A company can hold New York residents' information in systems operated far outside New York. After a security incident, counsel needs facts about the affected data and event, not a population count inferred from the location of the compromised server. For a multi-state business, the difficult technical work is often reconciling several systems and owners into one supported account.
Separate affected infrastructure from affected records
Start with the identities, applications and repositories involved. For each repository, record the available evidence of viewing, queries, downloads, staging or transfer. Access to an administrator account does not establish that every reachable record was accessed. Equally, incomplete logging cannot establish that no access occurred.
Describe logging coverage alongside the activity findings: which events were enabled, the retained period, collection errors and any uncertainty in clock alignment. Preserve the relevant native logs and queries before reducing them to a report summary.
Build a population with traceable decisions
Inventory the fields present in the material supported by the evidence. Distinguish customer, employee and counterparty records, then reconcile repeated people across business units. A row count is not automatically a count of people. Keep the matching rules and uncertain matches available for review.
- Identify the source owner and the business entity responsible for each dataset.
- Retain source identifiers while working with appropriately limited review copies.
- Separate observed facts from assumptions used for a preliminary estimate.
- Record encryption circumstances and known access to relevant keys.
- Track additions and corrections between successive population versions.
Deliver facts that counsel can use across jurisdictions
The New York Attorney General describes the SHIELD Act's expanded private-information framework and reasonable-safeguard requirements. Counsel determines applicability, notification obligations and current deadlines. A technical report should not present one state's conclusion as the answer for every affected person or entity.
Preserve contemporaneous control settings, escalation records and response decisions as well as the affected data analysis. Date each preliminary conclusion and identify what new evidence could change it. This makes later revisions explainable without pretending the first estimate was final.
Our New York breach-response practice provides local context. Incident response and data discovery cover the technical collection and reconciliation work. GDF does not provide legal advice.