Hey everyone, long time lurker, seldom question-asker here :) I have crawled out of my hole to ask you for ideas on how to approach a puzzle I've uncovered while updating our company's cybersecurity incident response plan.
Various country and US state laws have requirements to notify if our company were to have a cybersecurity incident. You probably have heard of the EU's GDPR, California's CCPA…in total we figure we have 11 different privacy laws that apply to us, each with slightly different thresholds and requirements for notifying. Furthermore, a small number of our customers have a clause in their terms of agreement that require notification of a cybersecurity incident.
I've proposed the idea—for simplicity—of "let's just notify everyone if we get breached" but was asked if we can do this more granularly to notify only those whose laws or terms require it.
I'm thinking we should have a saved search or query we can run, if God forbid, we were to have a cybersecurity incident, and need to grab a set of contacts to notify of the incident. To pull this off, we'll need some sort of unique flag(s) to build the criteria for this contact set.
The country/state law notification is easy enough to achieve by just filtering on billto/shipto location. For customers individually requiring notification in their terms of agreement it's a little tricky and I'm brainstorming on how best to achieve this.
New custom fields would obviously work, but I don't like to customize where it might not be necessary. I'm wondering about the User Notes (notes) table being appropriate for this. We already have a custom field "User Note Category" that I think could be leveraged: create a new user note category ("Duty to Notify" - or something unique/descriptive) and then the user note memo would be where we fill in the specific notification requirements for that customer.
The only drawback I've imagined so far using the user notes table is that there's nothing to prevent duplicate "Duty to Notify" user notes from being created. We could overcome this by simply training everyone to edit the existing record if one is already in place. Of course, since a.) this only applies to a small subset of customers, and b.) changes in their terms of agreement are both unlikely and infrequent, this is probably not a big issue.
What are your thoughts? Am I overthinking this? (😊)