

What to do when you get hacked: Incident response and reporting duties for regulated businesses
Many organizations do not find out about a breach themselves. They hear it from a customer, a regulator, or the attacker's ransom note, often weeks after the intruders got in. By then, the technical clock and the legal clock are both running.
In 45 minutes, Yoann Garraux (LEXR) and Thomas Lentz (Trilight Defence) walk through what to do in the first hours after a breach, technically and legally, and how to use the incident to harden the organization for next time. The session closes with a live Q&A.
What you'll learn:
How breaches actually surface, and why silent systems mean nothing
What to do in the first hour, technically and legally
When your notification clocks start running under GDPR, DORA and FINMA reporting
Contractual and sector-specific duties for regulated businesses
How to use the incident to harden the organization for next time
Who should attend:
General Counsel, CISOs, Data Protection Officers, CFOs and board members with cyber oversight responsibility
Financial entities and their critical suppliers in scope of DORA and NIS2
Companies processing large volumes of personal data
Speakers:
Yoann Garraux is a Senior Associate in LEXR's Tech, Contracts and IP team. He advises technology and financial companies on data protection, contractual confidentiality and sector-specific reporting requirements after a security incident.
Thomas Lentz leads business development at Trilight Defence, a European offensive cybersecurity firm whose operators come from the front line of Ukraine's cyberwar. He works with financial institutions, digital-asset businesses and critical infrastructure operators across Switzerland and Europe.