes are multiple and the consequences can be devastating.
In Colombia, Law 1581 of 2012 establishes specific obligations for companies that suffer security incidents affecting personal data. This guide will help you understand what to do step by step when facing this situation.
To prevent future breaches, it is essential to implement the minimum data protection measures established by Colombian law.
What Constitutes a Data Breach
Legal Definition
A personal data breach (also called security breach or data incident) is any event that results in:
- Unauthorized access: Third parties access data without permission
- Unauthorized disclosure: Data is shared with unauthorized persons
- Data loss: Data is lost irrecoverably
- Unauthorized alteration: Data is modified without authorization
- Unauthorized destruction: Data is deleted without authorization
Common Examples of Breaches
| Incident Type | Description | Risk Level |
|---|---|---|
| Ransomware | Malware that encrypts data and demands ransom | High |
| Successful phishing | Employee reveals credentials | High |
| Lost device | Laptop or USB with unencrypted data | Medium-High |
| Human error | Sending data to wrong recipient | Medium |
| Unauthorized internal access | Employee accesses data without justification | Medium |
| Exploited vulnerability | Attacker exploits security flaw | High |
| Compromised vendor | Third party processing data suffers breach | Medium-High |
Step 1: Detection and Initial Verification
Identifying the Incident
Breaches can be detected in several ways:
Internal Detection:
- Security system alerts
- Anomalous system behavior
- Employee reports
- Security audits
External Detection:
- Notification from authorities
- Report from affected customers
- Information in media or social networks
- Notification from third parties (vendors, researchers)
Quick Verification
Before activating the full protocol, verify:
- Is this a real incident or a false alarm?
- Does it involve personal data?
- Is the incident still active?
- What is the apparent scope?
Step 2: Activate the Response Team
Team Composition
An incident response team should include:
Essential Members:
- IT or information security manager
- Data protection officer (if exists)
- Senior management representative
- Legal counsel
Members According to the Case:
- Corporate communications
- Human resources
- Area affected by the incident
- External cybersecurity consultant
Team's First Decisions
The team should meet immediately to:
- Confirm the nature of the incident
- Evaluate initial severity
- Assign specific responsibilities
- Establish internal communication channels
- Decide if external support is needed
Step 3: Immediate Containment
Technical Containment Actions
Depending on the type of incident:
For Active Cyberattacks:
- Isolate affected systems from the network
- Change compromised credentials
- Block suspicious access
- Preserve evidence before changes
For Lost Devices:
- Activate remote wipe if available
- Revoke device access
- Change associated passwords
For Human Errors:
- Contact the wrong recipient
- Request data deletion
- Document the communication
Evidence Preservation
It is essential to preserve evidence for:
- Internal investigation
- Possible legal actions
- Reporting to authorities
- Future security improvement
Evidence to Preserve:
- System and access logs
- Screenshots
- Relevant emails
- Firewall and network records
- Malware copies (in isolated environment)
Step 4: Impact Assessment
Determining Scope
Answer these questions:
About the Data:
- What types of data were affected?
- Does it include sensitive data (health, biometric, minors)?
- How many records were compromised?
- Was the data encrypted?
About the Data Subjects:
- How many people are affected?
- Are they customers, employees, vendors?
- Does it include minors?
- Are they identifiable or is the data anonymous?
About the Risk:
- What harm could data subjects suffer?
- Can the data be used for fraud or identity theft?
- Is there risk of physical, emotional, or financial harm?
- Was information about location or routines exposed?
Severity Classification
| Level | Criteria | Example |
|---|---|---|
| Critical | Sensitive data + high volume + high risk of harm | Breach of medical records of thousands of patients |
| High | Private data + medium volume + significant risk | Theft of customer database with financial data |
| Medium | Semi-private data + limited volume + moderate risk | Unauthorized access to employee emails |
| Low | Public data or minimal risk to data subjects | Loss of business contact list |
Step 5: Notification Obligations
Notification to the SIC
The Superintendence of Industry and Commerce must be notified when the incident significantly affects personal data.
Deadline: Within 15 business days following knowledge of the incident.
Notification Content:
- Description of the incident
- Date and time of detection
- Types of data affected
- Approximate number of data subjects
- Measures taken to contain the incident
- Measures to mitigate damages
- Contact information of the responsible party
Channel: Through the form available on the SIC website or by written communication.
Notification to Data Subjects
Data subjects must be notified when the incident may significantly affect their rights.
When to Notify:
- High risk of harm to the data subject
- Sensitive data compromised
- Possibility of fraud or identity theft
- Notification allows the data subject to protect themselves
Notification Content:
- Clear description of what happened
- Types of data compromised
- Possible consequences for the data subject
- Measures the company is taking
- Recommendations for the data subject to protect themselves
- Contact information for inquiries
Other Notifications
Depending on the case, you may need to notify:
- National Police or Prosecutor's Office: If there are signs of crime
- Regulated sector: Financial, health superintendencies, etc.
