Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider working with Seattle-area businesses since 2005. This one is written for the chief executive rather than for the IT team.
A breach is a public relations and financial event, squarely in a CEO’s wheelhouse, and the CEO is ultimately responsible for the decisions that led up to it happening. That responsibility runs both before the breach and during the response to it.
The decisions that lead up to a breach
Day-to-day cyber security planning may sit with a CIO, CTO or CISO depending on the size of the organization, but cyber security spending is a bottomless rabbit hole – no amount of spend gets a company to fully secure. Risk assessment and budget allocation are therefore decisions made in coordination with the CFO and CEO, and sometimes the board, with the CEO as the ultimate arbiter of what gets funded: assessments, products and services, third-party validation, and the closely related area of business continuity and disaster response planning.
The decisions at the moment of breach
When a breach happens, the questions that matter first are whether the right information reached the people making decisions, whether budget was allocated appropriately based on what was known, whether the products and services that were funded were actually deployed properly, and whether there is a functioning business continuity plan to fall back on now that a breach has occurred anyway. From there, the CEO has a series of rapid decisions: when to initiate the disaster response plan, whether and when to notify insurers and law enforcement, whether and how to notify customers, and whether and how to notify vendors.
What Washington law actually requires
For a Washington business, customer notification is not discretionary. RCW 19.255.010 requires notice to affected consumers in the most expedient time possible, without unreasonable delay, and no more than 30 calendar days after the breach is discovered. State and local government agencies fall under the parallel statute, RCW 42.56.590. If more than 500 Washington residents are affected, the Attorney General must also be notified within that same 30-day window.
Enforcement runs through the Consumer Protection Act, under RCW 19.255.040, with civil penalties of up to $7,500 per violation, and separately, destroying or concealing public records is its own felony under RCW 40.16.010 and .020. What the statute does not do is set a per-record penalty – whether “per violation” scales with the number of affected residents is a matter of case law and enforcement practice, not something the statute itself states, and it should not be quoted as a fixed dollar amount per record.
What it actually costs
IBM’s Cost of a Data Breach 2024 report put the global average breach cost at $4.88 million, up 10% year on year and the largest single-year jump since the pandemic, with 70% of breached organizations reporting significant or very significant operational disruption. That is the honest scale of the consequence a CEO is managing, measured in cost and disruption rather than in a company’s odds of survival, which is not something any reputable source actually measures.
If it later comes out that a breach happened because of known deficiencies that were flagged and the remedy was vetoed, the consequence lands on the CEO personally, through dismissal, or on the company, through costs and disruption it cannot absorb. Either way, the CEO is engaged at virtually every point leading up to and following a breach, whether or not that was the plan.
Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.

