1. What counts as a breach
Everyday examples
Most breaches are not dramatic. They happen on ordinary days, to careful people, doing routine work. Here are the situations you are most likely to actually meet.
The misdirected email
You type a name, autocomplete suggests the wrong recipient, and a message containing personal data goes to someone who should never have received it. This is one of the most common causes of reported breaches, and it happens to experienced professionals as easily as to new starters. A variant is using "To" or "Cc" instead of "Bcc" on a group email, revealing every recipient's address to everyone else.
The wrong attachment
The email goes to the right person, but the file attached is the wrong one: last month's payroll instead of the blank template, the full client list instead of the one-line extract. The recipient was correct, the data was not.
The lost or stolen laptop
A work laptop, phone, or USB stick goes missing from a car, a train, or a cafe. Whether this becomes a serious breach depends heavily on protection: a fully encrypted laptop with a strong password is a very different situation from an unencrypted device with cached files and saved logins.
Papers left on a train
Physical documents count too. Printed reports, case files, or notebooks containing personal data that are lost, left in public, or thrown in ordinary bins instead of confidential waste are breaches just as much as any digital incident.
Ransomware and account compromise
An attacker encrypts your systems, or gets into a colleague's email account through a phished password. These are the incidents people most readily recognise as breaches, but remember the earlier lesson: the accidental, low-tech incidents above are far more common day to day.
The thread connecting all of these is that none required malice from staff, and all are reportable internally the moment they are spotted. Recognising these patterns quickly is most of the skill this course teaches.
› Course contents
What counts as a breach
First response
Assessing and notifying
Learning and prevention
Putting it into practice