- Job title
- Data entry clerk
- Sector
- Insurance
- Organization type
- a company within a holding
- Joined
- Oct 2024
- Message
- 99
Customer data was attacked. Should we notify them immediately? Within how many days if we don't delay?
Customer data was attacked. Should we notify them immediately? Within how many days if we don't delay?
Doki · Log management setup · 2025
Under KVKK, data breaches must be reported to customers within 3 days. The number of personal data records stolen must be disclosed. Notification must be written and official. Hiring a consultant is recommended.
Prepare a notification template in advance. Also keep an IT security log — who accessed, when, which data was stolen — must be recorded.
Let me share my experience. Forgotten test environments are more often the entry point than live systems.
I agree with this. The biggest time-waster for us was not knowing who had the final say.
Good luck with that.
Let me summarize whats been said so far. Start with a small trial; dont commit to everything at once.
Of course, it varies if your situation is different.
I think it's hard to be that definitive about what to tell customers after an attack. When you try to change everything at once, nothing settles.
This is my opinion, I'm not claiming it's absolute truth.
Doki · Interface design · 2024
Following. The real issue isn't the number, but what it's based on.
If you post the result here, it will help others too.
I have a question, don't want to go off-topic though. The harder it is to reverse a decision, the slower you should make it.
Taking notes for two weeks yields better results than a six-month estimate.
I went through the same thing two years ago. The real issue isn't the number, but what it's based on.
Saved. Processes without records never improve, because you don't know what to fix.
If I were you, I'd go this route.
There is something to watch out for. Most time waste accumulates in tasks waiting for approval.
If you post the result here, it will help others too.
There's one point I'm curious about. People defend habits, not processes. Resistance comes from there.
An automated scan report is not the same as a penetration test. Proven by experience.
How did you solve this? Any unwritten clause becomes a point of disagreement later as both sides remember it differently.
This is my opinion I'm not claiming it's absolute truth.
Doki · Backup setup · 2023
I didn't know that. Payment information changes are never verified through the channel they came from.
If I were you, I'd go this route.
If you're going this route, sort this out first. Forgotten test environments are more often the entry point than live systems.
Taking measures without an inventory leaves doors you haven't seen open.