Cybersecurity · September 6, 2026 · intSignal Research

The Six-Month Silence: California Breaches Take a Median 174 Days to Surface

Share this article

Half a year between the breach and the notice

When a California organization breaches the personal information of more than 500 residents, it must file a sample notice with the state Attorney General, who publishes the register. That register is one of the few incident-level records of how breaches actually unfold in the state — and intSignal Research analyzed the complete public export: 1,536 notices reported between January 2024 and August 2026.

The central finding is uncomfortable. For the 1,442 notices that list a usable breach date, the median gap between when the breach occurred and when it was reported to the Attorney General was 174 days — roughly six months. Only 4.2 percent of notices arrived within 30 days of the breach; 13.6 percent within 60 days. Forty-nine percent took longer than six months, and 16 percent took longer than a full year. The longest gap in the window approached ten years.

What the 174 days does — and doesn't — measure

It is worth being precise, because this figure is easy to misread. California's legal clock runs from discovery of a breach, not from when it occurred. A long occurrence-to-notice gap is therefore not, by itself, a legal violation — an organization can discover a breach months after it happened and still notify promptly from that point.

What the gap does measure is the exposure window: the stretch of time during which affected Californians' data was compromised but they had not yet been told through this channel. Across the register, that window is typically about six months. For a business, the takeaway is not that everyone is breaking the law — it is that breaches routinely go undetected and unreported for a long time, and detection speed is the variable you actually control.

Why SB 446 turns this into a measurable question

In October 2025, California replaced its long-standing "most expedient time possible" notification standard with a fixed deadline. Under SB 446, organizations must notify affected Californians within 30 calendar days of discovery, and the Attorney General within 15 calendar days after consumers are notified, for breaches affecting more than 500 California residents.

The early data hints at a shift. Among notices filed in 2026 for breaches that began on or after January 1, 2026 — the first cohort arising fully under the new regime — the median occurrence-to-notice gap was 70 days, and 41.7 percent arrived within 60 days. That is markedly faster than the legacy pattern. But two cautions apply: that early cohort is right-censored (slower notices for 2026 breaches simply have not arrived yet, so the true median will rise), and even in this fastest-available group, only 13.6 percent of notices arrived within 30 days of the breach occurring. The full 2026 cohort will be the first year SB 446 compliance can be meaningfully benchmarked.

What this means for your business

SB 446's 30-day clock starts at discovery, which makes two capabilities decisive:

  • Detection that shortens the silence. The exposure window is long primarily because breaches go unnoticed. Continuous monitoring and response — a managed SOC or MDR capability — is what turns a six-month silence into a same-week discovery.
  • Readiness to investigate and notify inside a month. Once you discover a breach, 30 days is not long to scope it, identify affected residents, and notify. That requires logging sufficient to reconstruct what happened, a tested incident-response plan, and counsel and notification vendors identified before the incident — not during it.

The organizations that will meet SB 446 comfortably are the ones that can answer "when did we find out, and what was taken?" in days. The register suggests most have historically operated nowhere near that speed.


The figures in this article are drawn from the California Cybersecurity Risk Report 2027 by intSignal Research, where each is traced to its source, method, and limitations, and the full breach-register capture and analysis scripts are published for independent verification.

Share this article