Two Companies, Same Breach, Different Outcomes: Why the Response Was Decided Months Earlier
Editor’s Note: The gap between a breach that’s handled calmly and one that spirals into chaos rarely comes down to what happens during the incident itself. It comes down to what happened months or years earlier, before anyone knew there was a problem. That’s the thread running through a recent HaystackID® webcast, where cyber and incident response experts traded stories about the blind spots and overlooked habits that separate a controlled response from a chaotic one: knowing where sensitive data lives, understanding which regulatory clock starts ticking first, catching the one mistake that invites a threat actor back for a second visit. Some of those habits sound almost too simple to matter until the moment they’re missing. The following article follows that thread, written for legal technology professionals who may find themselves on either side.
Two Companies, Same Breach, Different Outcomes: Why the Response Was Decided Months Earlier
By HaystackID Staff
A company gets hit by ransomware. Teams race to get the company’s systems back online within days and close the incident. Weeks or months later, the same attacker comes back, this time harder, because the company failed to rotate the credentials the first time. It’s a pattern Michael Sarlo, HaystackID’s Chief Innovation Officer, has seen play out more than once: organizations mistake a fast recovery for a finished one.
It’s also the kind of gap Sarlo had in mind when he opened a recent webcast with a simpler question: two companies suffer the same kind of breach; one handles it calmly, and the other is chaos. What did the first organization do months or years earlier that the other skipped?
One answer starts before the breach ever happens, with something that sounds almost too basic to matter: knowing where your own sensitive data resides.
When “We Know Our Data” Turns Out to Be Wishful Thinking
Ask a security team where their organization’s sensitive data resides, and you’ll typically get a partial answer built around the systems everyone already knows about, including the HR platforms, CRM databases, and commonly used repositories.
“If you ask your cybersecurity team where critical sensitive data is, I bet you’ll get different answers from all of them,” said Nate Latessa, Chief Revenue Officer of HaystackID, sharing that some team members will share where the PII is located. In contrast, others will focus on major data systems like Workday.
“Those systems obviously contain a lot of data,” Latessa added. “There are other places in the organization where [that data exists]; it’s a blind spot. They’re not monitoring this stuff. They’re not looking for it because they don’t really have the tools to do that proactively.”
That blind spot becomes expensive the moment an incident starts. Often, the first substantive question that anyone asks is what was taken. And that answer depends entirely on already knowing where information was kept. Data governance isn’t just a compliance obligation; it’s a speed advantage: understanding retention, ownership, and location before a breach turns a slow, expensive investigation into a fast, defensible one.
When working with clients during an active incident, Gabe Landau, Senior Vice President – eDiscovery & Incident Response Solutions, HaystackID, finds that many enterprises don’t know what is in their data.
“They’re relying on custodial interviews, and oftentimes the information that we’re getting is only top-line,” he said. “And what we’re seeing in the data doesn’t match their expectations because humans are humans, and people say things and create information.”
Anya Korolyov, Executive Vice President of Cyber and LDI Strategy at HaystackID, sees the same oversight from a different angle: companies that think they know their environment until an acquisition complicates the picture.
“Many times, we deal with companies that know their data so well,” she said. “The one thing that they forgot is they acquired five other companies, and they haven’t had a chance to map out their data, and they haven’t had a chance to take inventory of that data. So they have no idea what’s in there.”
Her advice to those clients, delivered mid-incident more often than anyone would like: “Let us map the data for you and do a full overview of your data that you can use later.”
Custodial interviews weren’t built for petabyte-scale environments, where sensitive information sprawls across systems no interview script was designed to surface. Taken together, what Latessa, Landau, and Korolyov describe from three different vantage points is a shared conclusion: an organization’s account of its own data is only as reliable as the classification systems behind it, and in their experience, that’s the piece most often missing.
Preparation Isn’t a Binder, It’s a Decision Structure
The instinct to prepare for a breach usually produces a document, a playbook, a flowchart, or something dense that sits untouched until the day it’s needed and then can’t be found fast enough. During the discussion, Sarlo put a fine point on why that instinct falls short, boiling his advice down to “practice, practice, practice” and warning against leaving people “trapped in a 200-page playbook that doesn’t do anything.”
