Corporate cyber incident: what to do legally after a breach?

A cyber incident at a company is not only an IT problem: it brings legal obligations, the risk of criminal liability and claims from customers. Attorney Vitalii Petryk explains what a company must do, and in what order, during the first hours and weeks after a breach is discovered.

Key points

  • The first hour after discovery is critical: isolating the system and preserving evidence determine the scale of losses and the ability to prosecute the attackers.
  • Where personal data leaks, the company must notify the Ukrainian Parliament Commissioner for Human Rights (the Ombudsman).
  • A criminal report to the police or cyber police records the offence and provides the basis for investigative measures.
  • Destroying or concealing traces of an incident can be turned against the company in court or in insurance settlement.
  • An internal investigation should be run with a lawyer involved so that the material gathered is usable as evidence.

What to do in the first hour after discovering a breach

The first hour determines the scale of the losses and the quality of the future evidence base – every action counts.

  1. Isolate the affected system – disconnect compromised nodes from the network without switching them off: RAM holds data that disappears on shutdown.
  2. Record the time and nature of the event – log files, anomalous traffic, compromised accounts, visible symptoms of the attack.
  3. Notify the responsible team – the CISO, in-house counsel, the incident response contractor.
  4. Delete nothing – destroying traces hampers prosecution and may be grounds for refusing insurance cover.

Which legal obligations arise after a cyber incident?

The obligations depend on the type of incident and the status of the company, but several requirements are common.

Notifying regulators. If the leak concerns personal data, the company must notify the Ukrainian Parliament Commissioner for Human Rights. Critical infrastructure operators must also notify the State Cyber Protection Centre under the Law on the Basic Principles of Cyber Security of Ukraine.

Notifying customers and partners. If third party data has been compromised, those persons must be informed within a reasonable time – delay may become grounds for damages claims.

Reporting to law enforcement. A criminal report to the police or directly to the cyber police (cyberpolice.gov.ua) records the offence, triggers investigative measures and provides the basis for action against the attacker.

How to run an internal investigation properly

An internal investigation without a lawyer carries a risk: the material gathered may be held inadmissible in court or in criminal proceedings.

  • Involve a lawyer at the first stage – they will determine which actions are covered by legal privilege and which are not.
  • Engage a digital forensics specialist to take forensic images of disks and memory.
  • Record every action with the affected system in a chronological log.
  • Preserve the original media: they may be required by the court.
  • Do not disclose details of the incident until the investigation is complete – this protects against leaks and against creating unfavourable evidence against the company.

What criminal liability can a cyber incident bring?

Criminal liability threatens not only the attackers but, in certain situations, the company as well.

Attackers may be prosecuted for unauthorised interference with computer systems (Article 361 of the Criminal Code), distribution of malicious software (Article 361-1) and unauthorised collection or distribution of personal data (Article 182).

The company or its officers may be liable if they deliberately or negligently failed to implement statutory protection measures, concealed the incident from regulators or affected persons, or destroyed evidence or obstructed the investigation.

How to minimise legal risks after an incident

  1. Make no public statements without clearing them with a lawyer.
  2. Document every response measure taken: this demonstrates the company good faith.
  3. Check your cyber insurance policy: most policies contain notification deadlines and rules on engaging with the insurer.
  4. Quantify the losses: remediation costs, lost profit, the cost of notifying customers – all of this supports a civil claim against the attacker.

Frequently asked questions

Must customers be notified of a leak of their data?

Yes, if customers personal data has been compromised. The timing and procedure depend on the circumstances, but unjustified delay may give rise to claims. Consult a lawyer to determine the scope and deadline for notification.

What does reporting to the cyber police achieve?

It opens criminal proceedings, giving investigators powers to identify the attacker and seize evidence. It is also a necessary document for insurance settlement and certain regulatory procedures.

Can the IT contractor be held liable if the breach resulted from its negligence?

Yes, if the contract provides relevant warranties or you can prove that the contractor acts or omissions caused the vulnerability. Prospects depend on the contract terms and the evidence.

What if the attacker demands a ransom (ransomware)?

Do not pay without consulting a lawyer and cyber security specialists. Payment does not guarantee restored access and may complicate dealings with the insurer and law enforcement. The priority is isolating the system and engaging specialists.

How can we protect against a repeat incident from a legal standpoint?

Once the consequences are dealt with, run a legal audit of contracts with IT suppliers, update the internal information security policy and verify compliance with personal data protection law.


Has your company suffered a cyber incident and needs legal help?

Attorney Vitalii Petryk provides legal assistance in cybercrime cases, business protection during cyber incidents and criminal proceedings in the IT field.

  • Phone: +38 (096) 878-07-36
  • Email: info@advokat-petrik.com
  • Address: Kyiv, Holosiivskyi Avenue 132, RELE Business Centre

This article is informational and is not legal advice. To assess your specific situation, contact an attorney.

Prev PostHow to recover money from online fraudsters: a step-by-step algorithm
Next PostIs messenger correspondence evidence in a criminal case?

Один коментар

Коментувати

ENG
Передзвоню за 50 секунд×