Breach Management
Record personal data breaches through intake forms, score their risk, track notification deadlines per regulation, run response workflows, and close each incident with remediation and a signed-off review.
Breach Management helps you manage and respond to data breaches effectively: it streamlines your breach response process, ensures timely notifications, and maintains compliance with global regulations. Someone reports an incident on a breach intake form. Neostra scores the risk, derives the applicable regulations and deadlines, starts the right workflow, and gives your team one incident page to investigate, notify, remediate, and review. The module's menu has Dashboard, Incidents, Tasks, Breach Intake Forms, Breach Types, Breach Form Fields, and Breach Workflows.
Neostra drafts notifications and records when you sent them. It does not send anything to a supervisory authority, data subjects, or your board. You send through your own channel, then mark the notification as sent.
The building blocks
Breach form field. A question a reporter answers. Neostra ships system fields such as data categories, estimated individuals affected, geography, encryption status, and mitigation measures. Add your own, with options and translations, under Breach Form Fields.
Breach type. The kind of incident, for example ransomware or accidental disclosure. Neostra provides system types; add your own under Breach Types.
Intake form. The form used to report an incident. You pick its fields and breach types, set languages, allow attachments, and add rules that route a report to a workflow and owner with a due date. Its Scoring Rules page maps form options to the risk model below. Forms are edited as drafts and published. Manage them under Breach Intake Forms.
Workflow. How your team responds: ordered stages, each holding tasks with assignees, a response type, and due days in calendar or business days. A stage can auto advance when all its tasks are done. Basic rules enable or disable steps based on the report. Advanced rules add tags, send an email, or call one of your APIs (see Webhooks) when the workflow starts or completes, a stage starts or completes, or a task completes. Workflows publish as named versions. Manage them under Breach Workflows.
Incident. One reported breach: answers, reporter details, attachments, risk score, geographies, regulation deadlines, tags, and one workflow instance per matching form rule. Work them from Incidents.
Task. One unit of work inside a stage. Assignees answer it, add notes, and upload files. Listed under Tasks.
The incident lifecycle
Report
A reporter completes a published intake form, with or without contact details; reports without details show as Anonymous. Neostra assigns a reference, scores the risk, derives regulations and deadlines, and creates a workflow instance for each matching form rule. The incident starts as Open.
Investigate
The owner sets the incident to Under Review from the incident page. The first stage of each workflow instance is already running, so assignees start on their tasks.
Notify
The Notifications tab lists one deadline per regulation. Generate a draft for the supervisory authority, the data subjects, or your board. Neostra suggests the board always, the supervisory authority whenever the incident has a score, and data subjects at a score of 41 or higher. Edit the draft, send it yourself, then mark it sent, or suppress it with a reason.
Remediate
On the Remediation tab record the root cause, how the breach was discovered, and contributing factors. Add remediation actions and mark each Done. When all are done, add closure notes and mark the remediation resolved. Store supporting files on the Evidences tab.
Review and close
On the Review tab record lessons learned, prevention measures, the regulatory outcome, and the data subject impact. Lessons learned are required before sign-off, which records who signed and when and locks the review. Then set the incident to Closed.
Incident statuses
| Status | Meaning |
|---|---|
| Open | Newly reported. Workflows have started. |
| Under Review | Your team is actively investigating. Set by the owner. |
| Closed | Finished. Neostra refuses to close an incident until the remediation plan has been marked resolved. |
Workflow instance statuses (Open, In Progress, Completed, Canceled) are separate and driven by task completion. Every incident gets a reference in the form BI-<year>-<sequence>, for example BI-2026-0007; the sequence restarts each year.
Risk scoring
If the intake form has a scoring configuration, every incident is scored on submission: three factors added, a mitigation deduction subtracted, kept within 0 to 100.
| Factor | How it is counted | Default points |
|---|---|---|
| A. Data sensitivity | Highest matching base category, plus bonuses that always add | Contact 5, Financial 15, Government ID 20, Health 25, Biometric 30; bonus Children's data +10, Profiling data +10 |
| B. Exposure severity | Highest matching option | Internal 5, Unauthorised 10, Public 20, Ransomware 20, Dark web 25 |
| C. Harm probability | Highest matching option | Low 5, Moderate 15, High 25 |
| D. Mitigation | Sum of deductions, capped at 20 | Rapid containment 5, Pseudonymisation 10, Strong encryption 15 |
The strong encryption deduction is skipped when the report says the encryption key was compromised.
Classification by total: Low below 30, Medium 30 to 59, High 60 to 79, Severe 80 and above.
Escalation rules are conditions on the answers, for example a data category is present or the number of individuals affected exceeds a threshold. If any active rule fully matches, the incident is classified Severe regardless of score, and the rule is listed on the incident as a triggered escalation.
Scoring is configured per intake form on its Scoring Rules page: map form options to scoring keys, override default point values, and disable, edit, or add escalation rules. Neostra provides system escalation rules in every configuration; rules you edit become your own and are no longer updated by Neostra.
Regulations and deadlines
The form's geography field drives applicability. From the affected countries and states, Neostra finds every regulation in Settings > Regulations (see Regulations) whose jurisdiction matches and records one deadline per regulation: the submission time plus that regulation's notification window in hours. A regulation with no window set uses the 72 hour default, and when nothing matches the incident still gets a single 72 hour deadline. The earliest becomes the Regulatory Deadline shown in the queue and dashboard.
Notification windows are planning defaults. GDPR Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of the breach where feasible. DPDPA 2023 requires notifying the Data Protection Board and affected individuals in the manner set by the DPDP Rules 2025. Check the exact obligation for your case. See Regulations.
Who does what
| Role | Typical tasks |
|---|---|
| Privacy admin or DPO | Defines fields and breach types, publishes intake forms, configures scoring, designs workflows, maintains regulations. |
| Incident owner | Works the Incidents queue: drafts and records notifications, runs remediation, signs off the review, closes the incident. |
| Team member | Completes assigned work under Tasks, adds notes, uploads evidence. |
| Reporter | Submits the intake form, optionally with contact details and attachments. |