Blog Post

When Notification Cost Scales With the Subscriber List

September 23, 2026

Table of Contents

Notification appears in every breach cost model as a line item. A per-record figure multiplied by the records affected, sitting alongside forensics, legal and remediation.

At subscriber scale that line stops being a component. A carrier holding tens of millions of customer records faces a notification exercise that can exceed everything else combined, and the structure of the obligation means the cost is not a multiplication at all.

Which Obligations Apply?

Two, with different triggers and different consequences, and conflating them produces the wrong estimate.

Federal notification goes to the Commission, the Secret Service and the Bureau through a central facility, no later than seven business days after a reasonable determination that a breach occurred. The rule sets that timetable and it applies where five hundred or more customers are affected or where there is a risk of customer harm.

Federal Notification Is Automatic at Scale

A five hundred customer threshold is met by almost any incident at a carrier of any size, so the federal filing is close to certain in every scenario worth modeling. Its cost is a fixed process expense rather than a variable one, and it is not where the money goes.

Is Customer Notification Mandatory?

Not always, and this is the provision that determines the entire shape of the loss.

Per-event impact summary showing median loss with the first and ninety-ninth percentile range, alongside equivalent ranges for duration and records affected
A range for records affected is the input that matters most where the obligation to notify turns on a determination rather than on a count.

A 2023 order eliminated the customer notification requirement where a carrier can reasonably determine that no harm to customers is reasonably likely to result from the breach. The same order removed the mandatory waiting period that previously stopped carriers notifying customers until seven business days after law enforcement.

The Cost Becomes Bimodal

Either the determination can be made and supported, in which case customer notification is zero, or it cannot, in which case the notification covers everybody affected. There is no middle, so a per-record cost curve describes a distribution that does not exist. The loss has two modes separated by whether a determination holds.

What Does the Determination Require?

Evidence about what was accessed and whether it is usable, which either existed before the incident or cannot be produced afterward.

Establishing that harm is not reasonably likely means showing what data was reached, whether it left, and whether what left is exploitable. Access records scoped to the affected systems, a classification telling you what those systems held, and confirmation about exfiltration are the three inputs. None can be reconstructed retrospectively with any credibility, which a trail that records activity without attributing it fails on for a related reason.

Which Makes This the Highest-Value Control Here

Prevention reduces how often the scenario occurs. The determination capability decides which mode the cost lands in when it does, and the difference between the modes at subscriber scale is larger than most prevention investments could plausibly return, which pricing a capability by what it removes sets out as a general approach.

What Changed on the Frequency Side?

Considerably more than the notification provisions, and it is routinely overlooked.

Breakdown of extreme annual loss by damage type showing which categories contribute most at the one-in-hundred level
Where one damage category dominates the extreme case, the breakdown is what stops a single figure hiding it.

The definition of a breach was widened to cover inadvertent access, use or disclosure of customer information rather than only intentional unauthorized access. The scope also moved from network information alone to customer personally identifiable information generally.

Operational Error Is Now in Scope

A misconfigured storage location, a report sent to the wrong recipient or an over-permissioned internal query are all capable of triggering the obligation. Those occur far more often than successful external attacks, so a model weighted toward adversarial scenarios understates frequency substantially, and the frequency side of a model has the same problem for a related reason.

How Should the Two Modes Be Modeled?

As separate scenarios with a probability between them rather than as one distribution with a per-record multiplier.

The first scenario is a breach where the determination holds, costing the investigation, the federal filing and remediation. The second is one where it does not, adding a notification exercise across the affected population plus whatever follows from a public disclosure at that scale. The weighting between them is the probability that the evidence supports the determination, which is a property of your logging rather than of the attacker.

What Is That Probability?

Estimable from your own history. Take the last several security investigations and count how many reached a defensible conclusion about what was accessed within the available window. The proportion is the weighting, and it is a measurement rather than a judgment, which cyber risk quantification can then apply across the scenario set.

Does State Law Change the Answer?

Frequently, and it is the reason a federal-only analysis understates the position.

The federal rule does not supersede state requirements except where they are inconsistent with it, and then only to the extent of the inconsistency. So a carrier able to rely on the federal harm exemption may still face notification duties under state law for the same event, applied per state with different thresholds and different timetables.

The Exemption Is Partial

The determination removes a federal obligation and does not necessarily remove the exercise. A carrier with a national subscriber base is subject to many state regimes at once, so the realistic question is what proportion of the affected population sits in jurisdictions whose rules the determination does not satisfy.

What Does the Notification Itself Cost?

More than the per-message figure, because at population scale the message triggers a second wave of cost nobody budgets for.

Producing and delivering notices is the visible part and the cheapest per unit. What follows is a support volume, since a proportion of recipients contact the carrier, and at tens of millions of notices even a low response rate produces a contact volume exceeding normal capacity by a wide margin. Temporary staffing, extended hours and abandoned calls from ordinary customers all follow from a single mailing.

Which Makes It an Operational Event

A notification at that scale is a capacity problem rather than a communications exercise, and the cost lands in customer operations rather than in security. Modeling it as a per-record charge captures the postage and misses the call center, which cost that accrues per hour rather than per record describes in a different setting.

Does Churn Belong in the Figure?

Cautiously, since attributing subscriber losses to a notification is contested and the effect varies enormously with the market. In a market with switching friction the effect is small, and in a competitive one with portability it is not. Stating the assumption explicitly and reporting the figure with and without it is more defensible than embedding an estimate nobody can examine.

What Should Be Established?

Four things, and the first two decide the mode.

Whether access records exist at sufficient resolution to establish what a compromised account or system could reach, per system rather than in aggregate. Whether a data classification exists that maps systems to the categories triggering the obligation. What proportion of past investigations reached a supportable conclusion inside seven business days. Then what the aggregate notification cost would be at full population, since that figure is the second mode and the one justifying investment in the first three.

The Exemption Is the Model

Notification at subscriber scale is not a per-record line item. Federal filing is close to certain in any scenario worth modeling, since the threshold is five hundred customers, and its cost is fixed. Customer notification is the variable, and it can be avoided entirely where a carrier can reasonably determine that no harm is reasonably likely. The cost is therefore bimodal rather than linear, with the modes separated by whether the evidence supports a determination, which is a property of logging rather than of the attack. The determination capability is worth more in this scenario than most prevention. The widened definition also brings inadvertent disclosure and operational error into scope, which raises frequency in a way adversarial models miss. Kovrr's cyber risk quantification models the two modes separately with a weighting drawn from your own investigation history.

To see notification exposure modeled as two scenarios rather than a per-record multiple, book a demo with our risk experts.

Shalom Bublil

Kovrr Co-founder & Chief Product Officer

Notification Exposure FAQs

Speak to an Expert

Which notification obligations apply to a carrier?

Is customer notification always mandatory?

Why is the notification cost bimodal?

What does the harm determination require?

What changed on the frequency side?

Does state law change the answer?