We had a data breach last year and it still ranks #2. Is that fixable?
A year-old data breach article at position 2 can usually be displaced, but it takes sustained work over six to twelve months. The article has accumulated authority that Google weights heavily. The interventions that succeed run in parallel: authoritative current content on operations and remediation, refreshed entity signals across Wikidata and the Knowledge Graph, source-level work on outlets still citing the article, and editorial correction requests where the article contains factually outdated claims.
A breach article that has held position 2 for a year is a familiar problem, and the answer is usually yes: it is addressable. It takes understanding why the article has stayed there, then running the interventions that erode that position over time.

Why the article is still there
A year of ranking at position 2 means the article has accumulated authority, inbound links, citation patterns, and click signals that Google weights heavily. Content that ranks because of accumulated authority holds position through algorithm updates, while freshness alone is not enough to displace it. Google also weights high-authority sources heavily, so high-authority negative coverage is harder to move than a result on a lower-authority domain. The article is not there because the breach is still news. It is there because its authority signals have compounded over twelve months.
Step 1: Build authoritative current content
The main input to displacement is authoritative content covering the company’s current operations, its post-breach remediation steps, and what changed operationally as a result. This content needs to live on owned properties (the corporate site, the press hub, the newsroom) and be structured for extraction with clean headings, FAQPage or NewsArticle schema, and clear declarative statements. It gives Google stronger, more current material to weigh alongside the breach article. A single corporate site rarely carries enough authority signals on its own to displace a tier-one news article, so this step needs to be paired with the work below.
Step 2: Refresh entity signals
Refreshing entity signals across Wikidata and the Knowledge Graph reduces the relative weight the breach article carries in the entity context. When the engines see a well-structured, current entity (accurate Wikidata properties, updated sameAs links, complete Organization schema on the corporate site, an accurate Knowledge Panel), they have more authoritative reference points to draw on beyond the breach article. Google takes weeks to crawl and re-evaluate authority signals, and months for entity data to propagate through the Knowledge Graph and stabilize. This is infrastructure work, not a quick fix.
Step 3: Work the sources
Identify the outlets that have continued to cite the original breach article. Where those citations sit in secondary coverage that is itself ranking, pursue correction or update requests through editorial channels; most major outlets have correction processes and will update documented factual errors. Where the original article contains claims that are now factually outdated (scope that has been clarified, timelines that have been corrected, regulatory conclusions that have been reached), the outlet’s editorial process is the right path. Correction requests are private exchanges, not public statements, so filing one carries no reputational risk.
Step 4: Track AI engine treatment with AIQ
AIQ monitors how the eight AI engines it currently tracks (ChatGPT, Copilot, Gemini, AI Overview, Perplexity, Grok, Claude, and Google AI Mode) weight the breach article over time. AI engines often keep citing a breach article long after the press cycle has ended and after the SERP picture has begun to shift, because their training data and retrieval logic incorporate the refreshed entity signals more slowly than the live index does. Tracking this across the engines AIQ monitors shows which engines are still leading with the breach framing and which sources they draw on, so source-level interventions can be prioritized where they have the most leverage.
The realistic timeline
- Months 1, 2: Infrastructure built, owned content live, entity signals refreshed, AIQ monitoring active, source-level work filed.
- Months 3, 6: Early movement visible in AIQ data as engines begin weighting fresher authoritative material. SERP composition may begin shifting as the owned and earned content accumulates authority.
- Months 6, 12: Displacement is typically material and durable when all interventions run in parallel. The breach article may drop from position 2, lose its dominance in the AI narrative, or be balanced by a richer SERP that includes several authoritative current results.
Expecting displacement in weeks leads to short-term tactical work that fails. The article built its position over twelve months; unwinding it takes sustained parallel work over a similar span.
Last reviewed: 19/05/2026