# Set a time-to-notice for every door you opened

Leaks now run through access granted on purpose, so every channel that moves data needs a time-to-notice and an owner who judges what normal looks like.

**Type:** Brief
**Published:** 2026-10-08
**Author:** Kiteworks Marketplace team

This autumn's most instructive breach did not break in. A Danish company's lawful right to search the national population register was misused, allegedly through automated lookups, for about ten days in September. A register employee spotted it on October 2. Access like that exists to be used, so you cannot simply lock it. What you can decide is how long misuse may run before someone who understands it finds out.

## Every door that moves data needs a time-to-notice

Every channel that lets data out needs one number: how long misuse could run before someone who understands that channel would know. Most organisations set a recovery-time objective for outages and nothing for misuse of access they granted on purpose. That includes partner integrations, shared folders, lookup portals and AI connectors.

The past weeks show the cost of not having one. In Denmark, the [ministry responsible for the CPR register](https://fudm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/) said on October 5, 2026 that unauthorised persons had reached names, addresses and CPR numbers of about 8.8 million registered persons "by misusing a Danish company's lawful access to search information in the CPR system" (our translation). [Datatilsynet](https://www.datatilsynet.dk/presse-og-nyheder/nyhedsarkiv/2026/okt/datatilsynet-er-opmaerksom-paa-sag-om-opslag-i-cpr), the Danish data protection authority, says the numbers were allegedly retrieved through automated lookups, and [Ritzau](https://fagligsenior.dk/2026/10/05/cpr-laek-i-ti-dage-minister-erkender-svigt-i-sikkerheden/) reports the minister's view that the security around that company's access had not been good enough. In the United States, a flaw in a Defense Manpower Data Center file-sharing system left files reachable for roughly nine months before it was discovered, and a small number of unauthorized users accessed them, [SecurityWeek](https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/) reports. At Shinhan Bank, an outsider bypassed the normal authentication of a lookup service built for loan brokers, and [Herald Corporation](https://www.heraldk.com/article/2026100104545469433) reports the records were pulled by repeatedly entering changing query values. No single request had to look unusual; the pattern was in the repetition.

All three investigations are open; the point is not blame but a measurement most organisations lack.

## Your SIEM sees the events; only the owner can judge them

Your SIEM is the right place for real-time alerts, but only the owner of an access can judge whether normal-looking use is legitimate. Kiteworks can send its activity to the SIEM you already run [over syslog](https://www.kiteworks.com/platform/visibility/ciso-dashboard/), and that is where alerting on what looks hostile belongs.

Misuse of lawful access looks like business. A partner that pulls large volumes at quarter end is normal; the same partner pulling steadily for ten days in an ordinary month may not be. The [NIST Cybersecurity Framework 2.0](https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf) asks for both halves: monitoring personnel activity (DE.CM-03) and external service provider activity (DE.CM-06).

Give every high-volume identity (a partner, a service account, an AI agent) a named business owner who signs off its normal envelope once a year: expected volume, hours and folders. Let the SIEM's thresholds derive from that envelope, and route every step outside it to the owner, not only to the SOC queue.

## Run three clocks, not one

One cadence cannot serve both machines and people, so run three.

- **Real time, for machines.** The SIEM alerts on what looks hostile across everything you log.
- **Daily or weekly, for one question.** A Kiteworks admin asks [Activity Explorer](https://agents.kiteworks.com/catalog/audit-activity-explorer) the same aggregated question each time: what changed against the previous period, and which flags fired? The flags are plain rules, not scores: a category's daily volume above three times its period median, ten or more failures by one account within an hour, more than 100 downloads by one account in a day (adjustable), and activity outside the working hours you set. Because that question names no one, it is the one you can put on a cadence, for example with [Claude's scheduled tasks](https://support.claude.com/en/articles/13854387-schedule-recurring-tasks-in-claude-cowork). Decide three things first: whose Kiteworks admin account the run uses and who approved that standing access, where the answer lands and who reads it, and whether your Kiteworks connector is reachable from a scheduled run on your setup. Test that before you rely on it.
- **Monthly or quarterly, for owners.** The owner reads a saved report covering any period up to 12 months, read in 30-day windows and compared with the previous period. The report states how far back the log actually reached. [User Account Reviewer](https://agents.kiteworks.com/catalog/user-account-reviewer) adds dormant, locked and external accounts, and [Sharing Auditor](https://agents.kiteworks.com/catalog/sharing-auditor) shows where folder-level sharing opens access in the first place.

