Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Writing

Decide the Breach-Disclosure Questions Before You Have a Breach.

The tactical runbook is a comparatively solved problem. Materiality, the SEC's four-day clock, the OFAC ransom gate, and the external message are executive decisions to pre-wire with a standing disclosure committee — not to improvise at hour three.

By Michael YorkJune 7, 2026 9 min read 1,998 words All postsTable of contents

By hour three of a real breach, the tactical response is usually the calm part of the building. The incident commander is named. The evidence is preserved. The status cadence is running on the hour, and the engineers have room to work. The part that is not calm is the conference room next door, where four executives are discovering — in real time, on the worst day of the quarter — that nobody ever decided who gets to answer four questions. Is this material? When does the clock start? Can we pay? What do we say, to whom, and in what order?

Those four are not security questions. They are executive judgment calls with legal, financial, and reputational weight, and they are almost always improvised, because the people who own them have never been in the same room before the room was on fire. The tactical runbook — roles, evidence, comms cadence — is a comparatively solved problem, and plenty of teams rehearse it. The disclosure decisions sitting on top of it are the ones I still watch companies invent at hour three. Hour three is exactly the wrong time to invent them.

Materiality, the disclosure clock, the ransom question, and the external message are decisions to pre-wire in peacetime, with a standing body that owns them, not problems to reason out from first principles while a forensics timer runs. I run security, not the legal function — I am the person who ends up in that room, not the one who signs the filing. So read this as how a security leader reasons up toward those decisions and lays the track before the train, not as counsel. The shape is what matters, and the shape is knowable in advance.

Materiality is a determination, not a discovery

The SEC's cyber-disclosure rule turns on a single word. Item 1.05 of Form 8-K requires a public company to disclose a "material" cybersecurity incident, and material is not "did data leave the building." It is the old reasonable-investor standard — would this information matter to a reasonable investor's decisions — applied to a cyber event. The SEC deliberately declined to draw a bright quantitative line, which means the test is both quantitative (dollars, records, downtime) and qualitative (the nature of what was taken, the regulatory exposure, the damage to trust).

The trap is treating materiality as a fact you will eventually find in the logs. It is not discovered. It is determined — a judgment made by named people against a standard, on the record, with a timestamp. Nobody stumbles onto "material" while reading a packet capture.

If you are a private company, Item 1.05 does not bind you and you will never file an 8-K. You do not escape the concept. Your regulated customers ask the same question inside their vendor-incident clauses. GLBA and the state breach laws impose their own materiality-like triggers. And your board will ask "is this material to us" whether or not the SEC is watching. Pre-decide who makes the call, so the answer at hour three is a determination and not "we weren't sure, so we waited." The people in that determination are not the engineer with the freshest logs — that person supplies facts. The judgment belongs to counsel, finance, the security leader who can translate technical scope into business impact, and someone who owns the customer relationship.

The clock starts when you decide, not when you find out

Once you have determined an incident is material, the SEC's four-day rule gives you four business days to file. The subtlety that trips people is the trigger: the four days run from the materiality determination, not from discovery. Which sets up the dangerous temptation. The risk isn't usually disclosing late — it is never formally determining at all, letting the question drift, and hoping the clock never starts because nobody started it. The rule closes that door on its own terms: the determination has to be made "without unreasonable delay" after discovery. A company that sits on ambiguity to keep the countdown from beginning is running the exact play the rule was written to catch.

So the disclosure committee owns the determination timestamp — the date and time the group concluded "material," recorded, with the basis for the call. That one artifact is what makes the four-day math defensible instead of something reconstructed a year later under subpoena.

And the SEC's is not the only clock, and none of them sync. The banking agencies' interagency rule gives a supervised institution 36 hours to notify its primary federal regulator once an incident rises to a "notification incident." The FTC's amended Safeguards Rule puts a 30-day window on certain events. State breach-notification laws add their own triggers on their own terms. Pre-wire a clock matrix: which obligations apply to us, what event starts each one, and who owns each countdown. The stopwatch that catches you is almost never the one you were watching — it is the fastest one you forgot about. I will not pretend to render which clock legally binds you; that is counsel's call. My narrower point is that you should know which stopwatches exist, and who is watching each, before you are mid-incident trying to read all of them at once.

A ransom is a sanctions decision before it's a recovery decision

If you are being extorted, the instinct at hour three is to treat "do we pay" as a business tradeoff: the cost of the ransom against the cost of the outage. That framing skips the first gate. OFAC's advisory on ransomware payments makes facilitating a payment to a sanctioned person or region a potential sanctions violation — and sanctions liability is strict. Intent is not a defense. Not knowing who was on the other end is not a defense. So before "should we pay" is even a business question, it is a legal one: who is receiving this money, are they or their jurisdiction sanctioned, and can anyone in this company lawfully move it.

