Discussions
How do you track "duty to notify" in incident response?
Hey everyone, long time lurker, seldom question-asker here :) I have crawled out of my hole to ask you for ideas on how to approach a puzzle I've uncovered while updating our company's cybersecurity incident response plan.
Various country and US state laws have requirements to notify if our company were to have a cybersecurity incident. You probably have heard of the EU's GDPR, California's CCPA…in total we figure we have 11 different privacy laws that apply to us, each with slightly different thresholds and requirements for notifying. Furthermore, a small number of our customers have a clause in their terms of agreement that require notification of a cybersecurity incident.