Daily thresholds miss low-and-slow use by design: a partner that stays under 100 downloads a day for a month trips no daily rule. Comparing periods narrows where to look, because Activity Explorer shows the change by app, by activity category and in the share of external users. Following one account's trend is a person-level question, and it belongs to a case or to your SIEM, not to the routine report.

## Count AI agents as a population of their own

An AI agent with a connector acts with a person's permissions at machine speed, so its activity deserves its own baseline. Kiteworks says every AI-initiated operation through [Kiteworks MCP](https://developer.kiteworks.com/mcp-overview.html) is logged to its audit trail, and Activity Explorer gives activity from the Kiteworks MCP client its own section in every saved report, including when it is zero, with its failures. It counts only that client: an automation that calls Kiteworks through another app shows up under that app, so know which of your integrations is which. A rise in failed agent actions is worth a question to whoever approved the connector.

## The review record is your evidence

Logs prove that events happened; only a review record proves that someone looked and decided. For each cycle, keep the date, the reviewer, the period, how far back the log reached and the flags. Record one decision per flag: expected, tune the SIEM rule, narrow the access, or open a case.

Watch patterns before people. Activity Explorer starts from aggregates, never shows IP addresses or locations, opens a per-person view only with a case reference, and asks for approval before a saved report names anyone. That covers one tool, not your programme: the same activity in your SIEM carries account names and IP addresses. Before the first run, agree with your data protection officer and, where you have one, your works council on the legal basis and a DPIA for the whole review including the SIEM feed, on using review data for security and never for performance management, on how staff are told, and on how long records that name someone are kept.

Five questions to set your own time-to-notice:

1. Which channels can move sensitive data out, and who owns each one?
2. For each channel, how long could misuse run before its owner would know, and is that acceptable?
3. Which channels feed your SIEM, and which have nobody reading them?
4. What one question does each owner want answered every week, and is it on a schedule?
5. Who signed off the last review, on what date, and what did they decide?

The first number you set will be wrong. Not having one is worse. If you want to work out time-to-notice for your Kiteworks channels with us, email `sales@kiteworks.com` or [start a conversation](https://agents.kiteworks.com/contact?source=resource-time-to-notice). You do not need Claude or MCP setup to ask. For the permission half of the question, see [Review what your suppliers can still reach](https://agents.kiteworks.com/resources/review-what-suppliers-can-reach).

## Sources

- [Omfattende uautoriseret adgang til borgeres CPR-oplysninger](https://fudm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/), Forsknings-, Uddannelses- og Digitaliseringsministeriet (Denmark), 2026-10-05
- [Datatilsynet er opmærksom på sag om opslag i CPR](https://www.datatilsynet.dk/presse-og-nyheder/nyhedsarkiv/2026/okt/datatilsynet-er-opmaerksom-paa-sag-om-opslag-i-cpr), Datatilsynet, 2026-10-05
- [CPR-læk i ti dage: Minister erkender svigt i sikkerheden](https://fagligsenior.dk/2026/10/05/cpr-laek-i-ti-dage-minister-erkender-svigt-i-sikkerheden/), Faglig Senior (Ritzau), 2026-10-05
- [Pentagon Personnel Agency Data Breach Impacts 3 Million People](https://www.securityweek.com/pentagon-personnel-agency-data-breach-impacts-3-million-people/), SecurityWeek, 2026-09-29
- [대출모집인 전용 서비스 '보안 구멍'…신한은행 정보유출 원인](https://www.heraldk.com/article/2026100104545469433), Herald Corporation, 2026-10-01
- [CISO Dashboard](https://www.kiteworks.com/platform/visibility/ciso-dashboard/), Kiteworks
- [The NIST Cybersecurity Framework (CSF) 2.0](https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf), National Institute of Standards and Technology, 2024-02-26
- [Schedule recurring tasks in Claude Cowork](https://support.claude.com/en/articles/13854387-schedule-recurring-tasks-in-claude-cowork), Anthropic
- [Kiteworks MCP overview](https://developer.kiteworks.com/mcp-overview.html), Kiteworks

## Related agents

- [Activity Explorer](https://agents.kiteworks.com/catalog/audit-activity-explorer)
- [User Account Reviewer](https://agents.kiteworks.com/catalog/user-account-reviewer)
- [Sharing Auditor](https://agents.kiteworks.com/catalog/sharing-auditor)

Canonical URL: https://agents.kiteworks.com/resources/time-to-notice
