We had a data breach last year and it still ranks #2. Is that fixable?
A year-old data breach article at position 2 can usually be displaced, but it takes sustained work over six to twelve months. The article has accumulated authority that Google weights heavily; the interventions that succeed run in parallel, authoritative current content on operations and remediation, refreshed entity signals across Wikidata and the Knowledge Graph, source-level work on outlets still citing the article, and editorial correction requests where the article contains factually outdated claims.
A breach article that has been sitting at position 2 for a year is a recognizable problem and the answer is usually yes, it is addressable. But it requires understanding why the article has stayed there, then running the interventions that actually erode that position over time.

Why the article is still there
A year of ranking at position 2 means the article has accumulated authority, inbound links, citation patterns, and click signals that Google weights heavily. Content that ranks because of accumulated authority holds position through algorithm updates, while freshness alone is not enough to displace it. Google also weights high-authority sources heavily, making high-authority negative coverage harder to move than a result on a lower-authority domain. The article is not sitting there because the breach is still news; it is sitting there because its authority signals have compounded over twelve months.
Step 1: Build authoritative current content
The most important input to displacement is authoritative content covering the company’s current operations, its post-breach remediation steps, and what changed operationally as a result. This content needs to live on owned properties, the corporate site, the press hub, the newsroom, and be structured for extraction with clean headings, FAQPage or NewsArticle schema, and clear declarative statements. The goal is to give Google stronger, fresher, more current material to weight alongside the breach article. A single corporate site rarely carries enough authority signals on its own to displace a tier-one news article, so this step needs to be paired with the work below.
Step 2: Refresh entity signals
Refreshed entity signals across Wikidata and the Knowledge Graph reduce the relative weight the breach article carries in the entity context. When the engines see a well-structured, current entity, accurate Wikidata properties, updated sameAs links, complete Organization schema on the corporate site, an accurate Knowledge Panel; they have a richer set of authoritative reference points beyond the breach article. Google takes weeks to crawl and re-evaluate authority signals, and months for entity data to propagate through the Knowledge Graph and stabilize; this is foundational infrastructure work rather than a quick fix.
Step 3: Work the sources
Identify the outlets that have continued to cite the original breach article. Where those citations are in secondary coverage that is itself ranking, the source-level work is to pursue correction or update requests through editorial channels, most major outlets have correction processes and will update documented factual errors. Where the original article contains claims that are factually outdated (scope that has been clarified, timelines that have been corrected, regulatory conclusions that have been reached), the outlet’s editorial process is the appropriate path. Correction requests are private exchanges, not public statements, so they carry no reputational risk in filing.
Step 4: Track AI engine treatment with AIQ
AIQ monitors how the eight AI engines it currently tracks: ChatGPT, Copilot, Gemini, AI Overview, Perplexity, Grok, Claude, and Google AI Mode, are weighting the breach article over time. AI engines often continue citing a breach article in their responses long after the press cycle has ended and long after the SERP picture has begun to shift, because their training data and retrieval logic is slower to incorporate the refreshed entity signals than the live index. Tracking this across the engines AIQ monitors reveals which engines are still leading with the breach framing and which sources they are drawing on, so source-level interventions can be prioritized where they have the most leverage.
The realistic timeline
- Months 1, 2: Infrastructure built, owned content live, entity signals refreshed, AIQ monitoring active, source-level work filed.
- Months 3, 6: Early movement visible in AIQ data as engines begin weighting fresher authoritative material. SERP composition may begin shifting as the owned and earned content accumulates authority.
- Months 6, 12: Displacement is typically material and durable when all interventions are running in parallel. The breach article may drop from position 2, lose its dominance in the AI narrative, or be balanced by a richer SERP that includes multiple authoritative current results.
Pretending displacement can happen in weeks is what leads to short-term tactical work that fails. The article accumulated its position over twelve months; unwinding it takes sustained parallel work over a similar horizon.
Last reviewed: 19/05/2026