irp pt 3 no it strategy llc

By Nate Olson, Fractional IT Director & vCIO | N.O. IT Strategy LLC

The Clock You Don't Know Is Running. Data Breaches and Your Incident Response Plan. (Part 3)

A data breach is the rare disaster that can be completely over before you know it started. The attacker is gone, the files are already copied and nothing on your screen looks broken. You find out from someone else, a customer, your bank, law enforcement or a researcher who found your data for sale.

By then it has usually been a while.

On average it takes 241 days to identify and contain a breach, and 181 of those days are spent just noticing it happened. That’s most of a year with someone quietly carrying your data out the door.

The moment you discover the breach, a legal clock starts, and the law requires you to beat it. Let me show you what that means. Say an employee’s email gets phished. The attacker sits inside the account for a few months, reading, downloading and learning your business. Eventually they pull a file of customer records, names, addresses, payment details or financial information.

You find out when a customer calls about a fraudulent charge, or when a forensics firm finds the theft during unrelated cleanup. The technical problem might be solved in a day. You reset the password, lock the account and close the hole. If solving the technical problem were the end of it, you would move on.

But a data breach doesn’t work that way.

There’s a newer version of this that may not involve an attacker breaking in at all.

One of your own people, trying to move faster, pastes a customer list, contract, financial report, client file or chunk of source code into an unsanctioned AI tool to summarize it, clean it up or turn it into something useful. Nobody broke in. Nobody bypassed MFA. But company data just left your environment and went to a system you do not control. Depending on the tool, settings and contract terms, that data may be retained, reviewed or used in ways you never approved. You may have no log of it, no alert that it happened and no practical way to pull it back.

That is why shadow AI belongs in an incident response conversation.

IBM’s 2025 study found that 1 in 5 breaches involved shadow AI, the tools employees adopt without approval or oversight. Those incidents were more likely to expose customer personal information, 65% of the time versus 53% for breaches overall. Companies with high shadow AI use saw about $670,000 added to the cost of a breach. And 97% of businesses that reported an AI-related security incident lacked proper AI access controls.

Here’s the trap.

With stolen records, the law is clearer and the clock is more obvious.

With an employee pasting data into a chatbot, it may be murkier whether you have triggered a notification law at all, and that uncertainty is exactly what sinks businesses. You cannot investigate, notify or defend a disclosure you never knew happened.

A plan that maps your data and sets rules for which tools are allowed to touch it is the only reason you catch this before it becomes the kind of breach that does start the clock.

Every state has a breach notification law, all 50 of them, plus DC and the territories. There is no single federal standard, so you do not get to follow one rule. You follow the rule of every state where your affected customers live, all at the same time.

Roughly 20 states now set a hard deadline, commonly 30, 45 or 60 days from discovery. California joined the 30-day group on January 1, 2026, making it one of the strictest breach-notification states in the country. For breaches requiring notice to more than 500 California residents, you also have to submit a sample notice to the Attorney General within 15 calendar days of notifying affected consumers.

New York and Florida also run on 30-day timelines. Other states use language like “without unreasonable delay,” which sounds flexible right up until a regulator decides your delay was unreasonable.

If you handle financing, leasing, tax preparation, mortgage activity or other covered financial services, the clock may also be federal.

The FTC Safeguards Rule requires covered financial institutions to report certain breaches involving at least 500 consumers to the FTC no later than 30 days after discovery. That can include businesses that do not think of themselves as financial institutions at all, such as auto dealers that arrange financing, mortgage brokers, tax preparers and others.

If you are in healthcare, HIPAA gives you no more than 60 calendar days.

So here is the breach without a plan.

You have contained the technical problem, and now a legal clock is running on deadlines you did not know existed. You do not have a clean record of what data you held or where it lived, so you cannot say who was affected. You do not know which states your customers are in, so you do not know which deadlines apply.  You are calling a lawyer you have never met to ask questions you should have answered a year ago, and every day you spend figuring it out is a day off the clock.

Florida alone can assess escalating penalties for late notice, up to $500,000 for a single breach. And that is before the first class action lands.

Here is the same breach with a plan.

You already know what data you collect and where it sits, because you mapped it before anything went wrong. You know which states your customers live in. You have a breach coach and a forensics firm named in the plan, not hunted down in a panic. The clock is still running, but now it’s a process you rehearsed instead of a problem you’re meeting for the first time during the worst week of your year.

This is where the numbers stop being abstract.

IBM puts the average breach at $4.44 million globally and $10.22 million in the United States. Those costs are not just technical cleanup. They include detection, escalation, legal review, notification, regulatory exposure, customer response, lost business and post-breach recovery.

That is the whole argument for the plan.

It is not a binder.

It is a rehearsal for a clock you cannot stop and cannot ignore.

If you do not know what data you hold, where it lives, who is responsible for it and who you call when the clock starts, your incident response plan is not finished.

That’s Part 3.

In Part 4, the last one, I’ll show you where your incident response plan hands off to your disaster recovery plan, the difference between stopping the bleeding and actually getting back in business.

Containing a breach and reopening your doors are two different jobs, and you need both.

Sources: IBM Cost of a Data Breach Report 2025. FTC Safeguards Rule breach notification amendment, 16 CFR 314, effective May 13, 2024. California Civil Code 1798.82 as amended by SB 446, effective January 1, 2026. New York General Business Law 899-aa. Florida Statutes 501.171. HIPAA Breach Notification Rule, 45 CFR 164.404.