Stop the breach, preserve the relevant evidence — emails, logs, documents — without altering any of it, and make no formal statement before you have a legal assessment. Then open an internal investigation with a defined scope, and work out which notification duties the nature of the incident actually triggers.
Those duties are specific rather than general. If it is a personal data breach, notification to the Board and to the individuals concerned arises within a reasonable time under the Personal Data Protection Law (No. 6698). If there is a financial or criminal dimension, separate notification duties and sanction exposure come with it. From the findings you then plan the corrective actions, establish where responsibility lies, and put in the controls that stop it happening again. Early, systematic, documented intervention markedly reduces both the administrative sanction risk and the reputational damage; steps taken in a panic usually make things worse.
Shall we apply this matter to your situation?
Tell us your specific situation in a few sentences; we'll assess it with the right team.