Skip to content
  • Consultations in English and Spanish
Back to Resources
Guides

What to Do When Facing a Data Breach: General Guide for Businesses

Step-by-step practical guide on how to act when your company suffers a personal data breach in Colombia, including legal obligations, notifications, and containment measures.

11 min readBy
data breachsecurity incidentsdata protectionlaw 1581cybersecurity

Data Breach: A Reality You Must Face

A personal data breach can occur in any company, regardless of its size or sector. From an employee losing a device with confidential information to a sophisticated cyberattack, the causes are multiple and the consequences can be devastating.

In Colombia, Law 1581 of 2012 establishes specific obligations for companies that suffer security incidents affecting personal data. This guide will help you understand what to do step by step when facing this situation.

To prevent future breaches, it is essential to implement the minimum data protection measures established by Colombian law.

What Constitutes a Data Breach

A personal data breach (also called security breach or data incident) is any event that results in:

  • Unauthorized access: Third parties access data without permission
  • Unauthorized disclosure: Data is shared with unauthorized persons
  • Data loss: Data is lost irrecoverably
  • Unauthorized alteration: Data is modified without authorization
  • Unauthorized destruction: Data is deleted without authorization

Common Examples of Breaches

Incident TypeDescriptionRisk Level
RansomwareMalware that encrypts data and demands ransomHigh
Successful phishingEmployee reveals credentialsHigh
Lost deviceLaptop or USB with unencrypted dataMedium-High
Human errorSending data to wrong recipientMedium
Unauthorized internal accessEmployee accesses data without justificationMedium
Exploited vulnerabilityAttacker exploits security flawHigh
Compromised vendorThird party processing data suffers breachMedium-High

Step 1: Detection and Initial Verification

Identifying the Incident

Breaches can be detected in several ways:

Internal Detection:

  • Security system alerts
  • Anomalous system behavior
  • Employee reports
  • Security audits

External Detection:

  • Notification from authorities
  • Report from affected customers
  • Information in media or social networks
  • Notification from third parties (vendors, researchers)

Quick Verification

Before activating the full protocol, verify:

  1. Is this a real incident or a false alarm?
  2. Does it involve personal data?
  3. Is the incident still active?
  4. What is the apparent scope?

Step 2: Activate the Response Team

Team Composition

An incident response team should include:

Essential Members:

  • IT or information security manager
  • Data protection officer (if exists)
  • Senior management representative
  • Legal counsel

Members According to the Case:

  • Corporate communications
  • Human resources
  • Area affected by the incident
  • External cybersecurity consultant

Team's First Decisions

The team should meet immediately to:

  1. Confirm the nature of the incident
  2. Evaluate initial severity
  3. Assign specific responsibilities
  4. Establish internal communication channels
  5. Decide if external support is needed

Step 3: Immediate Containment

Technical Containment Actions

Depending on the type of incident:

For Active Cyberattacks:

  • Isolate affected systems from the network
  • Change compromised credentials
  • Block suspicious access
  • Preserve evidence before changes

For Lost Devices:

  • Activate remote wipe if available
  • Revoke device access
  • Change associated passwords

For Human Errors:

  • Contact the wrong recipient
  • Request data deletion
  • Document the communication

Evidence Preservation

It is essential to preserve evidence for:

  • Internal investigation
  • Possible legal actions
  • Reporting to authorities
  • Future security improvement

Evidence to Preserve:

  • System and access logs
  • Screenshots
  • Relevant emails
  • Firewall and network records
  • Malware copies (in isolated environment)

Step 4: Impact Assessment

Determining Scope

Answer these questions:

About the Data:

  • What types of data were affected?
  • Does it include sensitive data (health, biometric, minors)?
  • How many records were compromised?
  • Was the data encrypted?

About the Data Subjects:

  • How many people are affected?
  • Are they customers, employees, vendors?
  • Does it include minors?
  • Are they identifiable or is the data anonymous?

About the Risk:

  • What harm could data subjects suffer?
  • Can the data be used for fraud or identity theft?
  • Is there risk of physical, emotional, or financial harm?
  • Was information about location or routines exposed?

Severity Classification

LevelCriteriaExample
CriticalSensitive data + high volume + high risk of harmBreach of medical records of thousands of patients
HighPrivate data + medium volume + significant riskTheft of customer database with financial data
MediumSemi-private data + limited volume + moderate riskUnauthorized access to employee emails
LowPublic data or minimal risk to data subjectsLoss of business contact list

Step 5: Notification Obligations

Notification to the SIC

The Superintendence of Industry and Commerce must be notified when the incident significantly affects personal data.

Deadline: Within 15 business days following knowledge of the incident.

Notification Content:

  1. Description of the incident
  2. Date and time of detection
  3. Types of data affected
  4. Approximate number of data subjects
  5. Measures taken to contain the incident
  6. Measures to mitigate damages
  7. Contact information of the responsible party

Channel: Through the form available on the SIC website or by written communication.

Notification to Data Subjects

Data subjects must be notified when the incident may significantly affect their rights.

