Hundreds of Obligations Triggered by Single Cyberattack
A new report from BreachRx highlights the complexities of modern breach reporting. When a company suffers a cyberattack, it's not just about removing the threat, it's also about managing the aftermath, which can involve hundreds of regulatory obligations.
The study models five recent breaches: Change Healthcare, Snowflake, Salesloft and Drift Salesforce campaign, 700Credit, and Salt Typhoon. It finds that the number of reporting obligations is tied to connectivity, not breach size. For example, the Snowflake shared-credential campaign produced at least 209 obligations across just three analyzed victims.
The Change Healthcare disclosure ran for over 17 months as the affected population climbed towards 192.7 million people. The report finds that the same stress points exist in all five incidents: reporting clocks overlap, facts shift after the first disclosure goes out, one company's incident becomes another's duty, and the disclosure record scatters across teams.
Stephen Garcia, CISO at BreachRx, notes that 'regulators don't punish organizations for having a hard incident. They punish them for telling an inconsistent story about it.'