A Data Breach Is Not the Time to Decide Who Does What

by | Jul 25, 2026 | AI Knowledge Hub for Nonprofits, nonprofit

A nonprofit discovers that an employee account was compromised. A spreadsheet containing participant information was emailed to the wrong person. A laptop holding donor records disappears. A vendor reports unauthorized access to a shared system.

Employees may recognize that something serious happened without knowing whether it qualifies as a reportable breach, who must be contacted or what information should be preserved.

That uncertainty can delay containment, damage evidence and produce inconsistent communication.

Distinguish an Incident From a Confirmed Breach

Not every security incident results in confirmed exposure of personal information. The organization may need technical, legal and operational review before determining what occurred.

Employees should not make that judgment alone. Their responsibility is to report the event quickly through an approved process.

The procedure should explain:

  • What types of incidents must be reported
  • Who receives the initial report
  • How urgent events are escalated
  • Who contacts the technology provider
  • Who preserves logs, messages and devices
  • Who determines what information was involved
  • Who reviews notification requirements
  • Who communicates with affected individuals
  • Who coordinates with insurers and law enforcement
  • Where decisions and evidence are recorded

The Federal Trade Commission’s data-breach response guide recommends quickly securing operations, mobilizing the response team, preserving evidence and determining which legal requirements apply.

Know Where Sensitive Information Lives

A nonprofit cannot respond effectively when it does not know which systems contain personal information.

An inventory should identify data held in:

  • Case-management systems
  • Donor and fundraising platforms
  • Volunteer databases
  • HR and payroll systems
  • Email accounts
  • SharePoint and OneDrive
  • Exported spreadsheets
  • Vendor platforms
  • Laptops and mobile devices
  • Paper files

The inventory should also identify the system owner, vendor contact, types of information stored and responsible internal employee.

This allows the organization to retain institutional knowledge about its data environment instead of rebuilding that understanding during every incident.

Prepare Notification Procedures in Advance

Breach-notification requirements may depend on the state, the type of information, the people affected, contractual terms and whether specialized rules apply.

The FTC notes that every state, the District of Columbia, Puerto Rico and the Virgin Islands has enacted breach-notification legislation. Organizations may also face additional requirements involving health, financial or other regulated information.

Legal counsel should determine whether notification is required, who must receive it and when. Employees should not promise notification, deny that a breach occurred or communicate publicly without approval.

The nonprofit should maintain approved templates and contact information, but each incident requires review based on its facts.

Organize Guidance Without Exposing the Investigation

SharePoint should serve as the organized knowledge source for the incident-response plan, blank reporting forms, responsibility charts, vendor contacts and approved communication procedures.

Copilot Studio provides the conversational layer. Through Maisy, authorized employees could ask:

  • How do I report a suspected breach?
  • Who contacts our cyber insurer?
  • What evidence should I preserve?
  • Which vendor manages this system?
  • Who approves participant notifications?
  • Where is the incident-response checklist?

Maisy should retrieve approved procedures under the user’s Microsoft 365 permissions. It should not expose active investigation records, determine whether notification is legally required or speculate about who caused the incident.

Security platforms remain authoritative for technical alerts. Case-management, donor, HR and accounting systems remain authoritative for their records. Legal counsel, cybersecurity professionals, insurers and leadership must direct the response.

NIST’s data-breach guidance addresses preparation, detection, response and recovery from attacks involving unauthorized access to sensitive data. CISA also recommends involving senior leadership and board members in tested cyber-response plans through tabletop exercises. (NIST)

How Maisy Helps

Pixeldust begins by identifying sensitive data locations, repeated incident questions, vendor contacts, response roles, notification dependencies and permission requirements.

Pixeldust then organizes approved response guidance in SharePoint, assigns content owners and configures Maisy through Copilot Studio. Testing uses realistic scenarios involving lost devices, compromised accounts, accidental disclosures and vendor incidents.

This helps the nonprofit retain institutional knowledge about breach response while keeping forensic analysis, legal interpretation, notification decisions and public communication under qualified human control.

Pixeldust IT Contract Risk Review Icon

Free Assessment

Complete the form below, and let's talk about how we can help preserve your organizational knowledge and make it easier for your team to find the answers they need.

Name(Required)

Free Guide: The Knowledge Capture Playbook

A practical system for extracting critical knowledge from employees, documents, workflows and real operational cases. This white paper includes prioritization scoring, interview scripts, workshop agendas, capture templates, evidence standards, validation controls, performance metrics and a 30/60/90-day rollout plan.

Download The Free PDF Guide

The Intelligence Compound: A New Operating Model for AI in Small Business

The Intelligence Compound presents a practical framework for implementing AI in small business. Rather than treating AI as a collection of isolated productivity tools, the paper explains how businesses can use it to preserve knowledge, support decisions, reduce owner dependency, identify operational problems, and improve processes over time. It includes original use cases, governance principles, real-world examples, and a 90-day implementation roadmap.

Download Whitepaper PDF

Thought Leadership