The situation
What Fiona was actually afraid of, when she called at eleven at night on a Friday of a long weekend, was not the ransomware note itself. It was that the two investors who were supposed to sign a financing agreement the following Wednesday would walk if they heard about this before the deal closed, and that the small subscription business she had built with Ngoc and Raymond over three years would lose the funding it needed to survive its next stage of growth. That fear, more than the technical problem sitting on their server, was what she led with on the phone.
The company sold a curated monthly product box, built up slowly while all three founders kept their day jobs, Ngoc as an administrative assistant and Raymond as a dental assistant, putting evenings and weekends into the business until it finally supported itself and Fiona was able to leave her own job to run it full time. By the time of the breach it was doing modest but real revenue, comfortably into six figures, with a customer database holding names, addresses, order histories and partial payment information for several thousand subscribers built up over three years of steady growth. The financing round they were closing, their first outside capital, was meant to fund a warehouse move and their first real hires beyond the three founders.
The ransomware hit their order management system on the Friday night before a long weekend, encrypting files and leaving a ransom note. Fiona found it while checking on a batch of orders that were supposed to ship Tuesday, the first business day after the holiday, and her first instinct was simply to see whether the shipment could still go out on time. It could not. Nobody on the founding team had any experience with a security incident, and their entire operational calendar for the coming week was already committed to due diligence calls and final document review for the financing round, calls that suddenly felt impossible to get through without saying something.
Raymond wanted to pay the ransom quietly and hope the whole thing disappeared before Wednesday. Ngoc thought that was reckless and possibly illegal. Fiona, caught between them, made the call to us instead, at eleven at night, because none of the three of them had any idea whether either instinct was right, and because every hour spent arguing about it was an hour closer to a closing date they were suddenly not sure they could honestly sign.
They came to us that same night wanting two things at once: someone to tell them what they were legally required to do about the breach, and honest advice on whether they had to say anything to the investors before the closing, at a moment when either answer could end the deal they had spent the better part of a year putting together.
What the documents showed
The first task was establishing what had actually happened, since a founder's instinct in a crisis is to assume the worst and act on it. We brought in a breach response specialist to work alongside our team, and within two days the forensic logs showed the attackers had accessed the order database but the encryption had been contained to a single server, one that did not hold the full payment card numbers, only the last four digits and billing names the payment processor had stored for reference. That distinction, invisible to the founders at eleven at night on a Friday, turned out to be the difference between a manageable notification and a genuine financial data disaster.
The incident logs and the company's own vendor agreement with its payment processor turned out to matter more than anything else in the file. The processor's contract confirmed that full card numbers were never stored on the company's own systems at all, they lived entirely with the processor under a compliant tokenized system Ngoc had set up two years earlier without fully appreciating how much it would matter now. Ngoc had chosen that provider mainly because it was cheaper to integrate than the alternative, not out of any particular security foresight, and it was a genuine relief to all three founders to learn that an ordinary cost decision from years earlier was doing so much protective work now. That single document changed the shape of the entire response, because it meant the exposure was limited to names, addresses and order history, not financial account numbers that could be used directly for fraud.
The company's own onboarding records also showed something useful: every subscriber had agreed to a privacy policy describing exactly what data was collected and how breaches would be handled, language Ngoc had adapted from a template two years earlier and largely forgotten about since. That policy gave the notification letter a foundation to build from rather than starting from nothing, since it had already set subscriber expectations about what the company collected and roughly how seriously it took protecting it.
Between the forensic findings and the existing contracts, what looked at midnight like a catastrophic exposure was, on paper, a contained one: a real breach requiring real notification, but not the kind of financial data disaster that would have justified panic among investors who read the documents carefully rather than reacting to the word ransomware on its own.
What we did
- Retained a forensic specialist within hours to isolate the affected server and determine the scope of the intrusion, because acting fast on containment mattered both for limiting the actual exposure and for demonstrating a prompt, responsible response if regulators or investors later asked what the company had done in the first hours after discovery, and because guessing at scope instead of confirming it would have driven every later decision off an unreliable assumption.
