On Friday 25 September, Dyfed-Powys Police published a short statement confirming that it had been hit by a cyber incident, identified on Monday 14 September, which disrupted some of its non-emergency systems. The Register had it the same day. The force says it has so far found no evidence that the public’s personal data was accessed, and it is still investigating whether the same is true for its staff.

This is not a dramatic story, and I don’t want to make it one. Nothing in the public reporting names a group, mentions a ransom or points to a leak-site listing, and nothing suggests that anyone who rang 999 in mid and west Wales that week failed to reach the police. But it carries a few lessons worth more than the headline, and the most important is about the people most incident plans remember last.

What we know, and what we don’t

Dyfed-Powys covers Carmarthenshire, Ceredigion, Pembrokeshire and Powys: just over half a million people across some 4,200 square miles, the largest police area in England and Wales, with a workforce of around 2,400 officers and staff. The force identified the incident on Monday 14 September. By the next day it was telling the public, as the Pembrokeshire Herald reported, that it was “experiencing technical difficulties impacting some non-emergency systems and services”, that online and email contact were unavailable, and that 999 and 101 still worked.

On 25 September it confirmed a cyber incident. It said its systems had been “subject to precautionary measures while specialist teams investigate”, that online and email contact were back, and that it had notified the Information Commissioner’s Office, though not when. Tarian, the regional organised crime unit for southern Wales, is running the investigation through its regional cyber crime unit, and the force has brought in cyber security specialists to help.

What we do not know is nearly everything an incident responder asks first: who, how they got in, how long they were there, whether ransomware was involved, and what “information relating to our staff” covers. I don’t know either, and I am not going to guess. Eleven days into an investigation, not knowing is usually the honest position, and the force has said as much.

The 999 lines held

Start with what the force got right, because it matters most and will get the least attention. The force says that throughout the incident, 999 and 101 kept working and emergency policing carried on. Whatever the architecture behind that, the outcome is the one the public cares about: if you needed the police in Aberystwyth or Brecon that week, you could reach them.

The force also says its systems were placed under “precautionary measures” while specialists investigated, and its online and email channels were down for a period. In my experience, that phrase usually means someone chose to take systems offline, or cut them off from each other, and to accept a visible outage rather than risk a worse invisible one. It is the right call, and plenty of boards flinch from it, because the outage makes the local paper and the threat does not.

It is worth putting the same question to your own organisation. If your email and your website were switched off tomorrow for ten days, which of the services your customers depend on would keep running? Dyfed-Powys has now answered that for its most important service, and plenty of organisations have never checked.

“Technical difficulties”

The communications are where I would have done one thing differently, and I want to be fair about it. On 15 September the public heard “technical difficulties”. On 25 September they heard “cyber incident”.

There are good reasons to say little in the first days. You often do not know what you are looking at, and it is entirely possible that on the 15th nobody knew for certain. You may not want an attacker to learn they have been spotted, and when a criminal investigation is running, the investigators may reasonably ask you to say less.

But once services are visibly offline, the attacker almost certainly knows you have noticed. From then on there is a form of words that is true on day one, still true on day eleven, and tells them nothing new. Something like this:

We are dealing with an incident affecting some of our non-emergency systems. We have taken some services offline as a precaution while specialists investigate. 999 and 101 are working normally. We will update you on Friday.

The only people a vague statement then keeps in the dark are the ones whose trust you will need later: the public, the press and your own staff. Some of the coverage has already led on the eleven days it took to confirm a cyber incident, rather than on the fact that 999 never went down. That is the cost of the first choice of words.

The staff question

The statement is crisp about the public: “At this stage, our investigation has found no evidence that members of the public’s personal data has been accessed or compromised”. It is careful about the staff. The force is “continuing to investigate whether any information relating to our staff may have been accessed or compromised”, is taking steps to protect it, “and will provide appropriate advice to colleagues if required.”

That is a fair account of where an investigation stands after eleven days, and “no evidence” is an honest phrase while you are still looking. I have no view of what the force has told its own people internally, and it may well have told them a great deal. But the public statement is the one everyone else reads, and not everyone reading it means well.

