Establish what actually happened, take advice where personal information is involved, then tell affected people plainly and early. Silence discovered later does more damage than the incident.

The situations this covers

Wider than a dramatic breach, and most of them are ordinary mistakes.

A compromised website. An email sent to the wrong person. A list of addresses in the visible field rather than blind copied. A lost laptop or phone. A file left somewhere it should not have been.

Most incidents at small businesses are the middle two, and they happen to careful people on busy afternoons.

What follows is general rather than legal advice, and anything involving customer information genuinely warrants a conversation with somebody qualified.

Establish what happened first

Before deciding anything, understand the scope.

What information was involved. Whose. How many people. Whether it was actually accessed or merely exposed. Whether it is recoverable.

That takes an hour or two and it determines everything that follows, including whether notification is required or simply advisable.

Do not announce before you know, because a correction to your own announcement is considerably worse than a slightly later first message.

Equally, do not spend a week establishing certainty. A day or two is reasonable; a fortnight is a delay somebody will ask about.

Whether you have to tell anybody

There are legal obligations here, and they turn on the nature of the information and the risk of harm.

Federal privacy law requires notifying affected individuals and the Privacy Commissioner where a breach of security safeguards creates a real risk of significant harm.

What counts as significant harm covers more than financial loss: humiliation, damage to reputation or relationships, and identity theft among others.

Record-keeping obligations apply to breaches even where notification is not required, which surprises people.

The threshold is a judgement, and it is exactly the judgement worth getting advice on rather than deciding alone.

A worked example

A business that sent a mailing to about two hundred customers with every address in the visible field.

Nothing sensitive was disclosed beyond the addresses themselves, and the recipients were a mixture of domestic and commercial customers.

The instinct was to say nothing and hope nobody noticed.

They sent a short message instead, within two hours, saying what had happened, apologising, asking recipients to delete the earlier message, and confirming that no other information had been disclosed.

Four people replied, all of them positively. Nobody complained.

The owner's view afterwards was that the second email was uncomfortable to send and considerably less uncomfortable than being asked about it a week later.

What the message should say

  1. What happened, plainly, in the first sentence.
  2. What information was involved.
  3. When it happened and when you found out.
  4. What you have done about it.
  5. What they should do, if anything.
  6. How to reach a person with questions.

The fifth is what people actually want. Somebody told their information was exposed wants to know whether to change a password or watch a bank account.

The sixth should be a named person and a real address, not a form, because this is the one message where somebody may genuinely need to speak to you.

How quickly to say it

Sooner than feels comfortable, and later than immediately.

A day or two, once you understand the scope, is a reasonable position for most small business incidents.

Within hours is right where somebody needs to act urgently: a password to change, a payment to stop, a message to delete.

Beyond a week, the delay itself becomes part of the story, and it is the thing you will be asked about rather than the incident.

Where the assessment is genuinely taking longer, an interim message saying what you know and that more will follow is better than silence while you find out.

Tone

Direct, brief, and without the language that makes these messages notorious.

Avoid describing it as an incident involving a limited number of records. Say what happened.

Avoid emphasising how seriously you take security in a message explaining that security failed.

Apologise once, properly, and then get on with the practical content people actually need.

And do not bury it inside a longer message about something else, which reads as an attempt to hide it and is always noticed.

The counter-case

Where telling everybody is not the right response.

Where the incident affected one person, in which case a personal message is better than a general announcement that alarms two hundred people unnecessarily.

Where the exposure was genuinely trivial and no personal information was involved, such as a broken page or an internal document.

And where an investigation is ongoing and premature disclosure would interfere, though that is rarer for a small business than it sounds and is not a reason for indefinite silence.

What is never right is deciding not to tell people because it would be embarrassing, which is the actual reason behind most silence.

What happens if you say nothing

Worth thinking through, because it is the alternative being weighed.

The incident becomes known anyway, frequently through somebody affected noticing something, and the story is then about the concealment rather than the mistake.

Customers who would have accepted an early apology react quite differently to discovering it was withheld.

And where notification was legally required, not doing it is a separate failing from the breach itself.

The asymmetry is severe: telling people early costs a period of embarrassment, and not telling them costs trust that does not come back.

Who to tell besides customers

Frequently overlooked in the focus on the affected individuals.

Your insurer, if you have cover that might respond, because most policies require prompt notification and late reporting can affect a claim.

Your bank, where anything financial was involved.

Any supplier or partner whose systems connect to yours, since a compromise of yours may reach them.

And anybody in the business who might receive a question about it, so that a customer phoning does not reach somebody who knows nothing.

That last one is the most commonly missed and the one that produces the worst impression, because a business whose staff have not been told looks like a business hiding something.

Afterwards

Two things worth doing once it is resolved.

Record what happened, when, what was affected and what you did, whether or not notification was required. That record is expected and it is useful.

And change whatever allowed it. An address disclosure caused by using the wrong field is fixed by a process change, not by resolving to be careful.

Most small business incidents turn out to be process problems rather than technical ones, and the fix is usually a checklist rather than a system.

Knowing what you hold in the first place is covered in where customer records ended up.


Frequently asked questions

What situations does this cover?

Wider than a dramatic breach. A mistaken email, addresses in the visible field, a lost phone, or a file left somewhere it should not have been.

What should I do first?

Establish what happened: what information, whose, how many people, and whether it was accessed or merely exposed. That determines everything else.

Do I have to tell anybody?

Federal privacy law requires notification where a breach creates a real risk of significant harm, which covers more than financial loss. Record-keeping applies even where notification does not.

What should the message say?

What happened, what information was involved, when, what you did, what they should do, and how to reach a real person.

What tone should I use?

Direct and brief. Avoid describing it as an incident involving limited records, and avoid emphasising how seriously you take security in a message about security failing.

What if I say nothing?

It usually becomes known anyway, and the story becomes the concealment rather than the mistake. Customers who would have accepted an apology react differently to discovering it was withheld.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Something went wrong and you are deciding what to say?

Early and plain nearly always costs less than discovered later, and the practical content matters more than the apology.

Start a Conversation