The breach tower · the atrium
Data breach: the tower, floor by floor
This is the entrance to the data breach tower. Almost everybody arrives here on the same day: a company has written to say something happened, or a browser has put a warning next to a password, and the question is how worried to be.
The honest headline is that this is survivable and mostly free to fix, and that the order you do things in matters far more than which product you buy. The floors above are arranged in that order. Check what is actually out, understand what that particular kind of data is worth to somebody, close the doors that are open, and only then decide whether any monitoring service is worth a subscription.
The second thing worth knowing is that a breach is rarely about you. Your details were sitting in a company’s database alongside several million other people’s, and that company was the target. Nothing you did caused it and no password of yours was guessed. What you control is entirely on the other side of the event: whether the password that leaked was used anywhere else, and how fast you close that off.
Three levels, and you are on the first. The atrium lists the floors; a floor covers one subject completely and holds the shorter guides underneath it. Nothing here is more than three clicks from the front door.
One more thing before you climb, because it changes how the whole building reads. There is a difference between your data being in a breach and your accounts being at risk, and the two are constantly presented as the same thing by companies with something to sell. Being in a breach is nearly universal: if you have used the internet for a decade, you are in several, and finding out is useful rather than alarming. Being at risk is a narrower and more answerable question — it depends on what leaked, whether that password protects anything else, and whether a second factor stands behind it. The floors above are built to move you from the first question to the second as quickly as possible, because the second is the one you can actually do something about.
Where to start
Five ways in. If you only have five minutes, take the first and then the third.
- “Am I in a breach at all?”
- Start with checking
- “A company emailed me to say I was.”
- Read what that means in what leaked
- “What do I do right now?”
- Go straight to the first hour
- “Should I pay for monitoring?”
- The honest answer is in monitoring and after
- “My card details were in it.”
- That is a specific floor in what leaked
- “It was my child’s school that was breached.”
- There is a floor for that in what leaked
Checking
Finding out what is actually out there, using services that do not charge for it and do not need anything from you beyond an address.
What leaked
Not all breaches are the same event. What was taken decides what can be done with it, how long it stays dangerous, and whether you need to act at all.
The first hour
What to do, in order, on the day you find out. Every step here is free, and the first three cover most of the risk.
Monitoring and after
The subscriptions sold on the strength of this fear, what they can genuinely see, and the free alternatives that do most of the same work.
What this tower will not do
It will not frighten you into a subscription. Fear is the entire marketing engine of this category, and most of what those services do — telling you that you appear in a leak — is available free and takes thirty seconds. The floors say clearly which parts are genuinely worth money and for whom.
It will not tell you to change every password you own every few months. That advice makes passwords weaker rather than stronger, the standards bodies dropped it deliberately, and the floors above explain what replaced it.
And it will not pretend a breach can be undone. Once data is out it is out, copies exist, and no service can retrieve them. What can be changed is what that data still unlocks, which is almost always more than people assume and entirely within their control.
A note on how these floors are sourced, because this subject is unusually full of confident numbers with no origin. Where a floor says what a checking service does with your address, that is quoted from the service’s own documentation with the date we read it. Where it describes what a company owes you after losing your data, it points at the regulation rather than paraphrasing it. And where the honest answer is that nobody knows — how many copies of a given dump exist, for instance — the floor says that instead of inventing a figure. What holds instead is simple: nearly every step in this tower costs nothing at all, and no floor carries an affiliate link.
Written by Alberto Gulotta
Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.
Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.
Independence and limits
No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.
This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.