Open cardosec

Case 710C40 · GRC · L5 Expert

Four Regulators, Four Clocks

Practise as: Incident drill · Interview

Live alertTuesday 09:00: ransomware has hit your company, a US-incorporated, NYSE-listed cloud provider whose EU arm is a NIS2 essential entity, and exfiltrated EU customer data. Legal asks which deadlines are already running.

Interview questionOne incident triggers GDPR, NIS2, SEC and contractual notification duties. How do you manage them in parallel?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. GDPR Art. 33: notify the lead supervisory authority within 72h of becoming aware of a personal data breach.
  2. NIS2 Art. 23: early warning within 24h of awareness of a significant incident, notification within 72h, final report in 1 month.
  3. SEC 8-K Item 1.05: 4 business days from the materiality determination, not discovery; record when and how it was made.
  4. Contracts add more: customer DPAs and SLAs often promise notice in 24-72h; processors must tell controllers without undue delay.
  5. Keep one fact base and timeline so every filing is consistent; early reports can be partial and updated as facts firm up.

If the interviewer pushes back

  • Your GDPR filing said no evidence of exfiltration; two days later the gang posts samples. How do you handle every regulator?
  • Who owns the materiality decision, and how do you stop it being delayed just to avoid starting the SEC clock?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.