Mission 45: The Executive Guide to New Mexico Data Breach Readiness
The 45-Day Clock Is Not the Time to Discover What Your Organization Doesn't Know
A cybersecurity incident can become a leadership problem within hours.
Technology may be compromised, but executives can suddenly face decisions involving customers, operations, attorneys, insurers, employees, vendors, finances, communications, and New Mexico law.
That is why breach readiness is an issue of executive due diligence.
Start With the Numbers
Several numbers help explain why New Mexico executives should prepare before an incident occurs.
1 Person
There is no general minimum number of affected New Mexico residents before individual notification requirements can apply.
A breach does not need to affect thousands of customers to matter.
That raises an immediate leadership question:
Do you know what personal information your organization possesses and where it resides?
Customer information may exist in email accounts, laptops, accounting systems, cloud applications, shared drives, mobile devices, backups, and third-party platforms.
If leadership cannot identify important information before an incident, determining what was affected afterward becomes considerably harder.
45 Days
When notification is required under the New Mexico Data Breach Notification Act, affected residents generally must be notified in the most expedient time possible and no later than 45 calendar days following discovery, subject to exceptions provided by law.
Not every incident requires notification. An appropriate investigation may determine that a breach does not create a significant risk of identity theft or fraud.
But consider what may need to happen while that determination is being made.
Someone may need to determine what happened, what systems were involved, what information was accessed, which customers were affected, what legal obligations apply, what insurance requires, and what customers should be told.
Who has responsibility and authority for each decision?
Forty-five days is not preparation time.
Preparation should already have occurred.
More Than 1,000 Residents
When a single breach requires notification to more than 1,000 New Mexico residents, additional notification requirements involving the New Mexico Attorney General and nationwide consumer reporting agencies apply.
The 1,000-person threshold does not create a general exemption for smaller incidents.
The practical lesson is simple: size alone does not determine whether leadership needs to be prepared.
The Law Is About More Than Notification
Mission 45 begins with the 45-day requirement, but the New Mexico law addresses responsibilities beyond sending breach notices.
It includes requirements concerning reasonable security procedures, disposal of personal information when it is no longer reasonably needed, and security requirements involving certain service providers.
That raises questions leadership should be asking before an incident:
Do we know what sensitive information we possess?
Who is responsible for protecting it?
Who has access—and is that access limited to what each person needs?
Which outside providers possess our information?
Are relevant responsibilities addressed with those providers?
Do we retain information longer than necessary?
How does leadership know appropriate safeguards are actually in place?
These questions do not require executives to become cybersecurity technicians.
They require executives to exercise due diligence.
The Executive SAVE Test
SecureNM™ provides a simple framework for approaching that responsibility.
SEE
See what your important cyber risks and responsibilities are.
Leadership should understand what needs protection, what could materially disrupt the organization, what obligations may apply, and where specialized expertise may be required.
Seeing the risk does not mean knowing how to configure a network or investigate an attack.
It means knowing enough to recognize what matters and ask informed questions.
ASSIGN
Assign accountability for addressing them.
Someone should be responsible for cybersecurity operations. Someone should know when legal counsel is needed. Someone should understand insurance requirements. Someone should coordinate communications.
Executives do not need to perform every task.
They need to know who is accountable for getting it done.
VALIDATE
Validate that appropriate practices and safeguards are in place.
Assumption is not validation.
This is particularly important for smaller organizations where executives may have limited internal cybersecurity resources and rely heavily on outside providers.
Leadership needs ways to examine whether the practices it assumes exist actually do.
ENSURE
Ensure necessary actions are performed and weaknesses corrected.
Finding a weakness is not the same as correcting it.
Executive due diligence includes following important issues through to resolution and obtaining enough information to know that necessary action occurred.
SEE. ASSIGN. VALIDATE. ENSURE.
Then repeat.
Due Diligence Is Not Due Care
This distinction is fundamental to Mission 45 and SecureNM™.
Executive due diligence is leadership's responsibility to understand risk, establish accountability, ask informed questions, validate readiness, make decisions, and ensure appropriate action.
