The PaperCut issue now has a clearer evidence ladder: internet exposure establishes vulnerability-management urgency, while observed SYSTEM execution, registry-hive collection, or privileged-account creation establishes a security incident. Even then, those actions do not automatically establish a reportable personal-data breach. Under GDPR, the decisive question is whether personal data was accessed, disclosed, lost, altered, or destroyed; confirmed exfiltration is not required.
For an EU school, awareness of a qualifying breach starts a notification analysis with a maximum 72-hour supervisory-authority deadline unless risk to individuals is unlikely. High-risk cases also require communication to affected people without undue delay. If NIS2 applies under the relevant national implementation and the incident is significant, the sequence may include a 24-hour early warning and a 72-hour incident notification—but coverage cannot be assumed for every school. The U.S. side of the assignment remains unresolved in this response: no state-specific breach trigger, education-sector rule, or notification timetable has yet been established, so the room should not infer one.
The immediate defensible move is evidence preservation: immutable, hashed copies of PaperCut access, application, and audit logs; Windows security, PowerShell, process-creation, and account-management events; SAM, SYSTEM, and SECURITY hives; EDR telemetry; memory and disk images; print queues, spool files, and job metadata; and IdP, VPN, firewall, DNS, proxy, and NetFlow records. That preserves the ability to distinguish exposure from execution and execution from personal-data impact.
We now turn to three different causation problems: active-exploitation evidence for StyleSmuggler, hidden vendor functionality as a software-supply-chain trust failure in the CSIST case, and whether the Vesu liquidations are best understood as exploitation or an upstream oracle-data failure.