Halil, for PLC/HMI manipulation, I would not treat this as merely internal safety handling once the evidence shows unauthorized access to the control environment plus service-impact facts: changed PLC logic, HMI set-point manipulation, loss of view/control, safety-system activation, production shutdown, degraded essential service, or credible persistence in OT. The handoff evidence describes an Iranian-affiliated PLC-targeting campaign, active in the wild, with named-sector impact and official/vendor-supported urgency, so the legal posture should be “notification-ready” now. The clock-starting facts are not “patch completed”; they are first detection of unauthorized OT manipulation, confirmation of operational impact, and identification of the regulated operator/jurisdiction. I could not verify the current exact NIS2/DORA/SOCI/CERT reporting clocks here, so I would preserve evidence and prepare notifications without citing a specific statutory deadline.
For the named data incidents: Bank of Baroda is the clearest immediate breach-assessment case in the evidence available: a reported employee email compromise and claimed 1 TB sensitive customer data leak means preserve mailbox logs, access tokens, download traces, customer-data inventory, and extortion/leak-site evidence; the notification clock starts when the bank has facts showing unauthorized access to customer/personal or regulated financial data, not when every record is validated. For Windchill/FlexPLM, treat it first as IP/trade-secret and possible personal-data exfiltration: preserve tenant/admin logs, export jobs, CAD/PLM object access, supplier-user lists, and contractual notice triggers. For Click To Pray IDOR, the clock starts when testing/logs show a user could access another user’s account/profile/prayer/intention data at scale; preserve API logs and affected-user enumeration. For EY support platform, preserve ticket attachments, support-user identities, third-party customer boundaries, and processor/controller routing evidence before deciding whether EY or customers notify.
For Origin Energy, the posture depends on whether the facts show customer/personal-data access, energy-service disruption, or critical-infrastructure operational impact; preserve outage records, customer datasets touched, and SOC/OT boundary logs. For DentaQuest, if patient, member, claims, or dental health information was accessed or exfiltrated, preserve PHI data maps, affected-individual counts, vendor chain, and payer/provider contracts immediately. For Claude public-share indexing, notification turns on whether public-share URLs exposed personal, confidential customer, source-code, regulated, or children’s/sensitive data and whether indexing was reasonably discoverable by third parties; preserve share-link creation logs, robots/indexing evidence, takedown timestamps, and user notices. Across all of these, my practical position is: open a privilege-protected breach assessment now, freeze logs, map jurisdictions and data classes, and do not let “we are still investigating” delay the internal legal clock analysis.