Due care is the work required to protect the organization. That can include implementing technical safeguards, configuring systems, providing legal advice, managing insurance, investigating incidents, restoring operations, and performing other specialized work.
SecureNM™ focuses on executive due diligence.
Qualified internal personnel and professional providers perform the due care appropriate to their responsibilities and expertise.
For smaller organizations, the same owner or executive may participate in both. The distinction is the responsibility being performed—not necessarily the person performing it.
Take the First-Hour Test
Imagine arriving at work tomorrow morning and learning that an employee's email account was compromised overnight.
The mailbox contains customer information.
Could leadership quickly answer:
Who is in charge?
What customer information might be involved?
Who investigates?
Who contacts the technology provider?
Who contacts insurance?
When should legal counsel become involved?
Which vendors may need to participate?
Who documents what happened and when it was discovered?
Who communicates with customers?
Could the organization continue operating if affected systems became unavailable?
If several answers are “I don't know,” “I'm not sure,” or “I assume someone handles that,” you have discovered something valuable before an actual crisis forced the discovery.
You have identified an executive due diligence gap.
45 Questions Before the Clock Starts
SecureNM™ has developed a 45-question Executive Due Diligence Assessment™ to help leaders examine those responsibilities systematically.
The assessment covers executive governance, information and data, people and access, technology, third parties, incident readiness, business resilience, legal and insurance responsibilities, and executive verification.
Every question can be answered:
YES — UNSURE — NO
“Unsure” matters.
It means leadership has identified something that should be investigated rather than assumed.
The assessment does not certify cybersecurity compliance or prescribe technical solutions. It helps executives determine where they have sufficient visibility and where additional questions, assessment, professional expertise, or action may be needed.
Go Deeper When the Questions Require It
The Executive Due Diligence Assessment™ asks whether leadership is appropriately engaged.
The more comprehensive Cyber-safe Self-assessment™ helps examine what is actually happening throughout the organization.
That distinction matters.
An executive may discover through the 45-question assessment that leadership has never validated how employee access is managed.
The Cyber-safe Self-assessment™ can then help leadership engage employees, internal personnel, and providers in examining actual practices.
Where implementation or specialized expertise is required, appropriate professionals provide the due care.
SecureNM™ provides the structure for executives to keep asking the questions.
Leaving Level 0
Level 0 is not defined by organization size, cybersecurity budget, or technical sophistication.
An organization may have excellent technology and still operate at Level 0 in executive due diligence when leadership is disengaged, lacks visibility, or simply assumes someone else has everything covered.
A small organization with limited resources can begin leaving Level 0 immediately.
It starts with executive engagement SAVE:
SEE the responsibility.
ASSIGN accountability.
VALIDATE what's actually happening.
ENSURE necessary action occurs.
Cyber readiness is not a destination reached by completing one assessment. Executive due diligence is a continuing leadership responsibility.
The First Step Is Free
Mission 45 is not intended to turn New Mexico executives into cybersecurity professionals.
It is designed to help them become better-informed leaders of cyber-ready organizations.
SecureNM™ Community Membership is free.
Community Members can access the downloadable 45-question Executive Due Diligence Assessment™, the comprehensive Cyber-safe Self-assessment™, online self-assessment workshops, member surveys, and member event opportunities.
Professional Members can engage further through automated assessment tools, Cyber-safe Peer Review™ groups, committees, panels, and other collaborative programs.
Enterprise Members help advance the broader mission through association support, sponsored programs, and initiatives that can also be developed around their constituencies and business-development objectives.
Businesses, associations, customer groups, and communities can also request a Mission 45 presentation.
And if you simply have a question, contact us.
The problem can be complicated.
Getting started isn't.
SEE. ASSIGN. VALIDATE. ENSURE.
Join SecureNM™. Start assessing. Leave Level 0 well behind.
www.SecureNM.org(opens in new tab)
Sources
- New Mexico Data Breach Notification Act, NMSA 1978, §§ 57-12C-1 through 57-12C-12
- Federal Trade Commission, Data Breach Response: A Guide for Business
- Federal Trade Commission, Protecting Personal Information: A Guide for Business
- Cybersecurity and Infrastructure Security Agency, Small and Medium-Sized Business Resources