Hone

Lessons · Cybersecurity · who to tell, and when

Who to tell, and when

Telling people is part of the response, in order: the incident manager, then the asset owner, then legal and data protection if personal data is involved, then the regulator and the people affected within the deadline the law sets.

Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.

What it is for

The technical work was finished by Tuesday. The fine came for telling the regulator eleven days later, because the clock had started the moment the organisation became aware, and nobody had started counting.

How to think about it

Two lists, written before an incident: who is told inside, in order, and who must be told outside, with the deadline against each. During an incident you follow the list rather than deciding; deciding who to tell at 3 a.m. is how the wrong person hears first.

Worked example

Inside first: the incident manager, who runs the response
One person coordinating, so the same fact is not chased by four people.
Then the asset owner, who can approve taking it offline
The name from the asset register, which is why the register exists.
Then legal and data protection, if personal data may be involved
They own the outside deadlines, and they need the facts early.
Then the regulator and the people affected, inside the deadline
Counted from when the organisation became aware, not from when the work finished.

Your turn

A notification deadline is counted from the moment the organisation becomes what? Write the word.

the clock starts when the organisation becomes 

The trap

Waiting until you know everything before telling anyone. The deadline does not wait for certainty, and a first notification that says what is known so far is what the rules ask for.

Practise who to tell, and when on HoneA question on it now, a coding challenge where there is one, and it is remembered for review. Free, no email needed.