// THREAT DETECTION AND DATA PRIVACY TERM

Breach Notification

Breach notification is the process where organizations must inform affected individuals, and often regulatory bodies, when their personal data has been compromised in a security incident or data breach. These notifications detail what happened, what data was involved, and what steps are being taken.

Breach Notification — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

Breach notification is a mandatory regulatory compliance requirement compelling organizations to promptly inform affected individuals, supervisory authorities, and potentially the public, about security incidents involving unauthorized access, acquisition, or exposure of sensitive personal data, outlining the breach's nature, scope, potential risks, and remediation efforts, as stipulated by data protection laws like GDPR, HIPAA, and CCPA.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • Data Breach Disclosure
  • Incident Notification
  • Security Incident Reporting
  • Data Compromise Alert
  • Data Security Breach Notification

USAGE NOTE

Organizations must adhere to specific timelines and content requirements for breach notifications to comply with various data privacy laws and avoid significant fines.

DEVELOPERS

Organizations developing technology related to Breach Notification.

  • OneTrust

    Provides privacy management software, including a comprehensive incident and breach management module designed to streamline the process of assessing, managing, and reporting data breaches in compliance with global regulations.

  • TrustArc

    Offers privacy compliance solutions, including an incident management platform that helps organizations assess, respond to, and report data breaches to meet regulatory requirements.

  • Exterro

    Develops a comprehensive legal GRC (Governance, Risk, and Compliance) software platform, which includes privacy and incident response solutions that aid in managing and reporting data breaches.

  • IBM Security

    Provides a range of cybersecurity products and services, including Security Orchestration, Automation and Response (SOAR) platforms like QRadar SOAR (formerly Resilient), which automate and manage incident response workflows, including breach notification processes.

  • ServiceNow Security Operations

    Offers incident response and security orchestration platforms that help organizations manage the full lifecycle of security incidents, including automating tasks related to breach investigation and notification.

  • Splunk

    Through its Security Information and Event Management (SIEM) and Security Orchestration, Automation and Response (SOAR) solutions (Splunk Enterprise Security and Splunk SOAR), Splunk helps organizations detect, investigate, and respond to security incidents, including automating parts of the breach notification process.

  • Microsoft

    Through offerings like Microsoft Purview and Azure Sentinel, Microsoft provides data governance, compliance, and security information and event management (SIEM) solutions that help identify breaches, manage incident response, and ensure compliance with notification requirements.

RELATED TERMS IN COMPLIANCE & PRIVACY