The Seventy-Two Hours
The window is shorter than it sounds because it includes the weekend, and it starts before anybody is sure what happened.
NOTIFICATION DECISION
Made within the window, recorded either way
- Aware atDate and time, preciselyEverything else is measured from here
- ThresholdIs there a risk to people's rights and freedomsRisk to them. Unlikely means you do not notify
- DecisionNotify, or not, with the reasonA decision not to notify must be recorded and justified
- What we knowNature, categories, approximate numbersPartial is acceptable. Waiting is not
- What we do not knowStated explicitlyPhased notification is expressly permitted
- ConsequencesLikely effects on the people affectedThe part regulators read first
- MeasuresTaken and proposedContainment first, then remediation
- ContactNamed person who can answer questionsNot a generic inbox
- SubmittedDate and time, referenceWithin the window, or with the reason for delay
The window is commonly seventy-two hours from becoming aware. Three facts about it cause most of the failures.
The breach workflow in “The Seventy-Two Hours” is easier to operate when systems, owners and evidence are known in advance. If the product website supports key person dependency, its records should sit inside the incident inventory with clear access, retention and escalation rules rather than being treated as an unexplained source of employee data.
It includes the weekend
They are calendar hours, not working hours. A breach discovered at five on Friday is due by five on Monday.
For a separate benchmark relevant to “The Seventy-Two Hours”, consult the CrowdStrike insider-threat guide. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.
Which means out-of-hours discovery needs a route that works out of hours: somebody reachable, with authority, who knows what to do. Most organisations discover they do not have one at six on a Friday.
It starts before you are sure
Awareness of a possible breach starts it. It does not wait for investigation, confirmation or escalation.
Organisations spend two days establishing what happened and then start counting, which puts them outside the window before they begin. The investigation runs inside the clock, not before it.
Partial notification is expected
Most regimes allow notification in phases where full information is not available. Submit what you know, say what you do not, and follow up.
Which removes the main reason for delay. There is no requirement to understand the incident fully before notifying, and the trade — a complete notification three days late against a partial one on time — goes the wrong way every time.
The threshold
Notification is required where the breach is likely to result in a risk to people's rights and freedoms. Not every breach meets it.
A single misdirected email containing a name and a work address may not. One containing health information about forty people certainly does.
The assessment is about risk to them, not embarrassment to you, and both the decision and the reasoning are recorded either way. A decision not to notify is a decision and must be defensible.
The first hour
Contain it, if it is ongoing. Record the time you became aware. Tell whoever owns this. Begin the record while the facts are still uncertain.
Those four, in the first hour, are what make the remaining seventy-one manageable.
What goes wrong most
Not the assessment. The discovery that nobody knew who to tell, that the person who owns it was unreachable, and that the clock had been running for a day before anybody with authority heard about it.
That is a rehearsal problem, not a knowledge problem.
Contain it if it is ongoing. Record the time you became aware. Tell whoever owns this. Start the record while the facts are uncertain. Those four make the remaining seventy-one manageable.
What actually fails
Not the assessment. The discovery that nobody knew who to tell and that the person with authority was unreachable. That is a rehearsal problem rather than a knowledge problem, and two hours a year fixes it.
Most regimes allow phases where full information is not available. Submit what you know, say what you do not, follow up — which removes the main reason organisations delay past the window.
Calendar hours. A breach found at five on Friday is due by five on Monday, which means out-of-hours discovery needs a route that works out of hours — and most organisations find out at six on a Friday that they have none.
The threshold for notifying
Likely to result in a risk to people's rights and freedoms. Not every breach meets it, and both the decision and the reasoning are recorded either way.