Upcoming Webinar

Data Breaches in Law Firms: What to Do in the First 72 Hours

Practical guidance for law firms on responding to a data breach in the critical first 72 hours, including ICO reporting, communications, evidence preservation and breach-response planning.

Data Breaches in Law Firms: What to Do in the First 72 Hours

Data Breaches in Law Firms: What to Do in the First 72 Hours

Webinar
Data Breaches in Law Firms: What to Do in the First 72 Hours

Date and Time
23 September 2026, Wednesday @ 12:00pm


Data breaches and cyber incidents can happen to any law firm. When an incident occurs, the actions taken during the first 72 hours can significantly affect the consequences for the firm, its clients and its regulatory position.

Following the first webinar in this three-part series, “Can We Use AI Safely in Law Firms? Data Protection, Compliance and Practical Guidance”, data protection expert and Spencer West Partner Kristy Gouldsmith returns to explain what firms should do immediately after discovering a suspected breach.

This practical session will explore how to assess and contain an incident, determine whether it must be reported to the Information Commissioner’s Office, decide if the affected individuals need to be told and preserve evidence for an internal investigation.

Kristy will also consider how firms should communicate with clients, employees and other affected parties without making the situation worse. She will explain the importance of clear responsibilities, accurate decision records and having an effective breach-response plan in place.

Key takeaways:

• The immediate actions firms should take after discovering a suspected breach.

• How to determine whether an incident is reportable to the ICO.

• How to decide what to tell the affected individuals

• Understanding the relevant reporting requirements and timescales.

• Common mistakes firms make when responding to a breach.

• Managing communications with clients, employees and other affected parties.

• Conducting an internal investigation and preserving evidence.

• Recording decisions and allocating responsibilities.

• Creating and testing an effective breach-response plan.

Delegates will leave with practical guidance to help their firm respond confidently while reducing legal, regulatory and reputational risk.

They will also have the opportunity to ask Kristy questions during a live Q&A session at the end of the webinar.


About the Contributor
I'm Kristy Gouldsmith, a data protection expert. I’m a solicitor who helps organisations to sort their data protection so that they can keep the trust of their customers and staff, avoid the cost and time of dealing with data breaches and create good data protection practices to enhance their business. I take care of your...

Be the first to know

Subscribe for our latest legal news in your inbox. All for FREE.