You’ve got MFA on your accounts, your staff have been through phishing training, your backups are running. Then you get an email from your accountancy software provider saying they’ve had a data breach. Or your payroll processor. Or the company that manages your IT. Suddenly your security posture is partly irrelevant, because somebody else’s security posture is now your problem.
Supplier and partner breaches are one of the most frustrating risks UK small businesses face, because by definition they’re largely outside your control. But how you respond to them — and how much damage you contain — is very much in your control. Here’s what to actually do when it happens.
Step One: Find Out What They Actually Had
The notification you receive from a breached supplier will often be vague. “We’ve become aware of a security incident that may have affected customer data” tells you almost nothing. Before you panic, before you notify the ICO, you need to know what data of yours the supplier actually held.
Go back to your supplier contracts and data processing agreements. Under UK GDPR, any supplier that processes personal data on your behalf should have a written Data Processing Agreement (DPA) with you that sets out what data they process, for what purpose, and how they handle it. If you’ve got that agreement, it tells you exactly what they had.
If you don’t have a DPA in place — which is unfortunately common for SMEs using off-the-shelf software subscriptions — contact the supplier directly and ask specifically:
- What categories of personal data were exposed?
- Were our customer records, employee records, or payment details included?
- What was the timeline of the breach and when was it contained?
- What specific data about our organisation was accessed?
You’re entitled to these answers. If they won’t provide them, treat the worst case as the assumption and act accordingly.
Step Two: Assess Your Exposure
Once you know what they had, work through the consequences systematically.
Customer or employee personal data exposed: Under UK GDPR, you may have a reporting obligation to the ICO even though the breach happened at a supplier, not at you — because you’re the data controller and your customers’ data was being processed under your instruction. The 72-hour clock for reporting to the ICO runs from when you become aware there’s a reasonable likelihood of a reportable breach, not from when you’ve confirmed all the details.
The NCSC’s guidance on personal data breaches distinguishes between breaches that need to be reported to the ICO (those that risk rights and freedoms of individuals) and those that don’t (data that was encrypted and the key wasn’t compromised, for example). Work through this assessment quickly. When in doubt, report — a late ICO notification is less damaging than a notification failure.
Credentials or access tokens exposed: If the supplier held login credentials, OAuth tokens, or API keys that relate to your systems, those need to be rotated immediately — before you do anything else. Don’t wait to establish the full scope of the breach first. Rotate the credentials, then investigate.
Payment details: If the supplier processed payment card data, the PCI DSS incident response obligations kick in alongside GDPR. You may need to notify your bank or card processor.
Step Three: Lock Down What You Can
If there’s any possibility that the breached supplier had access credentials to your systems — through an integration, an API, or remote access — revoke that access now.
This is where maintaining independent control of your own critical accounts pays off. If your MSP or IT supplier was breached, you need to be able to lock them out and continue operating. That requires having your own admin credentials to your domain registrar, your email platform, your cloud accounts. If you don’t have those independently, this is a problem you’ll need to address urgently — contact the relevant platforms directly to add your own administrative access before revoking the supplier’s.
Review the OAuth permissions granted to third-party applications. Go into your Microsoft 365 or Google Workspace admin portal and check which third-party apps have access to your users’ data. If the breached supplier had an app integration, revoke it. You can re-authorise it once they confirm the breach is contained and remediated.
Step Four: Notify Who Needs to Know
Your customers: You’re not always legally required to notify individual customers about a breach unless the risk to them is high, but it’s often the right thing to do and it’s always better than them finding out from news coverage. If their email addresses, payment details, or sensitive personal data were in the breach, notify them directly, tell them what happened clearly, and tell them what they should do (change passwords if credentials may have been exposed, watch for phishing, etc.).
The ICO: If you assess the breach as notifiable (meaningful risk to individuals’ rights and freedoms), report at ico.org.uk/report-a-breach within 72 hours of becoming aware. You can submit an initial report with the information you have and update it as you learn more — you don’t need to have complete information before reporting.
Action Fraud: If the breach has resulted in, or you believe may result in, financial fraud against your business or customers, report it to Action Fraud at actionfraud.police.uk. This creates a crime reference number you may need for insurance purposes.
Your insurer: If you have cyber insurance, notify them as soon as you’re aware of a potentially notifiable breach or any financial loss. Most cyber insurance policies have notification timelines (often 30–72 hours) that must be met to avoid coverage issues.
The Conversation You Need to Have With the Supplier
Once you’re through the immediate response, have a direct conversation with the breached supplier about what happened, what they’re doing to fix it, and what evidence they can provide that the issue is resolved. Specifically:
- What was the attack vector and has it been closed?
- Have they engaged external incident response support?
- Can they provide any forensic assurance about what data was actually accessed (versus potentially exposed)?
- What changes are they making to their security controls?
- Can they provide an updated penetration test or security audit report?
Whether to continue the relationship with the supplier after a breach is a judgment call — breaches happen to well-run organisations too. What matters is whether they respond transparently, take remediation seriously, and can demonstrate improved controls. A supplier who stonewalls, minimises, or sends vague communications is a different risk than one who communicates clearly and fixes the underlying problem.
What This Should Trigger in Your Own Practice
A supplier breach is a prompt to audit your third-party risk generally. Make a list of every supplier or service that holds personal data belonging to your customers or employees, or that has access to your systems. For each one:
- Do you have a DPA in place?
- Do you know exactly what data they hold and what access they have?
- Could you revoke their access within 30 minutes if you needed to?
- Do you have their security incident contact details somewhere accessible?
For most small businesses, doing this exercise reveals gaps. The time to find them is before a breach, not during one.