Cyberattacks Now Trigger Hundreds of Complex Reporting Obligations
A recent study from BreachRx, a cybersecurity incident-response-management vendor, has shed light on the complexities of breach reporting. The research models five recent breaches and reveals that a single cyberattack can trigger hundreds of breach reporting obligations, often before the facts are even stable.
The report finds that the number of obligations tracks connectivity, not breach size. For instance, Snowflake's shared-credential campaign generated at least 209 obligations across just three analyzed victims, while the Salesforce token cascade produced over 300 obligations across a handful of connected organizations.
The study also highlights the issue of overlapping reporting clocks and shifting facts after the first disclosure goes out. In the case of Change Healthcare's breach, the disclosure ran for over 17 months as the affected population climbed to 192.7 million people.
To mitigate this problem, BreachRx recommends building a live obligation map and shared deadline ledger, which can help teams coordinate their response plans more effectively. The vendor also suggests assigning one person to enforce fact consistency and logging the rationale for every filing.