Breach Governance
Structured incident response for breach detection, assessment and timely notification to the Board and affected data principals.
The Clock Starts at Detection
Breach obligations are time-bound. A defined process beats a war room trying to remember who needs to be told and by when.
Structured Intake
Capture suspected breaches from security tools, staff reports and vendor disclosures into one register.
Severity Assessment
Score impact using the data categories, volume and likelihood of harm to the data principals affected.
Notification Clock
Start the statutory timer at detection and track every deadline for Board and user notification.
Affected Party Scoping
Identify which data principals and purposes are involved by linking to the consent and data registry.
Response Playbooks
Run containment, investigation and communication steps as assigned tasks, not improvised calls.
Post-Incident Record
File the timeline, decisions and corrective actions as evidence of a reasonable response.
How Breach Governance Works
Detect & Log
The incident is registered with its source and detection time, which starts the notification clock.
Assess the Impact
Scope the data, purposes and people affected, then score severity to decide the response path.
Notify & Close
Issue Board and data principal notifications within the deadline, then record remediation and lessons.
Decide the Process Before the Incident
Put detection, assessment and notification on rails so a breach does not become a second compliance failure.