Digital download. All sales are final: no refunds or returns. Each format can be downloaded 3 times, and the links stay valid for 30 days. If you need more, reply to your confirmation email and we will sort it out.
Someone got in and took something, and the company knows. That is a technical incident for about a day; after that it is a decision, because the people whose data it is, the regulators whose rules run in days, and the market each have a claim to hear about it. Telling has a price the meeting can add up: the people told at what telling one costs, the customers who leave, and the fine for the breach itself, which is paid whichever route is taken once the breach is known. Hiding has a fee, the intruder's price, and behind the fee a bet on the chance it never surfaces, which no one in the meeting has stated as a number, because no one puts a share on their own concealment being found out. So the meeting prices the telling route whole and the hiding route as a fee, and the smaller number wins by default. This pack prices both routes the same way. What hiding costs is the intruder's price plus the chance it surfaces times everything you would have paid anyway plus the price of the hiding itself, which counsel has never been asked for because counsel prices the breach and not the concealment. Set the two routes equal and the decision reduces to the break-even surfacing chance, how likely the intrusion must be to surface on its own before telling is cheaper, and to one clock: what each day undecided costs, against the days the tightest rule leaves before it reads the silence as concealment. It stops on two halts: no one has stated the chance, and no one has priced the hiding itself.
What is the Breach Strategy Pack
The Breach Strategy Pack is a complete decision-support kit for one question: you know about the intrusion, so what does telling cost against hiding it, and what does each day undecided add? It is built around one organizing claim: telling has a price the meeting can add up, and hiding has a fee with a bet behind it that no one has stated as a number. Sixteen files carry it: the foundations, a concept deck, a scored decision wizard, a disclosure model blank and worked, the moves at each position, nine sourced intrusions, a fit worksheet, a roadmap template, a practitioner manual, a field checklist, and an orientation page.
The test that runs through every file
whether hiding is a bet on the chance it never surfaces that anyone in the meeting would state aloud, and what each day undecided adds. It is the argument in the deck, it becomes the wizard’s axes, it drives the model’s inputs, and it reappears as lines on the checklist. That is what makes 16 files a product rather than 16 documents.
The model resolves to one number you can negotiate with: The break-even surfacing chance — how likely surfacing must be before telling is cheaper than hiding. It ships blank and worked, and every input is a named cell rather than a figure buried inside a formula, so the number arrives with its assumptions attached rather than on its own authority.
Why a data breach response strategy is priced on one side only
Not because anyone is hiding the second number. Because it has two parts that live in different places. The chance the intrusion surfaces without you is a share no one will state, because no one puts a number on their own concealment being found out, so the meeting says 'contained' and moves on. What the hiding itself would cost if it surfaced is a question for counsel, and counsel prices the breach, not the concealment, because no one is asked to price their own.
So the meeting compares the telling route, priced whole, against the intruder's demand, and the smaller number wins by default. Uber's meeting did exactly that in 2016 with $100,000. The second bill, a record $148 million settlement for the handling of the breach and a conviction for its security chief, arrived two years later.
This pack turns that into arithmetic. What telling costs, once, is the people told at what telling one costs, plus the customers who leave, plus the fine for the breach itself. What hiding costs is the intruder's price, plus the chance it surfaces times everything you would have paid anyway plus the price of the hiding. Set them equal and the decision reduces to one figure, the break-even surfacing chance, and one clock, what each day undecided costs against the days the tightest rule leaves you.
What is in the Breach Strategy Pack
- Foundations. The framework: why an intrusion becomes a decision within days, the arithmetic of a bill against a bet, the four endings, and the conditions that stop the analysis.
- Concept deck. Twenty-two slides for a board or a crisis meeting, with nine sourced intrusions and what each does not establish.
- Decision wizard. Eight scored questions returning the band, the weakest answer, and either of the two halt conditions.
- Disclosure model. Eleven candidate surfacing chances across the columns, from never to certain, the break-even chance that decides it, and what a day undecided costs.
- Strategies and tactics. The moves at each of the four positions, what to do when the model halts, and four ways to make the next intrusion cheaper to judge.
- Case studies. Nine sourced intrusions: two hid, five told within ten days, one told after forty, one was visible from the first minute, and one refused and paid the largest bill.
- Fit worksheet. The single page of record: what was taken, what telling costs, what hiding costs at a stated chance, what a day costs, and the days the rule leaves.
- Roadmap template. Five phases with gates and owners, the assumptions register, a reporting change, and a periodic review line.
- Practitioner manual. The count, the per-person cost, the chance, the rules' days, the hiding itself, the board paper, and six failure modes.
- Field checklist. The one-pager that survives outside the binder.
- About the package. What each file does and the order in which to run them.
Who the Breach Strategy Pack is for
A chief executive in the eleventh day of a meeting about an intruder's demand; a general counsel who has priced the breach and been asked to price nothing else; a chief information security officer who owns the failure and has inherited the decision about whether anyone hears of it; a chief financial officer being asked to approve a fee against a bill with nothing stated between them; a board member reading a notification cost with no alternative beside it; a private equity operating partner whose portfolio company has just received the email; and the adviser who would otherwise start from a blank page. It is worth buying when a real intrusion is in front of you, or before one is. It is not worth buying to read.
An honest note on fit
This is a kit for running a decision, not a research report, not a forecast, and not legal advice. Worked examples use an explicitly fictional company with numbers tuned to teach rather than to flatter. In the worked case a retailer with 1.3 million members' data taken finds that telling costs $13.5 million once, that the largest line is the fine for the breach itself, and that the customers who leave, the line the meeting feared most, is the smallest. Hiding is cheaper only if the chance of surfacing is below 27.6 percent; the meeting, made to state a figure, said one in two, at which hiding costs $24.2 million. And the eleven days undecided cost $858,000, twice the intruder's $400,000, at $78,000 a day.
