
Data left your network. Now what?
Containment is not the end. It is the beginning of a different problem: what DORA, NIS2, or SEC disclosure rules may require you to establish about what was taken.
I work through that question with CISOs and Incident Commanders in a free 30-minute Exposure Check, an inference-risk framework built on 22+ years in data protection, including 12+ years in Product Management with direct cyber-resilience customer work, and one and a half years of hands-on R&D on post-exfiltration data usability.
Thirty minutes. No access. No documents.
You'll know whether your position holds up, and what's missing if it doesn't.