An aspect of data breaches that doesn't receive enough attention is timing.
When a company discovers personal information may have been exposed, the clock should start immediately! Unfortunately, many organizations focus on investigating, validating, assessing scope, consulting with attorneys, insurers and forensic firms, all while preparing public statements, yet before informing the very people whose information is at risk.
Identity thieves don't wait for investigations to conclude.
If there is any possibility that highly sensitive data were exposed, affected individuals should be notified as soon as practical. This should be done even if all of the facts are not yet known. Additional updates can always follow as more information becomes available.
Organizations justify delays by citing the complexity of investigations. While important, people deserve the chance to immediately take action and protect themselves through actions such as freezing credit files, examining their accounts, changing passwords, and generally increasing their awareness of fraud attempts.
These steps are far more effective early rather than months, or even years, later.
There is also a broader issue of accountability.
When organizations collect and store personal information, they assume responsibility for protecting it. That responsibility should not end when a breach occurs. In many cases, the consequences of identity theft lasts for years, while the protections offered to affected individuals last only months.
Transparency builds trust. Delayed notification erodes it.
Perhaps it is time for legislators to strengthen breach notification requirements.
A few ideas worth considering:
- Mandatory disclosure within a defined timeframe once potential exposure of sensitive personal information is identified, rather than allowing indefinite delays while investigations continue.
- Multi-year identity monitoring requirements when Social Security numbers, dates of birth, financial information, or medical information are involved.
- Executive certification that affected individuals were notified promptly and completely.
- Personal liability for knowingly withholding information from affected individuals when there is evidence their information may have been compromised.
- Meaningful financial penalties for unreasonable notification delays.
The standard should be "What would we expect if it were our own information at risk?"
Until laws begin emphasizing transparency and accountability as much as data protection itself, organizations will continue to treat notification as a legal compliance exercise rather than an obligation to the people they serve and those they expect to serve them.