Police workforce data is not ordinary HR data. When the Police Service of Northern Ireland accidentally published the surnames, initials, ranks and roles of all 9,483 of its officers and staff in 2023, the Information Commissioner fined it £750,000 and said it was “impossible to imagine the fear and uncertainty” the breach caused. One of those affected took a job outside the police; another spent more than £1,000 on CCTV and lighting around their home.

Northern Ireland’s threat picture is its own, and I am not suggesting Wales shares it. But the regulator’s point travels. For people whose job is policing, a list of who they are and where they work is not an administrative record; it is a safety matter.

Nor does this start from a clean slate. In late July the Police National Legal Database (PNLD), a legal reference service used by police forces across England and Wales, found that attackers had stolen its data.

After the data surfaced on a criminal leak site, PNLD confirmed the theft of names, organisations and work email addresses belonging to police officers, staff and others. Investigators put the number of subscribers involved at around 114,000.

Any new dataset from any force can now be matched against that one. Breaches compound, and each one makes the next more useful to somebody.

The phishing starts when the news breaks

This is the part of the statement I would change. Advice to staff should not wait on “if required”, because the harm most likely to reach those 2,400 people in the next few weeks does not depend on what the forensics find.

It depends on the news. Once an incident is public, it becomes a pretext: the email from “IT” asking everyone to reset their password after the recent incident, the one from “HR” asking staff to confirm their bank details for the data review, the one from a “solicitor” offering to check whether you are affected. Those arrive whether or not a single staff record was touched, because the people who send them read the same headlines as everyone else.

The opportunists have already noticed. On the day of the force’s statement, a claims management company published a page inviting affected staff to register their interest in a claim. Whatever you think of that, it shows how quickly an incident becomes somebody else’s opportunity, and a phisher can copy a claims page as easily as a password-reset screen.

So the advice is required now, whatever the forensics say. It costs nothing, it cannot make anything worse, and it is the one protective step that does not have to wait for the investigation to finish.

Telling your own people first

None of this is specific to policing. Every organisation that holds data about its staff, which is every organisation, will one day have to tell those staff something uncomfortable. The shape of a good message is simple, and it is worth writing before you need it.

Tell them early, directly, and no later than you tell anyone else; nobody should learn about their employer’s incident from The Register. Tell them what you know, what you do not know yet, and the date by which you will tell them more. Then keep that date, even if the update is “no change”.

Tell them what you will never do, in words as plain as these:

We will not ask you to reset your password, confirm your bank details or log in anywhere through a link in an email about this incident. If you receive one, it is not from us.

Give them one way to check, a named intranet page or a telephone number they already know, and make it easy to report anything suspicious.

If staff data does turn out to be affected, match the support to the data. Credentials mean forced resets and a warning about reuse, and bank details mean a warning to watch accounts. Home addresses, for a police force, mean a proper conversation about personal safety, not a leaflet.

The law points the same way. Under UK GDPR, a notifiable breach goes to the ICO within 72 hours of becoming aware of it, and the detail can follow in phases. Where a breach is likely to result in a high risk to people, you must tell them directly and without undue delay, and the ICO’s guidance expects you to give them clear advice on protecting themselves.

Rehearse it before you need it

Most incident plans contain a holding statement for the press and a template for the regulator. The message to staff is often an afterthought, drafted at speed by whoever is left in the room. Write it now, while it is a template rather than a crisis, and put it into your next tabletop exercise.

You do not have to do that alone. The unit investigating this attack, Tarian’s regional cyber crime unit, offers organisations across southern Wales fully funded services, from talks for staff to immersive exercises for senior leadership teams. In southern Wales, the people who would investigate your incident will help you rehearse for it first, and they will not send you an invoice.

Elsewhere, every regional organised crime unit in England and Wales has a cyber crime unit, and the Cyber Resilience Centres offer free and affordable help. If it is happening to you now, Report Fraud, the service that replaced Action Fraud, takes calls from organisations under cyber attack on 0300 123 2040.

The point

Dyfed-Powys Police did the hardest part well. The service that matters most kept running, the force moved to protect its systems, it told the regulator, and it has not claimed more than its evidence supports.

The next part is cheaper and easier, and it is the part few organisations rehearse: tell your own people, early, what you know, what you don’t, and what you will never ask them to do. Your staff will read about your incident somewhere. Make sure the first thing they read comes from you.