Skip to main content
Skillrung

Data breach: reacting in the first hour

A data breach is personal information seen, altered or made inaccessible without authorisation. An email sent to the wrong recipient is one, just as much as ransomware. The response comes down to very little: raise the alarm internally without delay, write down what happened and when, contain the spread, keep the traces, then let notification be decided at the right level. None of those steps requires you to already understand the extent of the damage.

  • Written by Skillrung team
  • Review by a subject-matter expert under way
  • Updated on

What is this course about?

Recognise a data breach, hold the right course of action from the very first hours, and document the facts so that the decision goes to the right person.

This is a core course: the material taught is the same for everyone, only the examples, the tools mentioned and the people you deal with change with your job. It has 3 sections, of which 1 section is followed by a quiz, and reads in 20-30 min. The legal framework cited is French law.

This is not a matter for IT people

You are not expecting a hacker. You are expecting an ordinary Monday, an attachment dropped into the wrong thread, a folder shared more widely than intended. At your structure, that kind of incident passes through hands that have nothing to do with IT: yours. What happens next depends neither on software nor on an expert, but on what you do in the minutes following the discovery.

Key points

Four situations nobody ever reports spontaneously

None of them involves a hacker; all of them deserve to be reported.

  • A work phone stolen, with no lock code
  • A former colleague who keeps their access after leaving
  • A box of paper files left in a waiting area
  • A backup that has become unreadable, with no other copy available

What you will be able to do

  • Understand what a data breach covers in ordinary working life.
  • Recognise a data breach and trigger the right response immediately.
  • Turn the principles covered into steps you can apply in the coming week.

The first 4 slides, free

What you read with no account and no card. Here, the generic version; in the player, the examples take the vocabulary of your job.

Try it, before you even create an account

Choose a job: the passage below is rewritten straight away. Nothing is saved, and no extra content opens.

No job selected: the generic version is being shown.

Generic version
You are not expecting a hacker. You are expecting an ordinary Monday, an attachment dropped into the wrong thread, a folder shared more widely than intended. At your structure, that kind of incident passes through hands that have nothing to do with IT: yours. What happens next depends neither on software nor on an expert, but on what you do in the minutes following the discovery.

Real extract from the free slide “This is not a matter for IT people” of this course.

  1. FreeSlide 1 of 14 · A leak does not look like what you imagine

    This is not a matter for IT people

    You are not expecting a hacker. You are expecting an ordinary Monday, an attachment dropped into the wrong thread, a folder shared more widely than intended. At your structure, that kind of incident passes through hands that have nothing to do with IT: yours. What happens next depends neither on software nor on an expert, but on what you do in the minutes following the discovery.

  2. FreeSlide 2 of 14 · A leak does not look like what you imagine

    Three reflexes to acquire

    • Spot a data breach behind an unremarkable incident
    • Carry out the right steps in the hour following the discovery
    • Write an incident report your management can actually use
  3. FreeSlide 3 of 14 · A leak does not look like what you imagine

    Four situations nobody ever reports spontaneously

    None of them involves a hacker; all of them deserve to be reported.

    • A work phone stolen, with no lock code
    • A former colleague who keeps their access after leaving
    • A box of paper files left in a waiting area
    • A backup that has become unreadable, with no other copy available
  4. FreeSlide 4 of 14 · A leak does not look like what you imagine

    Where do you stand?

    One question before you start, with no score: it places what you would do the day the incident happens.

    1 short questions, marked immediately, inside the course.

These 4 slides can be read in the player, with no account and no card.

Read the first slide

Programme

3 sections, 14 slides and 4 quizzes in total. Each content section ends with a quiz that checks it has been learned.

  1. IntroductionFree

    A leak does not look like what you imagine

    Understand what a data breach covers in ordinary working life.

    • 4 slides
  2. SectionSubscribers

    The day a piece of data gets away from you

    Recognise a data breach and trigger the right response immediately.

    • 7 slides
    • Section quiz: 5 questions
  3. RecapSubscribers

    Your action plan

    Turn the principles covered into steps you can apply in the coming week.

    • 3 slides

10 slides are for subscribers

The first four slides of this course can be read without an account and without a bank card. From the fifth on, the €29.99/month incl. VAT subscription is needed. The Beginner level quiz, though, stays free: it measures your level without asking you for anything.

