For years, the response to a data breach has focused heavily on one question: Was personal information compromised? Increasingly, that is no longer the only question organizations need to ask. A cyber incident may trigger a regulatory reporting obligation even when no personal information was accessed, acquired, or disclosed and, in some jurisdictions, the reporting is required in as little as one hour.