Regulatory Note: OCR fines and state AG investigations can follow a single patient complaint or breach notification. Compliance is not optional.
If you believe you have an active data breach: call immediately — do not restart systems, do not delete evidence, do not alert attackers. If you're assessing your breach response readiness: book a free assessment and find out whether your notification obligations are understood, your incident response procedure is documented, and your security posture would limit the scope of a breach.
No disruption. No lengthy onboarding. A fast, smooth transition to a partner that has your back from day one.
For active breaches: immediate incident response — call 866-710-0308. For preparedness: a breach readiness assessment evaluates notification obligation awareness, incident response procedure documentation, forensic capability, and security posture — giving an honest picture of breach response readiness. At no cost, no obligation.
For active breaches: full incident response — containment, forensic assessment, notification coordination, remediation, documentation, and post-breach hardening. For preparedness: a breach readiness program — documented incident response procedures, notification obligation mapping, and the security controls that reduce breach likelihood and limit scope.
Our engineers deploy, configure, and meet your team — typically live within 1–2 weeks without disrupting daily operations.
Post-breach or post-implementation: enrollment in the managed security program — 24/7 SOC monitoring, EDR, email security, and vulnerability management — so the hardened post-breach posture is maintained and the controls that stopped the last attack stop the next one.
In the first hour: call Gradius at 866-710-0308 for immediate incident response guidance. Do not restart affected systems — a restart may overwrite memory that contains evidence of how the attacker gained access. Do not run antivirus scans on affected systems — scanning alters file timestamps that forensic analysis relies on. Do not delete files or logs in an attempt to "clean up" — this is evidence destruction that may create additional legal exposure. Do not alert the attacker that they've been detected if you have evidence of an ongoing intrusion — this may cause them to accelerate damage or destroy evidence. Do notify your cyber insurance carrier as soon as possible — most policies have timely notification requirements that, if missed, can affect coverage. Document what you observed and when. Then call Gradius and let incident response professionals take it from there.
Yes, in most cases — and the specific requirements depend on what data was involved and where affected individuals reside. New Jersey's breach notification law requires notification to affected NJ residents and the NJ Attorney General when personal information — including name plus financial account numbers, Social Security numbers, driver's license numbers, or medical information — is compromised. New York's SHIELD Act requires notification to NY residents and the NY AG under similar circumstances, and also requires businesses to maintain reasonable cybersecurity safeguards. Connecticut's breach notification law has comparable requirements. If health information was involved, HIPAA breach notification requirements apply separately — with 60-day individual notification and HHS reporting. For businesses with customers in multiple states, breach notification obligations may extend to every state where affected individuals reside. The timing of notification matters: NJ requires "in the most expedient time possible," NY requires "in the most expedient time possible and without unreasonable delay." Gradius identifies all applicable notification obligations and helps coordinate the response.
A security incident is any event that threatens information security — a failed login attempt, malware that was blocked, a phishing email that was caught by a filter, suspicious activity that was investigated and found to be benign. A data breach is a specific type of security incident in which personal information or protected data was actually acquired, accessed, or used without authorization. Not every security incident is a data breach — and not every breach triggers notification obligations. The forensic assessment after a security incident determines whether a notifiable breach occurred: what data was in the affected systems, whether the attacker had access to it, and whether there is evidence of exfiltration. The assessment is also important because HIPAA, for example, treats ransomware as a presumptive breach — the covered entity must demonstrate through a risk assessment that PHI was not accessed, rather than simply assuming it wasn't.
Notification timelines vary by law. New Jersey: "in the most expedient time possible and without unreasonable delay" — no specific number of days but regulators interpret this as prompt notification. New York (SHIELD Act): "in the most expedient time possible and without unreasonable delay." Connecticut: notification must be made "without unreasonable delay." HIPAA: covered entities must notify affected individuals within 60 days of discovery; if 500 or more individuals in a state are affected, HHS must be notified immediately (rather than in the annual log). NY DFS Part 500: cybersecurity events must be reported to DFS within 72 hours. Cyber insurance: policies typically require prompt notification, often within 24-72 hours of discovery, as a condition of coverage. The fastest notification timelines — DFS 72 hours, cyber insurance immediately — mean the clock starts the moment a breach is discovered, making it critical to engage incident response professionals immediately so notification decisions are based on a real forensic assessment rather than worst-case assumptions.
Post-breach security improvement starts with closing the specific gap the attacker exploited — the credentials that were phished, the unpatched system, the missing MFA, the network that wasn't segmented. But effective long-term breach prevention requires addressing the full attack surface: DMARC and advanced email security to stop phishing before it delivers; MFA on every account so stolen credentials can't log in alone; EDR on every device to catch attacks that get through email filtering; patch management to close known vulnerabilities before they're exploited; and 24/7 SOC monitoring to detect the attacks that get through all the other layers before they cause significant damage. Gradius offers post-breach enrollment in the full managed security program — implementing all of these controls and monitoring them continuously so the hardened post-breach posture doesn't degrade over time.
No long-term lock-ins for the managed security program. We offer month-to-month and annual agreements. Active incident response is engaged as needed — there is no requirement to be a managed IT client to receive breach response assistance, though managed IT clients receive priority response. Post-incident, most businesses enroll in the managed security program to maintain the hardened posture and ensure the security controls that address the breach vector remain active. We earn the renewal every month through performance.
Gradius IT Solutions serves businesses throughout the Tri-State area. Headquartered in Hackensack, NJ with coverage across Bergen, Hudson, Passaic, Essex, Union, Morris, Middlesex, Somerset, Sussex, Westchester, Rockland, and Fairfield Counties.