Case E4A0A3 · GRC · L3 Applied
Payroll Vendor Breach Notice
Practise as: Incident drill · Interview
Live alertFriday 6pm: your payroll SaaS vendor emails that an attacker accessed their customer database, including your employees' names, SSNs and bank details.
Interview questionA critical vendor tells you they were breached and your employee data was taken. How do you respond?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Open an incident; loop in legal, privacy, HR and comms. Preserve the vendor notice and request IOCs and a timeline.
- Cut exposure: rotate API keys/SSO certs to the vendor, review integration logs for anomalous pulls or logins.
- Confirm scope: which records, which fields, date range. Map to state breach laws and any GDPR notification duty.
- Protect people: notify employees, offer credit monitoring, warn about payroll-diversion phishing targeting them.
- Afterwards: invoke contract clauses (notice SLA, costs), reassess vendor tier, and document in the risk register.
If the interviewer pushes back
- The vendor says it cannot confirm whether your tenant was affected. Do you notify employees anyway? Why?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.