Skip to content
Pro IT NW

Field notes · 8 min read ·

Share

Washington's first data privacy report and the mid-market

There is no deadline here, and saying otherwise would be false. The Attorney General published a report and a set of policy priorities on August 14, 2026 — not a rule, not a bill, not an obligation. The reason to read it is that it is the office that would eventually write one, describing what it is seeing in this state.

Two things landed four days apart in August 2026, and they are more useful read together than apart.

On August 14, 2026, the Washington State Attorney General released the office's first-ever Data Privacy Report. On August 18, security firm Black Kite published research arguing that ransomware's primary target is not the enterprise but the mid-market. One is independent data on who actually gets hit. The other is our own state's enforcing office publishing what that looks like here, in Washington, with names on it.

Read this first, because it changes how you should read everything below. The Attorney General's report is a report. It states findings and identifies policy priorities. It is not a statute, not a rule, and not a regulation. Nothing in it imposes any obligation on any Washington business today. If you see a vendor describing it as a new compliance requirement, that is a sales pitch, not a reading of the document.

What the Attorney General actually published

The report is the first of its kind from the office, and its headline figures are specific. For 2025:

  • 209 data breaches reported.
  • More than 8 million Washington residents affected.
  • More than 80% of those breaches exposed Social Security numbers.

Alongside the findings, the report identifies policy priorities across three areas: strengthening baseline protections for personal data, bolstering privacy enforcement and institutional capacity, and raising the baseline of digital literacy in Washington. Those are the office's stated priorities. They are not a bill, and we are not going to guess at what the Legislature does with them or when — the report does not announce legislation and neither will we.

Why the local number is the one that should move you

If you run IT for a mid-market organization in the Puget Sound region, you have read a great many national breach statistics, and you have probably learned to discount them. That instinct is correct and it does not apply here.

209 breaches. Eight million Washington residents. Eighty percent with Social Security numbers. That is a named, on-the-record, in-state figure, published by the office that enforces this state's privacy statutes, drawn from breach notifications filed with that office. It is not a sample of a market you may or may not resemble. It is not a vendor's panel. It describes your neighbors, your employees, and in a great many cases your customers.

That is a materially better input for a budget conversation than any national survey, and it is worth using as one. When a CFO asks why the identity project matters, "the state Attorney General logged 209 breaches affecting eight million Washingtonians last year, four in five of them exposing Social Security numbers" is a sentence that survives the follow-up question. Most security statistics do not.

The second data point: who ransomware actually hits

Four days later, Black Kite published research reporting that 73% of ransomware victims from January 2023 through June 2026 were companies with $10 million to $1 billion in annual revenue — the mid-market, not the enterprise tier that dominates the headlines.

Disclose the interest in the same breath as the finding: Black Kite sells third-party cyber risk monitoring. A finding that the mid-market is under-attended and over-targeted is directly useful to their commercial position. We are citing it anyway, and here is the specific reason why.

The finding survives the methodology test, which most vendor statistics do not:

  • The sample is stated. 13,336 incidents with verifiable revenue data, plus external risk scans of 120,128 mid-market organizations across North America and Europe.
  • The period is stated. January 2023 through June 2026 — three and a half years, not one quarter.
  • The revenue band is defined against Dun & Bradstreet's revenue bands, not the author's own judgment.
  • It holds year over year. 74.6%, then 72.1%, then 74%, then 72.3% in the first half of 2026. A finding that repeats across four consecutive periods is not a one-year artifact or a sampling accident.

That is enough to take the headline seriously as a well-constructed vendor finding. It is not government data and we are not going to treat it as such. We are also deliberately not repeating the risk-scoring percentages the same research produces from Black Kite's own scanner — those measure the product's view of the world, and they are a different kind of claim than counting incidents.

Reading the two together

Put them side by side and the picture is unusually coherent for two unrelated publications four days apart. Independent incident data says the organizations most likely to be hit are in the revenue band that describes most of the companies in this region. Our own Attorney General says that in 2025, in this state, 209 breaches reached eight million residents and four in five of them spilled Social Security numbers.

The mid-market is not too small to be interesting. It is exactly the size that is interesting: enough revenue and enough regulated data to be worth an attacker's time, typically run by a security program sized for a much smaller organization — a lean internal team, heavy dependence on outside providers, and identity infrastructure that grew by accretion over fifteen years rather than by design.

The recommendations are a direction, not a due date

Here is the useful move for an IT director, and it is not "get ready for the law."