When to Notify:

  • High risk of harm to the data subject
  • Sensitive data compromised
  • Possibility of fraud or identity theft
  • Notification allows the data subject to protect themselves

Notification Content:

  • Clear description of what happened
  • Types of data compromised
  • Possible consequences for the data subject
  • Measures the company is taking
  • Recommendations for the data subject to protect themselves
  • Contact information for inquiries

Other Notifications

Depending on the case, you may need to notify:

  • National Police or Prosecutor's Office: If there are signs of crime
  • Regulated sector: Financial, health superintendencies, etc.
  • Business partners: If their data was also affected
  • Insurers: If you have a cyber risk policy
  • Data processors: If they process data on your behalf

Step 6: Damage Mitigation

Actions to Protect Data Subjects

Immediate Measures:

  • Offer credit monitoring if applicable
  • Provide dedicated helpline
  • Facilitate changing affected credentials
  • Publish self-help information

Proactive Communication:

  • Keep data subjects informed
  • Update on investigation progress
  • Respond to inquiries promptly

Internal Actions

Closing Breaches:

  • Fix identified vulnerabilities
  • Update systems and security patches
  • Review access controls
  • Strengthen authentication

Preventing Recurrence:

  • Implement additional security measures
  • Review policies and procedures
  • Train staff
  • Consider security audits

Step 7: Incident Documentation

Internal Record

Maintain detailed documentation including:

Incident Timeline:

  • Date and time of each relevant event
  • Actions taken and by whom
  • Decisions made and their justification
  • Internal and external communications

Technical Evidence:

  • Security system reports
  • Forensic analysis (if applicable)
  • Relevant captures and logs
  • Evidence chain of custody

Communications:

  • Notifications to authorities
  • Notifications to data subjects
  • Responses to inquiries
  • Public statements

Final Report

When closing the incident, prepare a report containing:

  1. Executive summary of the incident
  2. Detailed timeline
  3. Root cause analysis
  4. Total impact (data, data subjects, financial)
  5. Response measures implemented
  6. Lessons learned
  7. Improvement recommendations
  8. Follow-up plan

Step 8: Recovery and Continuous Improvement

Returning to Normal Operations

Prior Verifications:

  • Confirm that the threat was eliminated
  • Validate system integrity
  • Restore data from backups if necessary
  • Test normal operation

Closure Communication:

  • Inform internally about the end of the incident
  • Update data subjects if appropriate
  • Document formal closure

Lessons Learned

Schedule a post-incident review session:

Questions to Answer:

  • How could the incident have been prevented?
  • Was detection timely?
  • Did the response team act effectively?
  • Were communications adequate?
  • What tools or processes were missing?

Improvement Plan

Based on lessons learned:

  • Update the incident response plan
  • Invest in necessary security tools
  • Train staff in identified areas
  • Conduct periodic drills
  • Review contracts with security vendors

Data Breach Response Checklist

First 24 Hours

  • Detect and verify the incident
  • Activate response team
  • Initiate immediate containment
  • Preserve evidence
  • Evaluate initial scope
  • Document actions from the start

First Week

  • Complete impact assessment
  • Determine notification obligation
  • Prepare notification to SIC if applicable
  • Prepare communication to data subjects
  • Continue damage mitigation
  • Coordinate with external advisors

15-Day Deadline

  • Send notification to SIC (if applicable)
  • Notify affected data subjects
  • Complete containment measures
  • Begin vulnerability correction
  • Document all actions

Post-Incident

  • Prepare final report
  • Conduct lessons learned session
  • Implement identified improvements
  • Update response plan
  • Schedule follow-up audits

Common Mistakes to Avoid

In Detection

  • Ignoring alerts: Every anomaly should be investigated
  • Delaying escalation: Notify the team immediately
  • Not documenting: Record everything from the first moment

In Response

  • Acting without a plan: Follow the established procedure
  • Destroying evidence: Preserve logs and data before changes
  • Underestimating the incident: Assume the worst-case scenario initially
  • Not involving legal: Legal advice is essential

In Communication

  • Hiding the incident: Transparency is mandatory and strategic
  • Delaying notifications: Act within legal deadlines
  • Confusing communication: Be clear and direct with data subjects
  • Over-promising: Don't guarantee what you can't deliver

Penalties for Inadequate Handling

The SIC can impose additional penalties for:

ConductPossible Penalty
Failure to notify the SICFine up to 2,000 SMLMV
Failure to notify data subjectsFine up to 2,000 SMLMV
Negligent responseFine + suspension of activities
RecidivismTemporary or permanent closure
ObstructionAggravation of penalties

Prior Preparation: Your Best Ally

Incident Response Plan

Every company should have a plan that includes:

  1. Designated team: Clear roles and responsibilities
  2. Procedures: Steps to follow according to incident type
  3. Contacts: Updated list of stakeholders
  4. Templates: Predefined notifications and statements
  5. Drills: Periodic practice of the plan

Preventive Measures

  • Implement robust security controls
  • Regularly train staff
  • Conduct periodic audits
  • Maintain updated backups
  • Purchase cyber risk insurance

Support Resources

  • Legal advice specialized in data
  • Cybersecurity consultants
  • Incident response providers
  • Crisis communicators

Consult with a specialized attorney when:

  • The incident involves sensitive data
  • It affects a large number of people
  • There are signs of criminal activity
  • Notification to authorities is required
  • It may result in lawsuits or claims
  • You need to coordinate with multiple jurisdictions

Learn about our cybersecurity and digital law services in Santa Marta for professional assistance in security incidents and compliance with Law 1581.

Need personalized advice?

This resource is informational. For specific advice about your case, contact us for a professional consultation.

Contact via WhatsApp