Data Breach vs Cyber Incident: What’s the Difference?
“We’ve had a breach.” It is one of the most over-used and misunderstood phrases in cyber security, and the confusion it causes is expensive. A blocked phishing email gets treated as a crisis. A genuine data theft gets brushed off as “just an IT thing”. Getting the words right is not pedantry, it decides whether a legal clock starts ticking and who you have to tell.
This guide untangles the terms every UK business should understand: event, alert, incident, breach and personal data breach. It is a companion to our full cyber incident response plan guide.
The ladder, from harmless to serious
| Term | What it means | Everyday example |
|---|---|---|
| Event | Anything that happens on a system. The vast majority are harmless. | A member of staff signs in from home. |
| Alert | Something a tool or a person has flagged as worth a look. | A sign-in from an unusual country. |
| Incident | An event, confirmed or suspected, that could harm your systems or data, and that you decide to respond to. | That sign-in succeeded and mailbox rules were changed. |
| Breach | An incident where a security control has actually failed and something was affected. | The attacker read and forwarded emails. |
| Personal data breach | A breach that affects personal data specifically. This is the type with legal reporting duties under UK GDPR. | Those emails contained customers’ personal details. |
The key move up the ladder is from “incident” to “personal data breach”, because that is where the law gets involved.
Cyber incident: the broad category
A cyber incident is any event that may harm the confidentiality, integrity or availability of your systems or data, or that breaches your security policy. It does not have to involve a clever attacker or any personal data at all. A server that goes down, a malware infection on one laptop, a denial-of-service attack, or a member of staff emailing the wrong file, are all incidents. Most incidents are handled entirely in-house and never trouble a regulator.
Personal data breach: the narrower, regulated one
A personal data breach is a specific kind of breach: one that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In plain terms, information about identifiable people was lost, exposed, altered or accessed when it should not have been. This is the category that can carry a duty to report to the Information Commissioner’s Office (ICO), and sometimes to tell the affected people.
Not every breach is reportable
Here is the part that trips people up. Even a genuine personal data breach does not automatically have to be reported. Under UK GDPR, you must notify the ICO only where the breach is likely to result in a risk to people’s rights and freedoms. Many minor breaches do not meet that threshold. Where the risk to individuals is high, you also have to inform the affected people without undue delay.
Two things matter regardless of whether you report:
- You must record every personal data breach and your reasoning, including why you decided a particular breach was not notifiable.
- Where you do report, you have 72 hours from becoming aware to notify the ICO where feasible. You are not expected to know everything by then; the approach is to report what you know and update later.
This is practical guidance, not legal advice. The regulatory position can change, so check the current ICO guidance and take professional advice for your circumstances. Our ICO registration guide covers the wider data-protection basics.
Worked examples
| Situation | What it is |
|---|---|
| A phishing email is reported and deleted, never clicked | A low-severity incident. Not a breach. |
| Ransomware encrypts your file server, no data taken | A serious incident and a breach of availability. Only a personal data breach if personal data was affected. |
| An attacker reads and copies customer records from a mailbox | A personal data breach. Assess whether it is reportable. |
| A laptop with an encrypted, remotely wiped drive is stolen | An incident. Likely low risk to individuals if the encryption held. |
| An unencrypted laptop holding the customer database is stolen | A likely personal data breach with real risk. Assess for reporting. |
| A staff member emails a spreadsheet of clients to the wrong person | A personal data breach, even with no attacker involved. |
Why the distinction matters in practice
Getting this right changes three things: whether a legal clock starts, who you have to tell, and how you record your decision. Treating everything as a reportable breach wastes time and can cause needless alarm; treating a real personal data breach as “just IT” can land you in regulatory trouble. The middle path is to assess each incident properly and write down your reasoning. The free Cyber Incident Response Toolkit includes a personal data breach assessment form that walks you through exactly this decision.
Want help knowing where you stand?
We can help you understand your data-protection obligations and put a simple, defensible process in place for assessing and recording incidents, so you are not making these calls under pressure for the first time during a live event.
Frequently asked questions
A cyber incident is any event that may harm your systems or data, and it does not have to involve personal data. A personal data breach is a specific type of breach that affects information about identifiable people. Every personal data breach is an incident, but most incidents are not personal data breaches.
When the incident actually affects personal data, meaning it leads to the loss, unauthorised access, alteration or disclosure of information about identifiable people. A blocked phishing email is an incident but not a breach; the same attacker reading and forwarding customer details is a personal data breach.
No. Under UK GDPR you must report a personal data breach to the ICO only where it is likely to result in a risk to people’s rights and freedoms. Many minor breaches do not meet that threshold. You must still record every breach and your reasoning, including why you decided not to report one. Always check current ICO guidance.
It starts when you become aware that a notifiable personal data breach has probably occurred, not when the attack began or when you have the full picture. You then have up to 72 hours to notify the ICO where feasible, reporting what you know and updating later. If you take longer, you must explain why.
Related reading: the full Cyber Incident Response Plan guide, what to tell customers after an incident, and the free Cyber Incident Response Toolkit.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


