According to Article 33 – EU GDPR – “Notification of a personal data breach to the supervisory authority”; the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it.
Unless organization has not prepared for data breach – it’s impossible to achieve the timeline of 72 hours notification and but them in risk in front of regulatory bodies.