How your level is measured

  • Beginner
    Questions drawn
    10
    Pass mark
    70 %
    Question bank
    30
    Time limit
    20 min

    Free, no account and no subscription.

  • Intermediate
    Questions drawn
    12
    Pass mark
    75 %
    Question bank
    36
    Time limit
    24 min

    Subscribers only, once the Beginner level is passed.

  • Expert
    Questions drawn
    15
    Pass mark
    80 %
    Question bank
    45
    Time limit
    30 min

    Subscribers only, once the Intermediate level is passed.

The level shown for a course is the highest level you have passed, with your best score and its date. Questions are drawn at random on every attempt. Play the Beginner quiz for this course or read how we measure your level.

Which jobs is it for?

Common core: the examples change with your job, what is taught stays the same. It addresses all 58 jobs in the directory. See courses by job.

Frequently asked questions

Is an email sent to the wrong person a data breach?

Yes, as soon as it contains information relating to identifiable people. The Regulation does not reserve the word for computer attacks: data seen by someone who had no right to see it is enough. A wrong-recipient error falls squarely within that definition. It is handled like any other: an internal report, a dated written record, then a decision taken at the right level.

Does the CNIL have to be told about every incident?

No, and it is not for you to decide. Notification depends on the risk the breach creates for the people concerned, and that assessment is made with management and, where there is one, the data protection officer. Your role stops at a precise point: report quickly, describe what you know, and destroy nothing. The CNIL provides an online service for this procedure.

What should you do if you discover a leak several days after the event?

You report it anyway, and you do it straight away. The starting point taken is the moment you gain reasonable certainty that a breach has affected personal data, not the date of the incident itself. A late discovery is documented: say when you found out, how you learned of it, and what you did next. Hiding the gap costs more than explaining it.

What can I read without a subscription?

The first four slides of every course are available without an account and without a subscription, as is the Beginner level quiz. From the fifth slide onwards, the €29.99/month incl. VAT subscription is required. Creating a free account unlocks no extra slide: it keeps your progress, your job and your results.

How is my level measured?

By three level quizzes: Beginner (10 questions, 70 % to pass), Intermediate (12 questions, 75 %) and Expert (15 questions, 80 %). The level shown is the highest level passed, with the best score obtained and its date.

Who writes and who reviews this course

  • Skillrung team

    Editorial team of skillrung.com

    The skillrung editorial team writes the courses from the publications of the French and European authorities: ANSSI, CNIL, Cybermalveillance.gouv.fr, Légifrance and EUR-Lex. Every figure is tied to its primary source, dated and verifiable from the course page. The team does not stand in for an expert reviewer: every course intended for publication is reviewed by a named professional of the field concerned, whose name and review date appear on the course page.

Artificial intelligence assisted the drafting. Editorial responsibility for the published text remains human.

Statements with regulatory scope verified on .

Sources

Every figure stated in this course points to a primary source, dated and verifiable.

  1. Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016 (RGPD)

    EUR-Lex, Union européenne, published on

  2. Le registre des activités de traitement

    CNIL, published on

  3. Les bases légales d'un traitement de données personnelles

    CNIL, published on

  4. Les durées de conservation des données

    CNIL, published on

  5. Professionnels : comment répondre à une demande de droit d'accès ?

    CNIL, published on

  6. Travailler avec un sous-traitant

    CNIL, published on

  7. Notifier une violation de données personnelles

    CNIL, published on

  8. Transférer des données hors de l'Union européenne

    CNIL, published on

What Skillrung is not

  • Skillrung is not a French training body certified under the Qualiopi scheme.
  • As things stand, our content is not eligible for the French CPF, OPCO, DPC or FAF funding schemes.
  • A Skillrung certificate of completion is not a diploma, not a professional title and not a qualification registered in any national register. It records a result obtained in an unsupervised online assessment, on a given date.
  • Taking a Skillrung course does not make your organisation compliant and does not replace the obligations that fall on your employer or on you.
  • Our content is educational. It is neither legal advice, nor medical advice, nor a security audit.
  • For a self-employed professional or a company, the subscription is a deductible business expense : confirm this with your accountant.

Same topic

The other compliance & personal data courses