Not every incident is a breach in the legal sense
Security teams use the word loosely, but its legal meaning is narrower and shifts from one law to the next. Whether a data breach has occurred usually turns on what kind of information was involved and whether someone actually accessed or acquired it, rather than on whether a system was compromised at all. An attack that locked files without touching personal data may raise different questions from a quiet copy of a customer database. Encryption, and whether the key was exposed along with the data, often changes the analysis. That distinction drives much of what follows, from who has to be told to what claims anyone can bring, so it is worth settling before the word starts appearing in emails.
If your information was involved
Read the notice closely for what it says was taken, because a name and email address call for different steps than a Social Security number, account credentials, or medical details. If identifiers that can open credit were exposed, a credit freeze with the major consumer reporting agencies is usually the most effective protective step, and it costs nothing. Change any reused passwords and turn on multi-factor sign-in where it is offered. Keep the letter, along with a simple record of anything that happens afterward, such as fraudulent charges, tax filing problems, or hours spent on the phone with banks. Treat follow-up emails and calls claiming to come from the company with caution, since breach announcements reliably attract impostors.
If it happened inside your business
The first decisions are rarely technical ones. Someone has to call the cyber insurer, often before outside vendors are engaged, because many policies set conditions on which firms can be used and which costs are covered. Counsel is usually brought in early so the investigation is directed with the legal questions in mind and internal discussion stays disciplined. Notice obligations to individuals, regulators, and business customers can carry short deadlines that run while the facts are still being established. When we first speak with a company in this position, we separate what is known from what is still assumed, identify which obligations may already be running, and sort out which calls need to happen today.