Pre-decide the gates. Nobody negotiates or pays without counsel and OFAC screening in the loop. The screening happens before the finance conversation, not after it. And you have pre-chosen whether you notify law enforcement, because OFAC treats prompt reporting and cooperation as a mitigating factor if a payment later proves problematic. None of these are calls to make for the first time while an attacker runs a visible countdown.

The cleanest way to strip a ransom of its leverage is to make encryption a non-event — tested, immutable, isolated backups, so "we will just restore" is a sentence you can actually say. But modern extortion is rarely only encryption. It is stolen data, and no backup un-steals a file. So you pre-wire the payment decision even when your recovery is airtight, because the extortionist's second lever does not care that your restore works. And you pre-assign the authority narrowly: the list of people who can even say yes should be short, and it should not include whoever is under the most operational pressure to make the pain stop.

One voice, drafted before you need it

External communication in a breach fails in one of two ways. Silence that reads as evasion, or a dozen improvised voices that contradict each other by lunch. Both are avoidable with drafts and a matrix written while nothing is on fire.

Pre-write the holding statements for the handful of shapes an incident actually takes — confirmed breach, suspected breach, contained event, third-party incident — so hour-three comms is editing, not composing. You will never predict the specifics. You can pre-decide the tone, the disclosures you will and will not make, and above all the promises you refuse to make under pressure. "No customer data was affected," declared in hour two and walked back in hour twelve, is how credibility dies.

Then the notification matrix: who hears, from whom, in what order. Regulators on their statutory clocks, affected customers, partners with contractual notice rights, employees, and the market — sequenced so that nobody who should hear it from you first learns it from a reporter. The order is a judgment call, and you do not want to be making it while the phone is ringing. One authorized voice speaks externally. Sales does not reassure a nervous customer with a scope claim the incident team has not confirmed. Support does not speculate. In the tactical runbook the comms lead shields the responders; at this altitude the disclosure committee shields the message.

Stand up the committee before the breach

The thread through all four decisions is one body: a standing disclosure committee that owns them in peacetime and convenes them in the incident. Many public companies already have the seed of one — the SOX-era disclosure committee that vets what goes into financial filings. Extending its remit to cyber materiality is a smaller step than building a new body from scratch. If you are private, the same handful of people can hold the same charter without an 8-K anywhere in sight. What matters is that the seats and the decision rights exist before the breach, not that they carry a particular name.

  • Counsel owns the determination and the privilege. Legal runs the materiality call and the clock, and keeps the analysis under privilege so your candid internal debate does not become someone else's exhibit later.
  • Finance owns the quantitative side and the ransom money. The CFO's org sizes the impact and is the right seat to gate any payment, because a ransom is a treasury and sanctions act, not an IT purchase.
  • Security owns the facts and the translation. My job in that room is to turn technical scope into business impact accurately — no minimizing to calm people, no catastrophizing to be safe — so the judgment built on top of me stands on real ground.
  • Comms owns the single voice. One drafter, one approver, one spokesperson, one matrix.
  • A business owner owns the customer view. Someone who can say what a given disclosure does to the relationships that pay the bills, because materiality is qualitative too.
  • A board liaison keeps oversight in the loop. Directors do not run the incident, but they govern the company that had it, and they should learn of a material event from management on a cadence — not from the filing.

The committee's real work happens when nothing is wrong. It writes the charter, pre-assigns those decision rights, drafts the holding statements and the clock matrix, and then it rehearses. Run the disclosure decisions as their own tabletop, separate from the technical one. Hand the group a scenario and make them actually determine materiality, start the right clock, and reach the ransom and comms calls against the artifacts they will really have at hour three — which is to say partial, contradictory, and thin. The gaps you find in that room are free. The ones you find during the real thing are billed at the worst possible rate.

Pre-wire it while it's boring

Name the people who determine materiality before you need them, and make it a decision on the record, not a feeling. Build the clock matrix and know which stopwatch is fastest, because it is rarely the one you were watching. Gate the ransom decision behind counsel and OFAC screening, and keep the authority to say yes off the desk of whoever hurts the most. Draft the holding statements and the notification order now, in a quiet week, so hour three is editing and not inventing.

The question I would put to you is simple: does your company have a body that owns these four decisions, or does it have four executives who will meet for the first time on the worst day? If you have ever run a disclosure tabletop separate from the technical one, I would genuinely like to hear what broke — the gaps in the disclosure layer are the ones I see rehearsed least and improvised most. Tell me where yours were.

Incident ResponseDisclosureGovernanceCrisis Leadership