{"id":58842,"date":"2025-06-18T16:00:00","date_gmt":"2025-06-18T16:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=139469"},"modified":"2025-06-18T16:00:00","modified_gmt":"2025-06-18T16:00:00","slug":"data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/","title":{"rendered":"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b"},"content":{"rendered":"<p><span data-contrast=\"auto\">Seventy-four percent of organizations surveyed experienced at least one data security incident with their business data exposed in the previous year as reported in Microsoft\u2019s <\/span><a href=\"https:\/\/aka.ms\/datasecurityindex\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Data Security Index: Trends, insights, and strategies to secure data<\/span><\/span><\/a><span data-contrast=\"auto\">\u202freport.&nbsp; Despite the best people, process and technology we can apply to prevent it, confidential information is sometimes improperly exposed.&nbsp; Depending on the specifics of the incident, organizations must report these breaches to regulators, customers or other stakeholders.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Regulatory standards like General Data Protection Regulation (GDPR), Gramm-Leach Bliley Safeguards (GLBA), Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPAA), Network and Information Systems Directive 2 (NIS2), SEC Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rules and an ever increasing list of others require disclosure of data breaches to regulators and potentially to customers or other stakeholders.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">The requirements to report after an organization discovers the breach can be demanding.&nbsp; For instance, under GDPR, any breach requires notification to the EU data protection authorities and potentially individual affected users within 72 hours from the time the breach is discovered.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">NIS2 requires and initial notification to the relevant national authority within 24 hours of detecting a significant cyber event and a detailed report within 72 hours.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">PCI-DSS requires merchants and service providers to immediately notify the credit card companies in the event of a breach.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Under the SEC rules, a company must file a Form 8-K within four business days of having discovered a material breach which must be done \u201cwithout unreasonable delay.\u201d&nbsp; Materiality is determined by management based on the risk posed to shareholders by the exposed data.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Organizations discover they\u2019ve had a data breach from their security tools, unusual system behavior, reports from employees, customers or law enforcement.&nbsp; Available information is often incomplete and scattered across systems.&nbsp; Understanding the true scope of the breach is challenging.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Scoping the breach is an exercise not only in enumerating files and instances of sensitive information but also understanding the context, what data is sensitive, and the degree of risk the various exposed data presents to the organization and its stakeholders.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Management often turns to the CISO to understand the scope and risk of the data exposed to inform the organization\u2019s reporting.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">There can be a huge volume of information available from the organization\u2019s IT systems that must be reasoned over in a short time.&nbsp; Context is important as are semantics to understand the scope of the breach and risk to the organization, customers, other data subjects, employees and shareholders.&nbsp; There will be high demand on the information security team and its service providers.&nbsp; A force multiplier, in the form of artificial intelligence is needed to scope data breaches accurately and efficiently.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">DSI, an integrated part of the Microsoft Purview Data Security solution, allows an administrator to search Microsoft 365, locates documents, emails, Teams messages, Copilot prompts and prompt returns relevant to a data breach.&nbsp; Customers can also upload non-Microsoft 365 data to a SharePoint site for analysis.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">DSI reasons over the impacted data with Azure OpenAI, categorizes it in terms of the specific risks it poses to the organization e.g. credentials, customer information, health, financials and a range of other types of data exposed.&nbsp; It goes beyond keywords using deep content analysis to understand the nature and risk severity of the data.&nbsp; This can be part of determining the materiality of a breach for reporting purposes.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span class=\"lia-media-object lia-media-is-no-align lia-media-size-large\" data-image-alt><button aria-labelledby=\"TzXNW8_caption\" class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image <span data-ccp-props=&quot;{&amp;quot;134245418&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:120,&amp;quot;335559740&amp;quot;:360}&quot;><span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;>Figure <\/span><\/span><span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;>1<\/span><\/span><span data-contrast=&quot;none&quot;> <span data-ccp-parastyle=&quot;caption&quot;>&#8211; E<\/span><span data-ccp-parastyle=&quot;caption&quot;>xposed data is <\/span><span data-ccp-parastyle=&quot;caption&quot;>automatically categorized and assessed for risk severity by AI<\/span><\/span><\/span>&#8220;><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDI0OTUwLVR6WE5XOA?image-dimensions=999x558&amp;revision=4\" width=\"999\" height=\"558\" alt><\/button><span class=\"lia-media-caption-text\" id=\"TzXNW8_caption\"><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\"><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\">Figure <\/span><\/span><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\">1<\/span><\/span><span data-contrast=\"none\"> <span data-ccp-parastyle=\"caption\">&#8211; E<\/span><span data-ccp-parastyle=\"caption\">xposed data is <\/span><span data-ccp-parastyle=\"caption\">automatically categorized and assessed for risk severity by AI<\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span data-contrast=\"auto\">DSI can categorize and report on data based on predefined risks.