Blog
Practice the customer notice. Do not send it.
The filing clock and the customer clock are different decisions. How to draft the notice, time who would approve it, and keep the live send off the exercise.
At 09:12 the SOC confirmed it. A CSV from billing-export-03, customer emails and last-four card digits, is sitting in a public dump. Sam O (comms) asks whether anyone is writing the customer email. Dana K (legal) asks when the 24-hour SLA started. The status page still says the product is operating normally. Nobody hits send, because this is an exercise. Forty minutes later the notes say customers would be notified as required.
That sentence is how the gap survives. October is when a lot of teams finally book the annual tabletop. The inject they skip is the email they would send customers.
A discussion about notification is not a notice decision
A weak inject reads:
Discuss customer notification requirements.
The room says it would coordinate with legal and comms. An assessor who later reads the packet cannot tell who would have approved the wording, which clock started, or whether the draft named billing-export-03. The sentence would also be true of a team that has never opened the customer mailer. That is what it costs: on a real morning the first email customers see is written under a tweet, and the 24-hour SLA has already been running since 09:12.
A strong inject reads:
T+3h10. SOC confirmed at 09:12 that customer emails and last-four card digits from billing-export-03 are in a public dump. The Northwind MSA says notify affected customers within 24 hours of confirmed personal-data exposure. Sam O has a draft. Dana K has not approved it. A customer has posted: is my card in the dump. Status page still says operating normally. In four minutes of exercise time: start or hold the customer clock, approve or hold the draft, update or leave the status page. Do not send anything live.
Both produce a meeting. Only the second produces a notice decision someone who was not in the room can check. The injects post is the same rule with a different choice at the end of it.
The draft is the evidence, not the intention
A weak notice reads:
We take security seriously and are investigating a potential incident. We will provide updates as appropriate.
A strong one, written as an exercise draft and marked not sent, reads:
At 09:12 on 3 October we confirmed a file containing customer email addresses and last-four card digits from billing-export-03 was posted to a public dump. We isolated that export path at 09:41. We have not confirmed unauthorized charges. Next update by 15:00, or sooner if we confirm more fields. Draft approved by Dana K at T+3h18. Not sent.
The first is already in a template folder somewhere. The second is the call the room actually made. CISA, the FBI, and partners put the wording standard in Communicating Under Pressure: say what is known, what is unknown, and what is under investigation. Skip the spin. Align the wording with the clocks you actually have. That note is written for service-provider outages. The same three facts belong on a customer notice.
Our sample packet starts a 24-hour Northwind notification clock at T+2h41, with a named comms owner, and then records the stall when legal is not in the room. That is the shape. Copy it, including the stall if it happens.
Three clocks, one room
The 72-hour filing post is the regulator clock: who files, through which portal, when someone reasonably believes. The customer clock is a different decision, usually a different owner, and a different sentence.
- Contract SLA. Northwind MSA: 24 hours from confirmed personal-data exposure. Who records confirmed, at what time, against which facts.
- Data-subject notice. Separate from the regulator filing. Different audience, often a different owner, and a different blank in the plan.
- Status page and in-app banner. The customers who never open email. Who can change the public sentence, and whether the room treated that change as notification.
If the plan has one paragraph that says notify customers and regulators as required, split it before you book the room. Mixing the clocks is how the customer email never gets a draft. Ransomware with a customer clock is one of the scenario families we actually run.
Keep it off the wire
Do not send a live customer email, a live in-app banner, or a live status-page change from the exercise. Practise the wording, the approval, and the clock. Leave the send for a real event.
If someone in the room has production access to the mailer, say so on the record and take that access off the exercise path. An accidental send is not a finding you want to explain.
What to write down
The artifact that travels is the same shape every time:
- Clock start. Who recorded confirmed exposure, at what time, against which facts.
- Approver. Named person against the role the plan lists, including if the seat was empty or reassigned.
- Draft. The factual summary (known, unknown, under investigation), and that it was not sent.
- Channel. Email, in-app, status page: which ones the room would have used, which ones it could not operate.
- Follow-ups with owners. What will change before the next run.
That is the decisions and gaps fields in our free evidence template, and it sits with three other formats in the template library. If the plan cannot name who approves the customer sentence, stop and run the free plan self-check before you book the room. An empty comms or legal seat is a finding about the roster. The invite-list post covers how to write that down.
Drafting the notice does not prove the mailer delivers, that the affected-customer list is current, or that a real send would satisfy any contract or law. Those are technical and legal tests. The packet records that named people practised the notice decision under a concrete scenario, and that you kept the live send off the wire.
Bottom line: write the email, time the clock, name the approver, and do not hit send. A note that customers would be notified as required is not evidence of a notice.