
When a breach lands now, the hardest problem often is not getting the intruder out. It is telling hundreds of regulators, customers, insurers, and partners a consistent story about what happened while investigators are still reconstructing it. New research from BreachRx, a cybersecurity incident-response-management vendor, puts numbers on that pileup: a single cyberattack can set hundreds of breach reporting obligations running at once, long before the facts are stable.
- The report, Regulatory Concurrency, models five recent breaches: Change Healthcare, Snowflake, the Salesloft and Drift Salesforce campaign, 700Credit, and Salt Typhoon. It finds the reporting workload now behaves like a system-scale coordination problem that has outgrown the compliance checklist.
- Obligation counts track connectivity, not breach size. Snowflake’s shared-credential campaign produced at least 209 obligations across just three analyzed victims, and the Salesforce token cascade passed 300 across a handful of connected organizations.
- Change Healthcare’s disclosure ran more than 17 months as the affected population climbed toward 192.7 million people. The reporting clock outlived the technical cleanup many times over.
- The proposed fix is six operating capabilities, starting with a live obligation map and one shared deadline ledger, the coordination layer most response plans still leave to email threads and spreadsheets.
One Incident, Hundreds of Breach Reporting Obligations
BreachRx calls the pattern regulatory concurrency: dozens or hundreds of legally significant reporting workflows starting at the same moment, each on its own clock, while the underlying facts keep moving. Across the five incidents, the report found the same stress points. Reporting clocks overlap, facts shift after the first disclosure goes out, one company’s incident becomes another’s duty, and the disclosure record scatters across teams. One organization alone modeled more than 100 breach reporting obligations in the Change Healthcare case.
“Regulators don’t punish organizations for having a hard incident. They punish them for telling an inconsistent story about it,” said Stephen Garcia, CISO at BreachRx. That reframing matters because it moves the liability off the breach itself and onto the paper trail: what you said, when you said it, and whether every parallel filing agrees.
Why the Obligation Count Tracks Connectivity
The counterintuitive finding is that the obligation load has almost nothing to do with how many records an attacker touched. Salt Typhoon, a national-security-grade intrusion, generated relatively few visible obligations because law-enforcement sensitivities capped what could be said in public. The Salesloft and Drift campaign against Salesforce customers, far smaller in headline terms, cleared 300 modeled obligations because compromised tokens carried the incident into every connected tenant. The blast radius is the connections, and third-party risk is where it detonates. An organization can inherit a reporting duty the moment a partner it barely tracks suffers a data breach, so teams that measure readiness by their own controls miss the exposure. The same gap shows up in how firms score their programs; we have argued that a few well-chosen incident response metrics predict maturity better than control counts.
This is vendor research, and it doubles as a thesis for the platform BreachRx sells, so treat the six-capability shopping list with the usual skepticism. The incident data underneath it does not care who publishes it. Change Healthcare, Snowflake, and the Salesforce cascade are public record, and the concurrency they created is real whether or not any one product solves it.
Build the Obligation Map Before the Next Cascade
The guidance sequences cleanly: know your duties before an incident, hold the facts steady across every filing, then extend both to the partners who can pull you into their breach. Three moves carry most of the weight.
Map your reporting obligations before an incident – Build the obligation map and deadline ledger while calm, so a Change Healthcare event, 17 months and 192.7 million people, never starts from a blank spreadsheet.
Give one owner the job of narrative consistency – Assign one person to enforce fact consistency and log the rationale, so 200-plus parallel breach reporting obligations tell one story a regulator can reconstruct later.
Re-scope third-party risk around cascade blast radius – Rank vendors by how far their compromise carries into your breach reporting obligations, rather than by their size. That instinct is the one we brought to calling AI voice fraud a compliance problem first. Cyber insurance carriers belong on that list too, one more clock among the hundreds. The next Change Healthcare will not wait 17 months for your reporting map to catch up.
Join our LinkedIn group Information Security Community!










