Serious incidents are typically reported to senior leadership and the board, and often to regulators or authorities depending on your jurisdiction and the data involved. Many regions require notifying a data protection authority, and sometimes affected individuals, within set timeframes, and some sectors have their own reporting bodies. Your incident response plan should name exactly who to notify and when.