&nbsp; It can also search for custom categories important to the investigator.&nbsp; It uses vector based semantic search to identify similar information and user intent even in the absence of keywords.&nbsp;&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">DSI understands data in multiple languages so it can categorize and respond to questions on data even if the investigator doesn\u2019t.&nbsp; DSI uses Copilot to assist the investigator throughout the examination with interactive answers to questions in natural language.&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span class=\"lia-media-object lia-media-is-no-align lia-media-size-large\" data-image-alt><button aria-labelledby=\"Z0jC8G_caption\" class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image <span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;>Figure <\/span><\/span><br \/>\n<span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;>2<\/span><\/span><br \/>\n<span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;> &#8211; DSI investigation page with scope and progress of the investigation with risk and mitigation reporting<\/span><\/span>&#8220;><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDI0OTUwLVowakM4Rw?image-dimensions=999x562&amp;revision=4\" width=\"999\" height=\"562\" alt><\/button><span class=\"lia-media-caption-text\" id=\"Z0jC8G_caption\"><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\">Figure <\/span><\/span><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\">2<\/span><\/span><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\"> &#8211; DSI investigation page with scope and progress of the investigation with risk and mitigation reporting<\/span><\/span><\/span><\/span> <\/p>\n<p><span data-contrast=\"auto\">Data breaches can result from the actions of external bad actors or trusted insiders.&nbsp; They can result from intentional or accidental exposure.&nbsp; DSI helps organizations to investigate all of these.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">DSI can launch an investigation directly from a case in Purview Insider Risk Management, coming soon, or an incident in Microsoft Defender XDR.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span class=\"lia-media-object lia-media-is-no-align lia-media-size-large\" data-image-alt><button aria-labelledby=\"lZeVwT_caption\" class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image <span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;>Figure <\/span><\/span><br \/>\n<span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;>3<\/span><\/span><br \/>\n<span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;> &#8211; DSI investigation can be initiated directly from a Purview Insider Risk Management case<\/span><\/span>&#8220;><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDI0OTUwLWxaZVZ3VA?image-dimensions=999x555&amp;revision=4\" width=\"999\" height=\"555\" alt><\/button><span class=\"lia-media-caption-text\" id=\"lZeVwT_caption\"><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\">Figure <\/span><\/span><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\">3<\/span><\/span><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\"> &#8211; DSI investigation can be initiated directly from a Purview Insider Risk Management case<\/span><\/span><\/span><\/span><\/p>\n<p><span data-contrast=\"auto\">DSI can also initiate an investigation from its own part of the Purview Portal with or without the use of predefined search templates.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">We\u2019re focusing on data breach reporting in this article but DSI is a full scope investigatory tool for data security. DSI correlates the compromised data and the users which interacted with the data so that the source of the leak can be identified.&nbsp; DSI examines the data for credentials, security risks and evidence of threat actor discussion, explains its assessment and suggests mitigations, helping in the investigation and remediation.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span class=\"lia-media-object lia-media-is-no-align lia-media-size-large\" data-image-alt><button aria-labelledby=\"v5UqS8_caption\" class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image <span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;>Figure <\/span><\/span><br \/>\n<span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;>4<\/span><\/span><br \/>\n<span data-contrast=&quot;none&quot;><span data-ccp-parastyle=&quot;caption&quot;> &#8211; DSI visualizes the correlations between exposed data and users<\/span><span data-ccp-parastyle=&quot;caption&quot;> that have interacted with the data<\/span><\/span>&#8220;><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDI0OTUwLXY1VXFTOA?image-dimensions=999x557&amp;revision=4\" width=\"999\" height=\"557\" alt><\/button><span class=\"lia-media-caption-text\" id=\"v5UqS8_caption\"><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\">Figure <\/span><\/span><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\">4<\/span><\/span><span data-contrast=\"none\"><span data-ccp-parastyle=\"caption\"> &#8211; DSI visualizes the correlations between exposed data and users<\/span><span data-ccp-parastyle=\"caption\"> that have interacted with the data<\/span><\/span><\/span><\/span><\/p>\n<p><span data-contrast=\"auto\">Controls can be applied and vulnerabilities addressed to minimize the chances of a next data breach.&nbsp;<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Role Based Access Control (RBAC) ensures that only users authorized to work with DSI will have access to this sensitive information and can collaborate on the investigation securely.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">As part of scoping the DSI investigation, the investigator can triage, include or exclude data sources or locations, and deploy the AI to reason over the data, surface insights, risks, drill down and prepare reporting.