A data breach in the news usually arrives the same way. Somebody forwards you an article, the number in the headline has a lot of zeros in it, and the piece never quite says who is affected. You are left with a vague sense that you should probably do something, without knowing what.
Most of the time the honest answer is that it has nothing to do with you. Occasionally it has a great deal to do with you. Telling the two apart takes about 15 minutes and no technical skill at all.
Step one: work out whether you were ever their customer
Before anything else, answer one question. Did your company, or anyone in it, ever hand data to the organization named in the headline?
That covers more relationships than people expect. You may have been their customer. You may have been their supplier, which means your bank details and your staff contacts sit in their accounts system. You may have used a piece of software they own without knowing they own it. Somebody may have simply created an account on their website years ago with a work email address.
If none of those apply, you can stop here and go back to work. If one of them might, keep going.
Step two: find what the company itself has published
The article you read is not the source. Go to the company’s own website and look for their notice. Serious organizations publish one, usually under a heading like security incident or notice to customers, and it is the only document that will tell you three things the news coverage rarely does.
Look for the date range of the incident, so you know whether your dealings with them fall inside it. Look for the categories of information involved, because names and email addresses is a very different situation from names, dates of birth and social security numbers. And look for what they are offering, since credit monitoring is often included and is usually worth accepting.
Type their address into your browser yourself. Do not reach the page through a link in an email.
Step three: check the official lists instead of the coverage
Most American states require companies to file a breach notice with the state, and several publish those filings for anyone to read. These are the closest thing to a public record and they are free.
California’s Attorney General keeps a searchable list of every breach reported to the state, and because large companies report in many states at once, you will often find an incident there whatever state you are in. Washington and Maine publish similar directories. Searching the company’s name in one of those will tell you whether a notice was actually filed, what date it carries, and how many people it covers.
This step matters most when the news coverage is vague or when a company has said little. A filed notice is a fact. A headline is a summary of one.
Step four: check your own addresses
The last step is the one people usually do first, which is why they often do it wrong.
Have I Been Pwned lets you type in any single email address, free, and see which known breaches it appears in. It is run by a security researcher, it does not ask for a password, and it has been the reference for years.
For a business, there is a more useful version. You can have it watch every address on your own company domain rather than checking people one at a time. Watching a domain is free while fewer than 10 of your addresses appear in breaches, and costs $4.39 a month for up to 25 addresses after that. For most small companies that is the cheapest useful security purchase available.
Two rules while you are doing this. Never type a password into any site that offers to check whether it has leaked, and ignore any advertisement offering to scan the dark web for you. The genuinely useful version of that service is something your IT provider can arrange properly.
What to do, depending on what was taken
If passwords were involved
Change that password everywhere it was reused, not only on the site that was breached. The practical danger of a leaked password is that attackers try the same combination on banking, email and payroll systems, automatically, at enormous scale.
If the same password is on more than one of your accounts, that is the finding, and it is a bigger problem than the breach itself.
If payment card details were involved
Call the number on the back of the card and ask for a replacement. Do not wait for a fraudulent charge to appear. Card issuers do this all day and it costs you nothing.
If social security numbers or dates of birth were involved
This is the category that justifies real action. Accept whatever credit monitoring is offered, and consider freezing your credit file with the three bureaus, which is free and reversible. IdentityTheft.gov, run by the Federal Trade Commission, walks through the steps in order and is the right starting point.
The part nobody warns you about
Here is what actually happens to most small businesses after a breach makes the news, and it has very little to do with the stolen data.
Within days, messages start arriving that reference the incident by name. Some claim to be the breached company. Some claim to be your bank, warning you about exposure. They look plausible precisely because the event is real and because you have already read about it.
Tell them one thing: nobody legitimate will ask you to confirm anything by clicking a link in an email about a breach.
Questions to ask your IT provider
Four questions, worth asking once and then filing away.
- Would you tell me if one of our email addresses turned up in a breach, and how would you know? You are looking for an actual monitoring arrangement rather than good intentions.
- Which of our accounts still sign in with a password alone? Those are the ones a leaked password can open.
- Do we reuse any passwords across company systems? If nobody knows, that is the answer.
- When a breach like this is in the news, what do you send our staff? A provider who sends a short warning the same week is doing part of your training for free.
The short version
A breach in the news is worth 15 minutes, not a bad afternoon. Work out whether you ever gave them anything, read what the company itself published, check the official state list, and check your own addresses.
Then spend the remaining time on the part that will definitely affect you, which is the round of very convincing messages arriving next week.

