Skip to content
AI Protection
Free
Start with what’s already out there

We’ll show you your exposure before you pay anything.

Run a free scan

Breaches we’re tracking

All tracked breaches
No letter, but worried?

Enter your email and we’ll tell you which breaches include you.

Check my email

For organizations responding to an incident

Data Breach Response

When an organization experiences a breach involving customer, employee, member, patient, or other personal information, AI Protection can provide a response solution for the people affected: clear information about the incident, and protection the organization arranges on their behalf.

Who does what in a response
Organization
Discovers or discloses an incident. Arranges protection for the people affected.
AI Protection
Provides incident information for affected individuals and the protection services included in the program.
Affected individuals
Learn what happened and what to do, and activate the protection provided to them.

The breach is only the beginning of the response.

Once an incident involving personal information is discovered, the organization has a second problem that does not go away when the intrusion is closed: the people whose information was involved now need to hear from it, and many of them will need help.

Determining who was affected

Which individuals, which records, which categories of information, and how confident the organization is in each answer.

Communicating clearly

Explaining what happened and what was involved in plain language, without overstating or understating what is known.

Providing next steps

Telling affected individuals what they can do now, and giving them somewhere to go with questions.

Responding to concern

Handling the volume of questions, worry, and follow-up that a disclosure generates.

Offering protection where appropriate

Making monitoring, support, or other protection available to the people whose information was exposed.

Managing a risk that continues

Exposed information can remain in circulation after the incident is contained. The organization's response has to account for that.

What is data breach response?

Data breach response is the set of services and processes an organization uses after personal information has been compromised to communicate with the affected individuals, support them, and offer them appropriate protection. It begins once an incident has been discovered or disclosed, and it is distinct from the security work of detecting and containing the intrusion itself.

In this context, a data breach response typically includes explaining what happened and what information was involved, telling affected individuals what steps they can take, answering their questions, and providing services such as identity monitoring or restoration support for a defined period.

AI Protection's role is to provide that response on the organization's behalf. AI Protection is an identity protection provider. In a Data Breach Response program, the organization that experienced the breach arranges for AI Protection to provide incident information and protection services to the individuals affected, so the organization is not building a consumer-facing response from scratch during an incident.

AI Protection Data Breach Response

What AI Protection provides after a breach.

The program combines incident-specific information for affected individuals, a sponsored enrollment path, and the identity protection services AI Protection already delivers.

Incident information page

A dedicated page for the incident explaining what happened, what information was involved, what remains unknown, and what affected individuals can consider doing, with sources listed. The same format is used for the pages under this one.

Identity monitoring

Monitoring for exposure of personal information, including Social Security number and address, with alerts when something is found.

Removal of exposed information

Requests to remove personal information from data broker and people-search sites, reducing what can be found and combined with breached data.

Identity theft insurance

Up to $5M in identity theft insurance for eligible identity-theft-related expenses, subject to policy terms and conditions.2

Sponsored enrollment

Eligible individuals activate protection without purchasing it, using a unique code included in their notification or an eligibility check against the list the organization provides.

Program reporting

Activation and usage reporting for the organization throughout the program period.

How a Data Breach Response program works

Five stages, from the incident to ongoing support. Timing at each stage depends on the incident and the organization's decisions; no stage below carries a fixed deadline.

  1. 01

    Incident

    An organization discovers or discloses an incident involving personal information.

  2. 02

    Response setup

    AI Protection works with the organization to configure the response program: which services are included, who is eligible, and how the incident is described to affected individuals.

  3. 03

    Affected individuals are informed

    Individuals receive information about the incident and instructions for activating the protection being provided.

  4. 04

    Protection is activated

    Eligible individuals enroll in or activate the AI Protection services included in the program.

  5. 05

    Ongoing support

    AI Protection provides the included services for the program period, including monitoring alerts and restoration support if an individual's information is misused.

Who can be protected?

A program is structured around the population affected by a specific incident. The groups below are the kinds of populations a program can be built around; eligibility for any given program is defined with the organization during setup.

