risk
Failure to detect, assess, and notify breaches on time
Failure to detect, assess, and notify affected individuals and regulators of personal-data breaches within required timeframes and content (GDPR Art.33/34, HIPAA breach rule), resulting in sanctions and compounded individual harm.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- privacy
- domain
- Incident Management & Response
- Data Protection & Privacy
- Compliance, Audit & Assurance
- taxonomy
- nist-privacy-risk
- enterprise-risk
- inherent_rating
- high
Details
- risk_id
- ir-breach-notification-failure
- category
- privacy
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- nist-privacy-risk
- enterprise-risk
Source
No record-specific source URL is provided.
Connections
- UC-IR-03 — Provide channels to report events and obtain response help mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Prompt all-personnel event reporting enables timely detection, a prerequisite for meeting statutory breach-notification deadlines.
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Assessing records affected and magnitude sizes notification obligations, but the operative notification defense is UC-IR-08; assessment is an upstream input that contributes, not the notification act itself.
- UC-IR-01 — Maintain an approved incident response plan mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Plan defines communication paths and third-party/BC coordination that the downstream breach-notification chain depends on.
- UC-IR-04 — Triage, categorize, and escalate reported security events mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Validating and classifying events and declaring incidents is the assessment step that breach-notification-threshold decisions rest on.
- UC-IR-08 — Notify authorities and affected parties within deadlines mitigates Failure to detect, assess, and notify breaches on time
- strength
- primary
- rationale
- The notification matrix, statutory-window notifications to regulators/individuals, and retained evidence directly defend against late or incomplete breach notification (GDPR/HIPAA).
- UC-IR-11 — Respond to information spillage with defined procedures mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Assessing obligations triggered by the spill determines regulatory notification duties for the exposed regulated data.
- UC-DATA-15 — Record and notify unauthorized disclosures of personal data mitigates Failure to detect, assess, and notify breaches on time
- strength
- primary
- rationale
- Notifying affected subjects, regulators, and other parties within statutory windows directly counters failure to notify breaches on time.
- UC-DATA-16 — Bind third parties handling personal data to privacy commitments mitigates Failure to detect, assess, and notify breaches on time
- strength
- related
- rationale
- Routing vendors' breach notifications into incident response ensures timely detection/notification of third-party breaches.