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">DSI is a pay-as-you-go consumption billed service.&nbsp; An organization does not need a Purview license to use DSI.&nbsp; The ability to triage and scope allows the analyst to have predictable investigation costs.&nbsp;&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">DSI saves security teams time as they work to scope breaches accurately in the time allowed by regulatory requirements.&nbsp; It is an essential tool for data breach response, protecting the organization and allowing efficient, auditable compliance with regulatory standards.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/p>\n<p><strong><span data-contrast=\"auto\">If you\u2019d like to learn more about DSI:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/strong><\/p>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"30\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"none\">Try DSI<\/span><span data-contrast=\"none\">:\u202fYour Global Admin can begin using DSI by activating <\/span><a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/purview-payg-subscription-based-enablement\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Purview pay-as-you-go billing<\/span><\/span><\/a><span data-contrast=\"none\"> and provision Security Compute Units as part of the current Public Preview.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:360}\">&nbsp;<\/span><\/li>\n<\/ul>\n<p><em><span data-contrast=\"none\">\u200b<\/span><span aria-label=\"Rich text content control\"><span data-contrast=\"none\">\u200b<\/span><\/span><span data-contrast=\"none\">To learn more about Microsoft Security solutions, visit our\u202f<\/span><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">website.<\/span><\/span><\/a><span data-contrast=\"none\">\u202fBookmark the\u202f<\/span><a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Security blog<\/span><\/span><\/a><span data-contrast=\"none\">\u202fto keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<\/span><a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Microsoft Security<\/span><\/span><\/a><span data-contrast=\"none\">) and X (<\/span><a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener nofollow noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">@MSFTSecurity<\/span><\/span><\/a><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">)<\/span><\/span><span data-contrast=\"none\">\u202ffor the latest news and updates on cybersecurity.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/em><\/p>\n<p><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><em><strong><span data-contrast=\"auto\">Note: This document is provided \u201cas-is.\u201d Information and views expressed in this document, including URL and other Internet Web site references, may change without notice. You bear the risk of using it. This document is not intended to communicate legal advice or a legal or regulatory compliance opinion. Each customer\u2019s situation is unique, and legal and regulatory compliance should be assessed in consultation with their legal counsel.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:120,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/strong><\/em><\/p>\n<p>READ MORE <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-security-blog\/%E2%80%8B%E2%80%8Bdata-breach-reporting-for-regulatory-requirements-with-microsoft-data-security\/4424950\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Seventy-four percent of organizations surveyed experienced at least one data security incident with their business data exposed in the previous year as reported in Microsoft\u2019s Data Security Index: Trends, insights, and strategies to secure data\u202freport.<br \/>\nThe post Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":58843,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[],"class_list":["post-58842","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-18T16:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDI0OTUwLVR6WE5XOA?image-dimensions=999x558&amp;revision=4\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b\",\"datePublished\":\"2025-06-18T16:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/\"},\"wordCount\":1243,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations.png\",\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/\",\"name\":\"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations.png\",\"datePublished\":\"2025-06-18T16:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations.png\",\"width\":999,\"height\":558},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/","og_locale":"en_US","og_type":"article","og_title":"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-06-18T16:00:00+00:00","og_image":[{"url":"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDI0OTUwLVR6WE5XOA?image-dimensions=999x558&amp;revision=4","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b","datePublished":"2025-06-18T16:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/"},"wordCount":1243,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/06\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations.png","articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/","url":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/","name":"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/06\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations.png","datePublished":"2025-06-18T16:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/06\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/06\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations.png","width":999,"height":558},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/data-breach-reporting-for-regulatory-requirements-with-microsoft-data-security-investigations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Data Breach Reporting for regulatory requirements with Microsoft Data Security Investigations\u200b\u200b"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58842"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58842\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/58843"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}