A breach notification is not a technical document. It is a legal one, written to a regulator's deadline by people whose job is to say what is true without saying more than is required, and reviewed by counsel who know that every sentence may be read back to them in court. Understanding that is most of the skill. The letter is accurate; it is also carefully bounded, and the boundaries are where the information is.

Nine years of restoring these stories for The Vault has left this desk with a working method, and the same six questions have held from Anthem in 2015 to the disclosures of last month. None of them requires technical expertise. All of them require reading the letter twice.

1. What is the difference between the three dates?

Every incident has at least three: when the intruder got in, when the organisation found out, and when it told you. A good notification gives all three. A cautious one gives the last and implies the second. If a letter says only "we recently became aware", the gap it is not describing is usually the story — Home Depot's intruders were inside from April 2014 and the confirmation came in September; Anthem's administrator noticed a query running under his own credentials on 27 January 2015 and the public heard on 4 February. When the dwell time is short, companies say so, because it is the one number that flatters them. Silence about it is itself a data point.

2. Is the number final, or is it first?

Early figures are estimates produced under time pressure, and they move in one direction more often than not. Target's forty million cards became "up to seventy million" people a month later. Yahoo's five hundred million became a billion in December 2016 and all three billion in October 2017. OPM's four million became twenty-one and a half million within five weeks. The exceptions are instructive too: TalkTalk's "up to four million" fell to 156,959 once the forensics were done, and the smaller number is the one that stood. Treat any figure in a first notification as a reading taken mid-investigation, and diarise the follow-up.

3. What exactly is the verb?

"Accessed" and "acquired" are not synonyms, and the choice between them is deliberate. Accessed means the data was reachable; acquired means it left. "May have been affected" describes the population the company cannot rule out, not the population it knows was harmed. "No evidence of misuse" is true on the day it is written and says nothing about the day after. None of these phrases is dishonest. They are precise, and reading them loosely is the reader's error, not the writer's.

A practical test: cross out every sentence that would still be true if nothing bad had happened. What remains is the disclosure. It is usually two or three sentences long, and it is usually in the middle.

4. What is conspicuously absent?

Notifications are complete about what they cover and silent about what they do not. If a letter enumerates names, addresses and dates of birth but never mentions passwords, ask whether passwords were in that system at all — and if they were, why they are not in the sentence. If it says card numbers were encrypted, ask where the keys were. The absence of a denial where a denial would be natural is worth more attention than most of the paragraphs that are there.

5. Who is making the claim?

Much of what circulates in the first week is not the company speaking. It is a researcher's estimate, a journalist's source, or the attacker's own listing on a leak site — and attackers inflate, because the number is the advertisement. Keep the three apart in your own notes. This magazine's house rule, applied to every edition in the archive, is that a threat actor's figure is reported as a claim and the victim's dispute is carried alongside it. Apply the same rule to your incident reporting and your executives will trust your numbers when it is your turn.

6. What does it ask you to do — and what does it not?

Credit monitoring is the standard offer, and it addresses identity fraud rather than the account you actually hold. If the exposed data includes the answers to security questions — mother's maiden name, first school, first car — no monitoring product helps, because those answers cannot be rotated. That is the case for treating knowledge-based authentication as spent, which the IRS learned in 2015 when attackers answered its verification questions correctly using data stolen from somewhere else entirely.

One closing note for anyone who may one day have to write rather than read one of these. The notifications that aged well were specific, early and unglamorous; they gave the three dates, labelled the estimate as an estimate, and said plainly what was not yet known. The ones that aged badly promised completeness too early. A number you have to revise upward three times does more damage than the larger number would have done on the first day.