ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Field note / breach record

Give counsel facts that can support the notice analysis

Who accessed what, through which identity, during which period, and with what evidence is a technical question before it becomes a legal conclusion.

Incident response decision sequence covering authority, containment, evidence, recovery, and communications
Technical fact development supplies counsel with a documented event, data, and containment chronology.

The SHIELD Act changed New York's data-breach and reasonable-safeguard framework. Counsel determines whether an event meets a legal definition and what notice is required. Responders should preserve the facts needed for that decision while containment and recovery are still underway.

Separate system compromise from data access

A compromised account or host establishes risk, not necessarily access to every record the system could reach. Analysts identify the affected identity, privileges, systems, data stores, queries, file events, mailbox activity, transfer methods, staging, exfiltration indicators, and log coverage. The report states where evidence supports access, where it supports acquisition, and where available telemetry cannot distinguish the two.

Build the population carefully

If data was accessed, the team identifies the repositories, record types, fields, affected period, ownership, deduplication method, encryption state, and confidence in the count. Assumptions are listed. A preliminary estimate should not harden into a final population without reconciliation.

  • Initial access, persistence, privilege, and activity window
  • Affected systems, repositories, backups, and synchronized copies
  • Personal-information fields present in the accessed material
  • Evidence of viewing, querying, staging, transfer, or deletion
  • Known logging gaps and steps taken to validate them

Preserve safeguards and response decisions

Keep the relevant policies, technical controls, risk records, access reviews, vulnerability findings, training evidence, vendor terms, alert history, response chronology, and corrective actions. Those materials should reflect the environment at the time, not a post-event reconstruction. GDF provides technical findings and does not provide legal advice.

Primary and public sources

Preserve the facts behind a breach decision

Describe the work, the deadline, and the people authorized to act. Do not send evidence through the public form.

Contact GDF