Four limits are stated on the page rather than worked around. The model does not forecast the chance it surfaces; that figure is your own judgment, and the Model tab sweeps it from never to certain because no one can settle it in advance. It prices the hiding as if it surfaced today, and states the day cost rather than forecasting the days. It does not price what a known willingness to hide does to the next regulator, the next customer, or the next hire. And it sets aside what the attack itself costs to contain and rebuild from, because that is paid whichever route is taken. Case evidence is the smaller share of the pack and framework the larger, and each page marks which is which.
Questions about the Breach Strategy Pack
- What numbers does the disclosure model produce?
- Two headlines and twelve supporting rows. The break-even surfacing chance, how likely the intrusion must be to surface on its own before telling is cheaper than hiding, and what a day undecided costs. Around them: what telling the people costs, what telling costs once and how much of it is the fine, what hiding costs if it surfaces and at your own figure, the difference, the distance between your chance and the break-even, what the days so far have cost, the intruder's price in days undecided, the days the tightest rule leaves you, and what telling costs in years of profit. The Model tab sweeps the chance from never to certain, and one row turns from No to Yes at the point where telling becomes the cheaper route.
- Should we disclose the breach or wait until we know more?
- Scoping is legitimate for the days the rules give you, and the pack counts them. Past the shortest rule's day, waiting is concealment under another word. In the worked case a meeting eleven days into deciding whether to pay $400,000 had spent $858,000 on the deciding, twice the fee, with three days left under the tightest rule.
- Is paying a ransomware demand the same as concealing?
- No, and the pack separates them before pricing either. Paying for a decryption key to restart systems, disclosed as it is paid, is an operational purchase. Paying the intruder to delete the data and keep quiet is concealment, priced as a bet on the chance it never surfaces.
- Does this only apply to consumer data?
- No. It applies wherever an intrusion is known and a choice exists about who hears of it: customer data, employee data, payment details, credentials, intellectual property, and operational systems. Two of the nine cases are ransomware against plants and pipelines rather than data theft, and the pack reads them for what the attack costs on both routes.
- Are the case studies real companies?
- Yes. Nine sourced intrusions: Uber, Capital One, Equifax, Target, 23andMe, Norsk Hydro, Colonial Pipeline, Coinbase, and Maersk. Each is dated, read through what was chosen and what happened, and each states what its evidence does not establish. Where a figure is an allegation in a state's complaint, the pack says so. The worked model, wizard, and worksheet use an explicitly fictional company, labeled as such on every file.
- Is this a subscription?
- No. One payment, one download, sixteen files, yours to keep and to use inside your organization under the license included in the pack.
- What is the Breach Strategy Pack?
- The Breach Strategy Pack is a decision-support kit for one question: What disclosing a breach costs against concealing it, and what a day of deciding adds? It contains 16 files — foundations, concept deck, decision wizard, disclosure model, strategies and tactics, case studies, fit worksheet, roadmap template, practitioner manual, field checklist, about the package — built around a single organizing test: whether hiding is a bet on the chance it never surfaces that anyone in the meeting would state aloud, and what each day undecided adds. It is what a leadership team uses to run the decision and leave a record of what they assumed, rather than a report about the topic.
- Who is the Breach Strategy Pack for?
- Anyone who has to make this call and answer for it: an operator or owner facing the decision, the executive team running it, the board or investor testing the reasoning, or an adviser who would otherwise build the framework from a blank page. It is worth buying when a real decision is in front of you. It is not worth buying to read.
- What is in the Breach Strategy Pack?
- 16 files in Word, PDF, PowerPoint and Excel: Foundations (Word + PDF) — The framework: why an intrusion becomes a decision within days, the arithmetic of a bill against a bet, the four endings, and the conditions that stop the analysis. Concept deck (PowerPoint + PDF) — Twenty-two slides for a board or a crisis meeting, with nine sourced intrusions and what each does not establish. Decision wizard (Excel) — Eight scored questions returning the band, the weakest answer, and either of the two halt conditions. Disclosure model (Excel, blank and worked) — Eleven candidate surfacing chances across the columns, from never to certain, the break-even chance that decides it, and what a day undecided costs. Strategies and tactics (Word) — The moves at each of the four positions, what to do when the model halts, and four ways to make the next intrusion cheaper to judge. Case studies (Word) — Nine sourced intrusions: two hid, five told within ten days, one told after forty, one was visible from the first minute, and one refused and paid the largest bill. Fit worksheet (Word, blank and worked) — The single page of record: what was taken, what telling costs, what hiding costs at a stated chance, what a day costs, and the days the rule leaves. Roadmap template (Word) — Five phases with gates and owners, the assumptions register, a reporting change, and a periodic review line. Practitioner manual (Word + PDF) — The count, the per-person cost, the chance, the rules' days, the hiding itself, the board paper, and six failure modes. Field checklist (PDF) — The one-pager that survives outside the binder. About the package (PDF) — What each file does and the order in which to run them.
- What number does the Breach Strategy Pack produce?
- The break-even surfacing chance — how likely surfacing must be before telling is cheaper than hiding. The model ships blank and worked, and every input is a named cell rather than a figure buried inside a formula, so the number you take into a room arrives with its assumptions attached and can be argued with rather than merely believed.
- How is the Breach Strategy Pack delivered?
- As a single download of all 16 files, immediately after payment, with the same link sent by email. It can be downloaded 3 times and the link is valid for 30 days. There is nothing to install and no account to keep.