The organizations that stay composed under pressure didn’t write a more detailed document; they resolved a set of human questions long before any alert fired. This entailed items like:
- Who has authority to act?
- Who gets called at 2 a.m.?
- Who signs off before the board hears anything?
That list is notable for what it leaves out. None of it is about detection tools or response technology; it’s entirely about who decides what, and how fast that decision travels through the organization. A breach doesn’t wait for an org chart to sort itself out, so the companies that move fastest are the ones who settled those questions when nothing was on fire.
Testing matters as much as writing. Landau pushed back on the idea that a plan is worth much until someone has run it.
“It’s not just checking the box that you have backup tapes or some backup systems that you could restore, but testing them regularly to make sure they work,” he said.
Landau’s point is the gap between having a plan and having tested one, and a backup that exists on paper isn’t the same as a backup an organization has confirmed it can restore under pressure.
Compliance on a Countdown
Every regulatory regime a breach might touch comes with its own deadline, and none of them are generous. Sarlo laid out the range bluntly: public companies face a four-day SEC window, and only after determining whether the breach is even material. New York’s financial regulator and the EU’s GDPR both allow 72 hours. The FTC gives non-bank financial institutions 30 days.
That’s a harder problem than it sounds, because the clock’s start date is rarely obvious in the moment. Landau pointed to counsel as the party best positioned to make that call. In his view, deciding when the clock starts is itself a real strategic decision, not a formality to sort out later. Get it wrong, and an organization can spend weeks operating against the
The practical fix, according to Landau, isn’t more legal review; it’s faster visibility. Investigators need a quick read on what’s potentially affected early on, because the analysis has to keep pace with the shortest applicable deadline, not the longest. That feedback loop between counsel and the forensics team has to stay open continuously, with check-ins sometimes happening several times a day. A jurisdictional footprint that looks simple at first—customers in just one state, for instance—tends to widen once the data mining gets underway.
The Paper Trail That Becomes Institutional Memory
Documentation rarely feels urgent in the middle of a crisis. Korolyov argued that instinct can reverse the timeline. The record matters immediately, not just months later. Korolyov pointed out that IT teams, forensics vendors, corporate counsel, and the board absorb updates on different timelines, in different languages, often within the same hour.
That record does something more than satisfy auditors later on. Latessa framed it as protection against a very specific kind of hindsight bias: the tendency, months down the line, to judge an early decision by information nobody had yet.
“What you knew at 9:00 AM on the day of a breach could be very different by 4:00 PM,” he said, and a decision that looked sound in the morning can look questionable by afternoon. This isn’t because anyone made a mistake, but because the decision reflected the information available at that time. Six months out, Latessa added, nobody remembers what happened at 2 a.m.; the decision log is what remembers it for them.
The danger isn’t only that documentation gets skipped; it’s that evidence gets destroyed by the very effort to move fast. Teams eager to remediate sometimes wipe systems clean before anyone has confirmed what an attacker touched, and that instinct backfires: without evidence to narrow the scope, organizations end up assuming the broadest possible population was affected. Preservation, in other words, isn’t a forensics footnote. It’s the difference between a notification list built on facts and one built on worst-case guesswork.
Where Cyber Response Meets eDiscovery
At some point in every serious incident, the forensic questions give way to a different kind of question entirely: who was affected, and can you prove it? That shift is where cyber response quietly turns into something eDiscovery professionals would recognize instantly: collecting data, processing it, extracting what’s sensitive, and building a list that will eventually go out the door as a notification letter. Korolyov has watched that process surface problems companies didn’t know they had, especially after acquisitions where an absorbed company’s data was never properly mapped in the first place.
What’s changed, according to Landau, isn’t the process so much as who’s checking it. A notification list used to be the finish line; now it’s the start of a different kind of scrutiny.
“Gone are the days of just a notification list,” he said. “Now it’s regulators, very sophisticated regulators or aggressive plaintiff counsel, questioning how you arrived at that notification list.”
The list itself matters less than the ability to defend how it was built: the deduplication, the normalization, the quality checks along the way.