CustomersIndividuals whose account or purchase records were involved.
EmployeesCurrent or former staff whose HR, payroll, or benefits records were involved.
MembersMembers of an association, plan, or program.
PatientsIndividuals whose records were held by a healthcare provider or its vendors.
Account holders and usersPeople with credentials or profiles on the affected system.
HouseholdsFamily members of an affected individual can also be made eligible under the program.

Programs are available for U.S.-based affected populations.

Data breach resources

Incident pages published under Data Breach Response. Each explains what is known about a specific breach, what information was involved, and what affected individuals can consider doing. Entries are added as pages are published.

Why protection after a breach matters

Risk to affected individuals can continue after the security event is over. The points below describe how exposed information can be used in general. Whether any of them applies to a given incident depends on what was involved.

Can't be changedSome compromised information, such as a name, date of birth, or Social Security number, cannot simply be replaced the way a password or card number can.
Stays availableCopies of breached data may remain accessible after the original incident is contained.
Can be combinedInformation from one breach can potentially be combined with information from other breaches or public sources into a fuller profile.
Can be usedDepending on what was involved, compromised information can potentially be used for phishing, impersonation, account attacks, fraud, or social engineering.

For organizations responding to a breach

If your organization has experienced a data breach, talk with AI Protection about protecting the people affected.

Tell us what you know so far. We'll discuss what a response program for your affected population could include and what AI Protection would need from you to set it up.

Required: name, work email, company. Do not include personal information about affected individuals in this form.

Data Breach Response questions

Data breach response is the set of services and processes used after personal information has been compromised to communicate with affected individuals, support them, and offer them appropriate protection. It starts once an incident has been discovered or disclosed and is separate from the security work of detecting and containing the intrusion.

In general terms: investigate and contain the incident, determine who was affected and what information was involved, notify affected individuals and any required authorities, explain what happened and what people can do, and often provide protection or monitoring to those affected. Specific obligations depend on the jurisdiction, the type of information, and the organization, and should be confirmed with counsel.

Protection services provided to individuals after their information has been exposed in a breach, typically including monitoring for misuse of that information, help reducing further exposure, and support recovering if the information is used fraudulently. Because some exposed information cannot be changed, these services address a risk that can continue after the incident itself is over.

The organization that experienced the breach contacts AI Protection. Together they configure a response program: which services are included, who is eligible, and how the incident is described. Affected individuals are informed and given instructions to activate the protection, and AI Protection provides the included services for the program period. See the process section above for the five stages.

In an organization-sponsored program, the organization that experienced the breach arranges and pays for the protection provided to eligible affected individuals. Individuals activate the protection; they do not purchase it. Programs are priced per affected individual and quoted per incident.

Yes. That is what Data Breach Response is: an organization arranging for AI Protection's services to be provided to the individuals affected by its incident. Contact Breach Response to discuss a specific incident.

The individuals the organization identifies as affected by the incident and eligible under the program, which can include customers, employees, members, patients, or account holders. Eligibility for each program is defined during setup. Programs are available for U.S.-based populations, and family members of an affected individual can be included.

It depends on the incident: how well the affected population is defined, which services are included, and how the organization plans to notify people. AI Protection does not publish a standard launch time. Contact Breach Response with what you know and we can discuss timing for your situation.

To begin a conversation: a description of the incident, the categories of information involved, an estimate of how many people were affected, and where the organization is in its response. To set up the program: the list of eligible individuals (or the fields needed to verify eligibility), the incident description used on the information page, the eligibility criteria, and the planned notification timing.

AI Protection provides the incident information page that affected individuals are directed to, the enrollment path, and the protection services described on this page. Notification of affected individuals is handled by the organization as part of its own response.

The individual receives the services included in the program for its duration, typically 24 to 36 months: monitoring with alerts if their information is found exposed, removal requests for information on data broker sites, social media monitoring where connected, and access to U.S.-based restoration support and identity theft insurance (subject to policy terms) if their identity is misused. At the end of the period they are offered a discounted opportunity to renew; nothing renews automatically.

Give the people affected somewhere to turn.

Clear information about the incident and protection the organization provides on their behalf.