risk

Failure to detect, assess, and notify breaches on time

Failure to detect, assess, and notify affected individuals and regulators of personal-data breaches within required timeframes and content (GDPR Art.33/34, HIPAA breach rule), resulting in sanctions and compounded individual harm.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

category
privacy
domain
  • Incident Management & Response
  • Data Protection & Privacy
  • Compliance, Audit & Assurance
taxonomy
  • nist-privacy-risk
  • enterprise-risk
inherent_rating
high

Details

risk_id
ir-breach-notification-failure
category
privacy
likelihood
medium
impact
high
inherent_rating
high
treatment
mitigate
taxonomies
  • nist-privacy-risk
  • enterprise-risk

Source

No record-specific source URL is provided.

Connections