The 72-Hour Clock
Customers spot data exposure first; the notification clock starts with them.
The job
Treats customers' reports of seeing someone else's data as the earliest warning of a breach. Starts the notification clock at the first credible report, runs the case to a legally approved notification, and shows how often customers spot problems before internal monitoring does.
The moment
The privacy committee replays last month's data incident as a race between customers and the security team.
The first customer post about seeing someone else's data came at 21:14. The security operations centre's first alert came at 23:51.
The regulator was notified at 61 hours, with 11 hours to spare.
A counter shows that this year customers spotted problems 38 hours before the security team, across 4 incidents. The committee asks for a scheduled check of every channel.
What it does
- Confirm an exposure case and start the clock
- Page the DPO and SOC
- Draft the multilingual notification
- Send the draft to legal
- Log SOC detection and fix times
What you see
Incident stopwatch case room with a masked evidence strip, a split-lane race timeline and a cumulative lead-time counter
What it moves
How many hours earlier customers report a problem than internal monitoring detects it, and the share of incidents reported to the regulator within the legal deadline.
Built for
- Analysts & data
