Breach Governance

Structured incident response for breach detection, assessment and timely notification to the Board and affected data principals.

The Clock Starts at Detection

Breach obligations are time-bound. A defined process beats a war room trying to remember who needs to be told and by when.

Structured Intake

Capture suspected breaches from security tools, staff reports and vendor disclosures into one register.

Severity Assessment

Score impact using the data categories, volume and likelihood of harm to the data principals affected.

Notification Clock

Start the statutory timer at detection and track every deadline for Board and user notification.

Affected Party Scoping

Identify which data principals and purposes are involved by linking to the consent and data registry.

Response Playbooks

Run containment, investigation and communication steps as assigned tasks, not improvised calls.

Post-Incident Record

File the timeline, decisions and corrective actions as evidence of a reasonable response.

How Breach Governance Works

1

Detect & Log

The incident is registered with its source and detection time, which starts the notification clock.

2

Assess the Impact

Scope the data, purposes and people affected, then score severity to decide the response path.

3

Notify & Close

Issue Board and data principal notifications within the deadline, then record remediation and lessons.

Decide the Process Before the Incident

Put detection, assessment and notification on rails so a breach does not become a second compliance failure.