Ransomware + GDPR Notification
SaaS Company, RomaniaChallenge:
SaaS startup hit by ransomware; customer data potentially exfiltrated. Needed rapid containment, GDPR notification decision, and customer communications.
Response:
Legal: Privileged investigation, GDPR 72-hour notification to Romanian DPA, customer notification drafting. MSSP Partner: Threat containment, forensic imaging, malware analysis.
Outcome:
Notification completed within 48 hours, no regulatory fine, customer churn minimized.