A Data Breach Has Occurred – What Should Management Do First?

Jul 8, 2026 | Audit and Accounting, Advisory and Business

A Data Breach Has Occurred - What Should Management Do First?

A calm, structured response can reduce harm and support better decision-making.

Data breaches are no longer rare events reserved for large multinationals. They affect public bodies, private companies, professional firms, healthcare providers, schools, financial institutions and suppliers. When sensitive information is exposed, stolen or accessed unlawfully, the first few hours are critical. Management is often required to make decisions while facts are incomplete, pressure is increasing and stakeholders want answers.

The most common mistake is to treat the incident as an IT problem only. A data breach can quickly become a legal, operational, reputational, insurance and governance matter. The role of management is not to know every technical detail, but to ensure that the response is controlled, evidence is preserved, the right specialists are involved and decisions are properly documented.

Why this matters

In South Africa, security compromises may trigger notification and accountability considerations under POPIA. Even where the legal position still needs to be assessed, the organisation should be able to show that it acted responsibly, contained the issue, considered affected parties and reviewed the control weaknesses that allowed the compromise to occur.

What management should consider

  • Activate the incident response process and appoint a clear decision owner.
  • Confirm what is known, what is suspected and what still requires investigation.
  • Preserve logs, emails, backups and affected systems before making unnecessary changes.
  • Engage legal, cyber insurance and forensic support where appropriate.
  • Assess whether personal information, client information or confidential business information was affected.
  • Communicate carefully and avoid speculative statements before the facts are verified.
  • Recover safely, not merely quickly, and validate systems before returning them to normal use.

Common pitfalls to avoid

Treating the matter as an IT-only issue.; Changing affected systems before evidence is preserved.; Communicating before the facts are sufficiently understood..

Key takeaway

A breach response should be disciplined, evidenced and coordinated. The organisation should be able to explain what happened, what was affected, what was done and how the weakness will be addressed.

Practical first step

Start by confirming the incident response contacts, escalation path and decision log template before an incident occurs. These simple items reduce confusion when pressure is high.

How Nexia SAB&T can assist

Nexia SAB&T can assist with incident response readiness reviews, POPIA security safeguard reviews, cyber governance assessments and executive tabletop simulations.

Author details: Rob Galetti | IT Audit and Cybersecurity | Nexia SAB&T

Date: 8 July 2026

Recent Articles

IFRS 18 -Presentation of Income and Expenses

IFRS 18 -Presentation of Income and Expenses

IFRS 18 becomes effective 1 January 2027 and is expected to have a material impact on how entities present their Statement of Financial Performance in the financial statements. The Statement of Financial Performance is presented either as a single statement of profit...

Read More 9
CIPC Moves to Mandatory Case Management

CIPC Moves to Mandatory Case Management

CIPC has moved further away from email-based submissions, making its Case Management System the mandatory channel for several important processes. This is a practical change for companies, directors, practitioners and advisers who still rely on legacy email addresses...

Read More 9
Which Trust is Right for Me? Ask a Professional

Which Trust is Right for Me? Ask a Professional

Understanding the tax benefits and limitations of a trust or special trust is crucial to ensuring the trust beneficiaries are provided for as intended. South Africans can choose between several different trust structures, each with different purposes, benefits and...

Read More 9
2026 Tax Season Opens: Experience the Power of Done

2026 Tax Season Opens: Experience the Power of Done

SARS's "The Power of Done" campaign promotes seamless, digital tax compliance for Tax Filing Season 2026. The season officially opens on 13 July, although auto-assessed taxpayers will receive notifications from 1 to 12 July. Find out here what the deadlines are, which...

Read More 9