- Reviewed the payment processor agreement immediately to confirm what data the company itself actually stored on its own servers versus what lived only with the processor under a tokenized, PCI-compliant system, which turned out to be the single most important fact in the file and reshaped every notification decision that followed it, since the answer determined whether this was a financial data breach requiring far broader remediation or a contact information breach with a narrower, more manageable notification obligation.
- Assessed the notification obligation under Canada's federal private-sector privacy law, since Ontario has no general private-sector privacy statute of its own outside health information; concluded that the exposure of names, addresses and order history for several thousand subscribers created a real risk of significant harm under the statutory test, which made notifying both the affected individuals and the federal Privacy Commissioner mandatory rather than optional, and prepared that notice on a realistic timeline built around the actual facts rather than the closing date.
- Drafted a clear, plain-language notification letter to subscribers describing what was exposed, what was not, and what steps the company had taken to contain it, along with practical steps individuals could take to protect themselves, since a compliant notice has to give people something to act on, not just announce a problem. We avoided both alarmist language and understatement, since either creates more risk than the breach itself, one by triggering panic and cancellations, the other by inviting a credibility problem later.
- Advised the founders to disclose the breach to the investors proactively before closing, rather than waiting to see if it surfaced on its own, because a financing agreement signed without disclosure of a known material event creates far greater legal exposure than an uncomfortable conversation does, a point that took some convincing given how badly the founders wanted the deal to simply close on schedule.
- Prepared a short written summary for the investors setting out the forensic findings, the limited scope of the exposure, the remediation steps already taken, and the updated legal assessment of the company's residual risk, so the disclosure arrived as a managed update with a clear plan attached, rather than as a raw, alarming headline the investors would have had to interpret entirely on their own, without any context for how seriously the founders were taking it.
- Negotiated a brief extension of the closing date with investor counsel, four business days, to allow the investors' own advisors to review the forensic report and the payment processor agreement before signing, which avoided rushing a decision on either side and gave the investors room to ask their own questions directly instead of relying entirely on the founders' account of what had happened.
- Added updated data security representations to the financing documents reflecting the incident and the remediation completed, giving the investors documented comfort rather than a verbal assurance alone, and giving the founders a clear written record of exactly what they had disclosed and when, which mattered as much for protecting the company's own legal position as for reassuring the people writing the cheque.
The outcome
The financing closed, four business days later than originally scheduled, on materially the same terms the parties had negotiated before the breach. The investors' own counsel reviewed the forensic report and the payment processor agreement and concluded the exposure, while real, did not change their view of the company's underlying business or its security practices going forward, particularly once the remediation and updated representations were in place and the founders had shown they could handle a real problem competently under pressure.
The notification letters went out to affected subscribers within the timeframe the circumstances called for. A small number wrote back with questions, and a handful cancelled their subscriptions, but there was no wider customer exodus and no regulatory inquiry followed. The cost of the episode was mostly the forensic specialist's fee, a modest hit to that quarter's marketing budget to cover it, and the founders' time during what was already meant to be their busiest week of the year, spent on incident calls instead of the celebration they had originally pencilled in for closing day.
What made this a clear win rather than a near-miss was the decision to disclose before closing rather than after. Founders in a similar position are often tempted to stay quiet until the deal is signed, reasoning that the problem is smaller than it looks and the investors do not need to know yet. Here, disclosing early meant the investors could make an informed decision with full information, which protected the deal's legal footing and, in the end, cost the company only a short delay rather than a damaged relationship with the people funding its next stage of growth. A year later, the warehouse move and the first outside hires had both gone ahead as planned, and the incident had become, in Fiona's words, the story she now tells new hires about what actually happens when something goes wrong.
What you can learn from this
- Where your payment data actually lives, not where you think it lives, determines the real scope of a breach. Know your processor's contract before you need it in a crisis.
- Disclosing a material problem to investors before closing is almost always the safer legal position, even when the instinct is to wait and hope it resolves quietly first.
- A privacy policy written months or years earlier can become the operational foundation for your breach response. Keep it current, not just compliant on the day you wrote it.
- Fast containment matters as much for what it demonstrates about your response as for what it actually limits. Acting quickly is itself part of managing the legal exposure.
- A breach during a high-stakes deadline tests process, not just security. Build the disclosure conversation into your crisis plan before the crisis, not during it.
This is a corporate problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.