Generative AI (GenAI) has changed the economics of that defense. Sarlo estimated, from his own casework, that pairing AI-driven extraction with human review has cut completion times by roughly half, and Korolyov has seen real gains on the documents that used to slow reviews to a crawl, like bad PDFs, handwritten records, and structured data buried in free-text fields nobody wanted to touch by hand.
The Mistake That Invites a Repeat Visit
Getting a business back online fast used to be the hard part of a breach. Sarlo noted that’s largely solved now: replicated infrastructure, backups that spin up quickly, cloud operations that recover in hours instead of days. But that speed has created a new failure mode: organizations come back online so fast that they skip the harder question of how long an attacker was actually inside.
The assumption that follows is almost always wrong in the same direction.
“They assume the dwell time is short. They assume there’s no exfiltrated data,” Sarlo said, when in fact, by his account, “most cyber incidents of significance that occur come with some type of data exfiltration these days.”
Confirming operations are stable isn’t the same as confirming the attacker is gone, and treating those two facts as one is where the real damage starts.
What follows from that assumption is the mistake Sarlo calls out most bluntly: skipping credential rotation because the systems are already back up and running.
“They do not rotate all their security keys fast enough,” he said, and the consequence isn’t hypothetical. It’s the threat actor returning weeks or months later to hit the same organization again, this time harder. Recovery, in other words, isn’t finished when the lights come back on. It’s finished when every key the attacker might have touched has been changed, and that step is the one organizations are most likely to treat as optional.
A Simple Answer, Rarely Taken
The question that closed the panel wasn’t really about breaches — it was about time. Given one thing to fix before the next incident, none of the three panelists reached for a tool or a vendor. Landau’s answer amounted to two words: classify the data. Korolyov’s was just as spare—documentation, she said, is everything. Latessa stepped back from the specifics and named the pattern underneath them: the mistakes that drive up exposure rarely come from anyone failing to work hard during the crisis itself. They come from the absence of governance, data visibility, and decision-making structure that should have existed long before anyone knew there was a problem.
That’s a harder answer to act on than a product purchase, because it asks an organization to spend real effort on a crisis that hasn’t happened yet—to build the map before there’s a reason to need it.
None of that is a hard sell to anyone who’s lived through one of these incidents. The harder sell is to the organization that hasn’t yet; the one where a breach still feels theoretical enough that data classification loses to whatever’s due this quarter, and a tested incident response plan loses to whatever’s due this week. The panel’s real argument wasn’t about breach response at all. It was about which items get treated as urgent before there’s a reason to.
But the alternative shows up in the numbers this panel described all conversation long: the notification list that takes months instead of weeks, the coverage an insurer won’t honor because the wrong vendor got called first, the threat actor who returns because the keys never got rotated. None of that gets decided during the breach. It gets decided on an ordinary Tuesday before it, by whether anyone bothered to ask where the sensitive data lives.
About HaystackID®
HaystackID® solves complex data challenges related to legal, compliance, regulatory, and cyber requirements. Core offerings include Global Advisory, Cybersecurity, Core Intelligence AI™, and ReviewRight® Global Managed Review, supported by its unified CoreFlex™ service interface and eDiscovery AI® technology. Recognized globally by industry leaders, including Chambers, Gartner, IDC, and Legaltech News, HaystackID helps corporations and legal practices manage data gravity, where information demands action, and workflow gravity, where critical requirements demand coordinated expertise, delivering innovative solutions with a continual focus on security, privacy, and integrity. Learn more at HaystackID.com.
Assisted by GAI and LLM technologies.
SOURCE: HaystackID
Advisory Note: The pressure to contain a breach fast and the obligation to document that response defensibly often pull in opposite directions. Closing that gap is where most of the real risk in incident response actually lives. HaystackID® Global Advisory brings together the practices this work requires under one roof: Cyber Discovery and Incident Response for forensics, data mining, and notification workflows; Privacy and Compliance for regulatory exposure across jurisdictions; and Information Governance for the data mapping that should happen long before a breach makes it urgent. Rather than treating speed and defensibility as a tradeoff, these practices are built to deliver both at once, so legal and incident response teams aren’t left choosing between moving fast and building a record that holds up later. Organizations looking to close that gap in their own environment can connect with HaystackID’s team of experts to learn more.