The report's three priority areas — baseline protections for personal data, enforcement and institutional capacity, and digital literacy — tell you where the enforcing office's attention is going. That is genuinely worth knowing, and it is worth knowing for a reason that has nothing to do with anticipating a statute: the work those priorities point at is work that reduces your breach risk today, whether or not anything is ever legislated.

Knowing where personal data lives in your tenant is not a compliance chore awaiting a trigger. It is the thing that determines how bad a bad day is. Controlling who can reach that data is not a future obligation. It is the control that most often fails in the incidents that produce breach notifications in the first place.

What to actually do, in order

If the two publications above move anything on your roadmap, move these — in this sequence, because each one makes the next cheaper.

  1. Inventory privileged access and Tier 0. Which accounts can create a domain admin, reset a password, or read any mailbox? Most mid-market environments cannot answer that from memory, and the gap between the org chart and the group memberships is usually years wide. This is what an Active Directory audit is for, and the ninety-day version of the remediation is written up in AD Tier-0 in 90 days.
  2. Verify MFA and Conditional Access coverage rather than assuming it. Not "do we have MFA" — nearly everyone does — but which accounts, paths, and legacy protocols are excluded from it, and who granted each exception. Exclusions accumulate quietly, and they are where the attested control and the enforced control diverge.
  3. Find the Social Security numbers. Four in five Washington breaches last year exposed them. Where do they live in your environment — which SharePoint sites, which mailboxes, which file shares, which line-of-business exports that someone set up in 2019 and nobody has looked at since? Sensitivity labels and DLP policy are the answer, but the inventory comes first, and it is ordinary Purview and permissions work.
  4. Apply the same scrutiny to your providers' tooling. Your MSP's remote-management agent runs as SYSTEM on every endpoint you own. It is Tier 0 whether or not anyone has classified it that way, and it belongs in the same review as your domain admins — see the eight questions to ask your provider.
  5. Reconcile it with what you have already attested to. If you carry cyber insurance, you have made written statements about these exact controls. The gap between the attestation and the enforcement is where claims get contested — the pattern is laid out in cyber-insurance readiness for the mid-market.

What we are not saying

Three things, stated plainly, because the temptation to overclaim on a story like this one is considerable.

  • We are not saying you have a new obligation. You do not. The report is a report. Nothing in it binds a Washington business today.
  • We are not predicting a bill. The report states policy priorities. It does not announce legislation, and we have no basis to guess at the content or the timing of any, so we will not.
  • We are not treating a vendor's research as government data. The Black Kite finding is cited above with its methodology and its commercial interest both on the table, precisely so you can weigh it accordingly.

Related reading

Sources

Every figure in this post comes from one of those two documents. Where we have paraphrased rather than quoted, that is deliberate: we are describing what the documents say, in our own words, rather than presenting reconstructed text as verbatim.

The 30-second version

On August 14, 2026 the Washington Attorney General released the office's first-ever Data Privacy Report: 209 breaches in 2025, more than 8 million Washington residents affected, more than 80% exposing Social Security numbers, with policy priorities spanning baseline data protections, enforcement capacity, and digital literacy. It is a report, not a law, and it obligates nobody today. Four days later, Black Kite — which sells third-party risk monitoring — published research putting 73% of ransomware victims between January 2023 and June 2026 in the $10 million to $1 billion revenue band, consistently across all four periods measured. Together: the mid-market is the target, and our own state's enforcing office has now put local numbers on what that produces. The response is not to wait for a statute. It is to inventory privileged access, verify MFA coverage rather than assume it, find out where the Social Security numbers actually live, and hold your providers' tooling to the same standard.

If you want a senior engineer to look at your privileged-access inventory and identity posture against the real environment, the project intake form takes about three minutes. Two-business-day response with scope and a fixed-fee range.


Pro IT NW is a Seattle-area consultancy doing senior-led, vendor-neutral, fixed-fee work on the Microsoft stack for the regulated mid-market: Active Directory audits and Tier-0 hardening, Entra ID hybrid identity, Conditional Access and MFA rollout, Microsoft Purview data governance and DLP, Copilot readiness, and GCC High and CMMC readiness. We do preventive engineering, not breach response or forensics — those are a separate discipline, and you want a specialist firm for them. Nothing here is legal advice; for questions about Washington privacy statutes and breach-notification duties, talk to counsel.

