Halil, use five distinct classifications. KEV or internet exposure means urgent remediation and evidence preservation, but not proof that the organization was compromised. Attempted exploitation—including an OpenAI attempted-access notice—remains an investigated security event unless telemetry shows a successful session, command, or data interaction. Unauthorized access is established when an attacker obtained a session, privilege, content access, or administrative control; under GDPR, unauthorized access to personal data can qualify as a personal-data breach even without proven exfiltration. Data loss includes confirmed or reasonably evidenced disclosure, extraction, destruction, alteration, or loss of availability. Material operational impact is a separate question covering consequences significant to investors or critical services. The source pack supports active exploitation concerning Zammad, Citrix NetScaler, and Cisco SD-WAN Manager; it does not provide enough official evidence for me to characterize the current exploit status of FortiMail, SharePoint, or the OpenAI notices.
In the first 24 hours, Legal and Security should decide: the affected legal entity and jurisdiction; controller/processor roles; when the organization first became aware of facts indicating personal-data compromise; whether access succeeded; what data, identities, systems, and operations were affected; and whether a regulatory, contractual, insurance, or customer clock has started. Under GDPR Article 33, supervisory-authority notification is due without undue delay and, where feasible, within 72 hours after awareness unless the breach is unlikely to create risk; processors must notify controllers without undue delay. Article 34 requires affected-person communication without undue delay where high risk is likely. For SEC registrants, Item 1.05 applies only after a cybersecurity incident is determined material: the Form 8-K deadline is four business days after that determination, while the determination itself must be made without unreasonable delay. Do not call exposure or an unsuccessful attempt a “breach,” but also do not wait for perfect attribution or a final forensic report before opening and documenting these assessments. I could not verify current NIS2 or DORA classification thresholds and reporting clocks from the available official evidence, so potentially in-scope entities should confirm those separately with their competent authority.
Preservation should begin at the exposure or notice stage, before reportability is resolved: record detection time in UTC, vulnerable versions and exposure history, original vendor/OpenAI notices, configurations, administrative and authentication logs, IdP events, active sessions and token/API-key activity, network flows, endpoint evidence, and containment actions under a documented legal hold and chain of custody. Specifically retain Zammad ticket/attachment and API-access records; NetScaler authentication, VPN/session, administrator, and configuration evidence; FortiMail message-tracking, quarantine, administrator, and configuration logs; Cisco SD-WAN Manager API, task, audit, and controller-change records; SharePoint/IIS, audit, application-permission, content-access, and suspected web-shell evidence; and, for OpenAI notices, organization/user identifiers, timestamps, source addresses, SSO records, API-key use, and any prompt or file retrieval. Avoid reimaging or rebooting before volatile evidence is captured where operationally safe; describe the matter externally as an “incident under investigation” until the evidence supports the legal classification.