Lessons · Cybersecurity · who to tell, and when
Who to tell, and when
Telling people is part of the response, in order: the incident manager, then the asset owner, then legal and data protection if personal data is involved, then the regulator and the people affected within the deadline the law sets.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
What it is for
The technical work was finished by Tuesday. The fine came for telling the regulator eleven days later, because the clock had started the moment the organisation became aware, and nobody had started counting.
How to think about it
Two lists, written before an incident: who is told inside, in order, and who must be told outside, with the deadline against each. During an incident you follow the list rather than deciding; deciding who to tell at 3 a.m. is how the wrong person hears first.
Worked example
Inside first: the incident manager, who runs the responseOne person coordinating, so the same fact is not chased by four people.
Then the asset owner, who can approve taking it offlineThe name from the asset register, which is why the register exists.
Then legal and data protection, if personal data may be involvedThey own the outside deadlines, and they need the facts early.
Then the regulator and the people affected, inside the deadlineCounted from when the organisation became aware, not from when the work finished.
Your turn
A notification deadline is counted from the moment the organisation becomes what? Write the word.
the clock starts when the organisation becomes
Solve one, graded on the server
The trap
Waiting until you know everything before telling anyone. The deadline does not wait for certainty, and a first notification that says what is known so far is what the rules ask for.