Questions we get asked

Does the Washington Attorney General's Data Privacy Report create any legal obligation?
No. The report, released August 14, 2026, is the Attorney General's first-ever Data Privacy Report. It presents findings about data breaches affecting Washington residents and identifies policy priorities. It is not a statute, not a rule, and not a regulation, and it imposes no new compliance requirement on any Washington business as of its publication. Anyone telling you that you now have to do something because of this report is selling you something. The reason to read it is different: it tells you what the office that enforces privacy law in this state is currently paying attention to.
What did the Washington Attorney General's 2026 Data Privacy Report actually find?
The report, released August 14, 2026, states that 209 data breaches were reported in 2025, affecting more than 8 million Washington residents, and that more than 80% of those breaches exposed Social Security numbers. It recommends action across three areas: strengthening baseline protections for personal data, bolstering privacy enforcement and institutional capacity, and raising the baseline of digital literacy in Washington. Those are stated as policy priorities, not as requirements now in force.
Is the mid-market really the primary ransomware target?
Research published August 18, 2026 by Black Kite reports that 73% of ransomware victims from January 2023 through June 2026 were companies with $10 million to $1 billion in annual revenue. The finding is drawn from 13,336 incidents with verifiable revenue data, using Dun & Bradstreet revenue bands, and it holds year over year — 74.6% in 2023, 72.1% in 2024, 74% in 2025, and 72.3% in the first half of 2026. Black Kite sells third-party cyber risk monitoring, so it has a commercial interest in the mid-market paying attention to risk. The methodology is stated plainly enough — defined sample, defined period, defined revenue band, consistent across four periods — that the headline holds up on its own terms. Read it as a well-constructed vendor finding, not as neutral government data.
Why does a state Attorney General breach number matter more than a national vendor survey?
Because of who produced it and where. The Washington Attorney General's figures come from breach notifications filed with the office that enforces the state's privacy statutes, they are on the record, they are attributed, and they describe Washington residents specifically. A national vendor survey is a sample drawn for a vendor's own purposes across a market you may not resemble. For a Seattle-area organization deciding where to spend a limited security budget, an in-state, on-the-record number from the enforcing office is a stronger input than any national estimate.
More than 80% of Washington breaches exposed Social Security numbers. What should an IT director do with that?
Treat it as a data-location question before a security-controls question. Most mid-market organizations cannot say, without checking, which SharePoint sites, mailboxes, file shares, and line-of-business exports contain Social Security numbers, or who has access to them. That inventory is the prerequisite for everything else — classification, DLP policy, access review, retention. It is ordinary Microsoft Purview and permissions work, and it is answerable in weeks rather than quarters.
Should we wait for Washington to pass a law before changing anything?
Waiting is a defensible budget decision and an indefensible security one. Nothing in the August 14, 2026 report obligates a change, and no bill has been announced — nobody can honestly tell you what Washington will legislate or when. But the work the report's priorities point at, principally knowing where personal data lives and controlling who can reach it, is work that reduces breach risk today regardless of what any future statute says. It is not compliance spend waiting on a trigger; it is the same identity and data-governance hygiene that would have been worth doing in 2024.
Our organization is under 500 employees. Are we too small to be a ransomware target?
The Black Kite figures argue against that assumption directly: 73% of ransomware victims between January 2023 and June 2026 were in the $10 million to $1 billion revenue band, not the enterprise tier. The intuition that attackers concentrate on the largest organizations is not supported by the incident data. The plainer explanation is that this band holds enough data and revenue to be worth attacking while typically running a security program sized for a much smaller organization — a small internal team, a heavy dependence on outside providers, and identity infrastructure that grew by accretion.
Where should a mid-market IT director start if the security budget only covers one project?
Start with identity, because it is the path most incidents actually take and the one that governs everything else. In practice that means an honest inventory of privileged accounts and Tier-0 assets in Active Directory, verified MFA and Conditional Access coverage on every remote and administrative path including the exceptions someone added years ago, and the same scrutiny applied to the remote-management tooling your providers use into your environment. Data classification is the natural second project; it is more valuable once you know who can reach the data.
Does Pro IT NW do breach response or digital forensics?
No. Pro IT NW is a senior-led, vendor-neutral consultancy working on the Microsoft stack: Active Directory audits and Tier-0 hardening, Entra ID hybrid identity, Conditional Access and MFA rollout, Microsoft Purview data governance and DLP, Copilot readiness, and GCC High and CMMC readiness. That is preventive engineering, done before an incident. Incident response and forensic investigation are a separate discipline handled by specialist firms and, usually, by your insurer's panel.

Written by the team at · Senior-led Microsoft project consultancy · Seattle / USA-wide.

Have a project on the runway?

Tell us the workload, the seat count, and the deadline. We'll come back inside two business days with scope and a fixed-fee range.