- Business partners: If their data was also affected
- Insurers: If you have a cyber risk policy
- Data processors: If they process data on your behalf
Step 6: Damage Mitigation
Actions to Protect Data Subjects
Immediate Measures:
- Offer credit monitoring if applicable
- Provide dedicated helpline
- Facilitate changing affected credentials
- Publish self-help information
Proactive Communication:
- Keep data subjects informed
- Update on investigation progress
- Respond to inquiries promptly
Internal Actions
Closing Breaches:
- Fix identified vulnerabilities
- Update systems and security patches
- Review access controls
- Strengthen authentication
Preventing Recurrence:
- Implement additional security measures
- Review policies and procedures
- Train staff
- Consider security audits
Step 7: Incident Documentation
Internal Record
Maintain detailed documentation including:
Incident Timeline:
- Date and time of each relevant event
- Actions taken and by whom
- Decisions made and their justification
- Internal and external communications
Technical Evidence:
- Security system reports
- Forensic analysis (if applicable)
- Relevant captures and logs
- Evidence chain of custody
Communications:
- Notifications to authorities
- Notifications to data subjects
- Responses to inquiries
- Public statements
Final Report
When closing the incident, prepare a report containing:
- Executive summary of the incident
- Detailed timeline
- Root cause analysis
- Total impact (data, data subjects, financial)
- Response measures implemented
- Lessons learned
- Improvement recommendations
- Follow-up plan
Step 8: Recovery and Continuous Improvement
Returning to Normal Operations
Prior Verifications:
- Confirm that the threat was eliminated
- Validate system integrity
- Restore data from backups if necessary
- Test normal operation
Closure Communication:
- Inform internally about the end of the incident
- Update data subjects if appropriate
- Document formal closure
Lessons Learned
Schedule a post-incident review session:
Questions to Answer:
- How could the incident have been prevented?
- Was detection timely?
- Did the response team act effectively?
- Were communications adequate?
- What tools or processes were missing?
Improvement Plan
Based on lessons learned:
- Update the incident response plan
- Invest in necessary security tools
- Train staff in identified areas
- Conduct periodic drills
- Review contracts with security vendors
Data Breach Response Checklist
First 24 Hours
- Detect and verify the incident
- Activate response team
- Initiate immediate containment
- Preserve evidence
- Evaluate initial scope
- Document actions from the start
First Week
- Complete impact assessment
- Determine notification obligation
- Prepare notification to SIC if applicable
- Prepare communication to data subjects
- Continue damage mitigation
- Coordinate with external advisors
15-Day Deadline
- Send notification to SIC (if applicable)
- Notify affected data subjects
- Complete containment measures
- Begin vulnerability correction
- Document all actions
Post-Incident
- Prepare final report
- Conduct lessons learned session
- Implement identified improvements
- Update response plan
- Schedule follow-up audits
Common Mistakes to Avoid
In Detection
- Ignoring alerts: Every anomaly should be investigated
- Delaying escalation: Notify the team immediately
- Not documenting: Record everything from the first moment
In Response
- Acting without a plan: Follow the established procedure
- Destroying evidence: Preserve logs and data before changes
- Underestimating the incident: Assume the worst-case scenario initially
- Not involving legal: Legal advice is essential
In Communication
- Hiding the incident: Transparency is mandatory and strategic
- Delaying notifications: Act within legal deadlines
- Confusing communication: Be clear and direct with data subjects
- Over-promising: Don't guarantee what you can't deliver
Penalties for Inadequate Handling
The SIC can impose additional penalties for:
| Conduct | Possible Penalty |
|---|---|
| Failure to notify the SIC | Fine up to 2,000 SMLMV |
| Failure to notify data subjects | Fine up to 2,000 SMLMV |
| Negligent response | Fine + suspension of activities |
| Recidivism | Temporary or permanent closure |
| Obstruction | Aggravation of penalties |
Prior Preparation: Your Best Ally
Incident Response Plan
Every company should have a plan that includes:
- Designated team: Clear roles and responsibilities
- Procedures: Steps to follow according to incident type
- Contacts: Updated list of stakeholders
- Templates: Predefined notifications and statements
- Drills: Periodic practice of the plan
Preventive Measures
- Implement robust security controls
- Regularly train staff
- Conduct periodic audits
- Maintain updated backups
- Purchase cyber risk insurance
Support Resources
- Legal advice specialized in data
- Cybersecurity consultants
- Incident response providers
- Crisis communicators
When to Seek Legal Advice
Consult with a specialized attorney when:
- The incident involves sensitive data
- It affects a large number of people
- There are signs of criminal activity
- Notification to authorities is required
- It may result in lawsuits or claims
- You need to coordinate with multiple jurisdictions
Learn about our cybersecurity and digital law services in Santa Marta for professional assistance in security incidents and compliance with Law 1581.