The transferring of data, whether internally or to external recipients, carries additional security risks. Employees must therefore:
You should never assume that internal or external messages are necessarily private and confidential, even if marked as such. The Internet is not a secure means of communication and third parties may be able to access or alter messages that have been sent or received. So do not send any information in an email which you would not be happy being publicly available. The confidentiality of internal communications can only be ensured if they are sent by internal post or delivered personally by hand or included in a password protected online document.
Other indicators can include multiple failed login attempts, logins from unexpected geographic locations, creation of unexpected new accounts, unsolicited or suspicious emails, defaced or altered website content, customers reporting pop-ups or redirects, unexplained data deletions and persistent sluggish performance, overheating, resource spikes or connection of unauthorised devices to corporate systems.
Reports of suspected cyberattacks should include a clear description of what was observed, date and time of the occurrence, systems and/or applications and/or data affected, any recent actions performed by the user (e.g. downloads, emails opened, websites visited).
If an incident is considered to pose an operational or regulatory risk, it should also be reported to the DPM.
| Classification | Description | Typical Examples |
| Low | Minor or localised disruption, quickly contained with no data compromise | Localised malware, isolated phishing attempt |
| Medium | Disruption with potential data exposure or operational impact; further analysis required | Compromised credentials, unauthorised access to non-personal data |
| High | Confirmed or suspected data breach, ransomware infection, or significant operational disruption | System-wide malware outbreak, data infiltration, denial-of-service attack |
| Critical | Major incident affecting essential systems, large-scale data loss, or national regulatory impact | Catastrophic service outage, confirmed personal data breach of high risk to individuals |
Recovery will restore normal operations through verification of system integrity and patching, restoration from clean verified backups, validation testing to confirm systems are secure before reconnecting to the network, and ongoing monitoring for recurrence for a defined post-incident period (e.g. 30 days).
| Record Type | Purpose/Description | Minimum Retention Period | Responsible Team/Role | Disposal or Review Method |
| Incident Reports and Notifications | Initial and follow-up reports submitted via the Cyberattack Reporting Procedure, including internal alerts and external notifications to regulators, insurers, or law enforcement. | 6 years from closure or final contact. | Eg CIO or DPM | Secure destruction or anonymisation post-retention; extend if proceedings continue. |
| Incident Response Reports and Case Files | Full documentation of cyber or data security incidents. | 6 years from date of incident or closure. | Eg DPM | Secure destruction or anonymisation post-retention period; retain longer if legal action is ongoing. |
| Containment and Recovery Logs | Records of immediate containment, isolation, and recovery measures (e.g. network segmentation, credential resets, patching). | 6 years from incident closure. | Eg CIO | Secure deletion after review; extend where analysis or follow-up required. |
| Investigation and Analysis Notes | Forensic investigation materials, timelines, and analyst notes documenting attack vector, scope, and impact. | 6 years | Eg CIO | Secure destruction or anonymisation after retention. |
| Forensic Artefacts and Evidence Images | Disk images, packet captures, malware samples, and other evidential artefacts preserved for potential legal or regulatory use. | 6 years or until all matters concluded (whichever longer). | Eg DPM | Cryptographic wipe under chain-of-custody supervision; destruction logged. |
| Incident Register | Master log of all incidents, classifications, actions, decisions, and outcomes. | Permanent record (retain indefinitely or archive after 10 years). | Eg DPM | Secure archival storage; periodic review every 5 years. |
| External Communications (Customers, Regulators, Insurers, Law Enforcement) | Official notices, correspondence, and press statements related to the incident. | 6 years. | Eg DPM | Secure destruction post-retention; extend if proceedings ongoing. |
| Third-Party Communications and Contracts | Supplier and partner correspondence, SLAs, and remediation or forensic vendor documentation. | 6 years after incident resolution / contract termination. | Eg Legal Counsel | Secure deletion or anonymisation post-retention. |
| Post-Incident Review Reports and Improvement Plans | Lessons-learned documentation, review minutes, and corrective-action tracking following incident closure. | 6 years. | Eg DPM | Secure deletion or anonymisation after retention; archive summary for audit trail. |
| Audit and Compliance Reports (Security, Technical, Governance) | Independent or internal audit reports confirming control effectiveness or remediation. | 6 years from report date. | Eg DPM | Secure destruction or anonymisation after retention period. |
| System and Network Logs | Logs evidencing system activity, intrusion detection, and forensic reconstruction. | 12 months minimum (extend for investigations). | Eg CIO | Secure deletion or anonymisation following review and closure. |
| Access Control and Authentication Logs | User log-ins, privilege changes, and access attempts for accountability verification. | 12 months. | Eg CIO | Secure deletion or anonymisation; extend where required for analysis. |
| Backup and Recovery Logs | Confirmation of backup success, integrity, and restoration testing. | 6–12 months depending on system criticality. | Eg CIO | Secure deletion / overwrite after scheduled rotation. |
| Cybersecurity Training and Awareness Records | Evidence of completion of training and awareness programmes for all staff and contractors. | Duration of employment + 6 years. | Eg CFO | Secure destruction post-retention; extend for legal / disciplinary cases. |
| Disciplinary and Employee Investigation Records (Cybersecurity Related) | Employee investigations into misuse, negligence, or policy breach. | Duration of employment + 6 years. | Eg CFO | Secure destruction or anonymisation post-retention; extend if active case. |
| Security Awareness Testing and Phishing Simulations | Results of staff testing to measure cyber awareness and resilience. | 3 years. | Eg CFO, DPM, CIO | Secure deletion or anonymisation after retention. |
| Simulation Results | Records from incident-response simulations or readiness exercises. | 3 years. | Eg CIO | Secure deletion after retention; retain summaries for training records. |
| Insurance Claims and Correspondence | Notifications, claim forms, and insurer communications arising from a cyber incident. | 6 years from claim closure. | Eg Legal Counsel | Secure destruction post-retention; extend if dispute continues. |
| Financial and Sanctions Checks (SAMLA 2018) | Evidence of sanctions and AML checks performed before authorising payments (e.g. ransomware or vendor fees). | 6 years. | Eg Legal Counsel | Secure destruction after retention; retain audit confirmation. |
| Terrorism Act 2000 / Proceeds of Crime Act 2002 Reports | Records of Suspicious Activity Reports or communications with NCA under terrorism or proceeds-of-crime legislation. | 6 years from submission or closure. | Eg Legal Counsel | Secure archival storage; destruction after retention with NCA clearance. |
| Legal Advice and Opinions | External or internal legal advice obtained during incident response. | 6 years from closure. | Eg Legal Counsel | Secure destruction post-retention; retain privileged copies with secure access |
CSCSP 10/2025