Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Writing

Pre-Wire Breach Disclosure Before the Breach

Materiality, the SEC's four-day clock, the OFAC ransom gate: decisions to pre-wire with a standing disclosure committee, not improvise at hour three.

By Michael YorkJune 7, 2026 9 min read 1,919 words All postsTable of contents

By hour three of a real breach, the tactical response is usually the calm part of the building. The incident commander is named. The evidence is preserved. The status cadence runs on the hour and the engineers have room to work. The room that is not calm is the one next door, where four executives are discovering, in real time on the worst day of the quarter, that nobody ever decided who gets to answer four questions. Is this material? When does the clock start? Can we pay? What do we say, to whom, and in what order?

Those four are not security questions. They are executive judgment calls with legal, financial, and reputational weight, and they are almost always improvised, because the people who own them have never been in the same room before the room was on fire. The tactical runbook of roles, evidence, and comms cadence is a comparatively solved problem, and plenty of teams rehearse it. The disclosure decisions sitting on top of it are the ones I still watch companies invent at hour three. Hour three is exactly the wrong time to invent them.

Materiality, the disclosure clock, the ransom question, and the external message are decisions to pre-wire in peacetime, with a standing body that owns them. I run security, not the legal function. I am the person who ends up in that room, not the one who signs the filing, so read this as how a security leader lays the track before the train, not as counsel. The shape is what matters, and the shape is knowable in advance.

Materiality is a determination, not a discovery

The SEC's cyber-disclosure rule (opens in new tab) turns on a single word. Item 1.05 of Form 8-K requires a public company to disclose a "material" cybersecurity incident, and material does not mean "data left the building." It is the old reasonable-investor standard applied to a cyber event: would this information matter to a reasonable investor's decisions. The SEC deliberately declined to draw a bright quantitative line, so the test runs both ways at once, quantitative on dollars, records, and downtime, and qualitative on the nature of what was taken, the regulatory exposure, and the damage to trust.

The trap is treating materiality as a fact you will eventually find in the logs. Nobody stumbles onto "material" while reading a packet capture. It is determined: a judgment made by named people against a standard, on the record, with a timestamp.

If you are a private company, Item 1.05 does not bind you and you will never file an 8-K. You do not escape the concept. Your regulated customers ask the same question inside their vendor-incident clauses. GLBA (opens in new tab) and the state breach laws impose their own materiality-like triggers. And your board will ask "is this material to us" whether or not the SEC is watching. So pre-decide who makes the call, and the answer at hour three is a determination rather than "we weren't sure, so we waited." The engineer with the freshest logs supplies facts. The judgment belongs to counsel, finance, the security leader who can translate technical scope into business impact, and someone who owns the customer relationship.

The four-day clock starts at the determination

Once you have determined an incident is material, the SEC's rule gives you four business days to file. The subtlety that trips people is the trigger: the four days run from the materiality determination, not from discovery. Which sets up the dangerous temptation. The risk is rarely disclosing late. It is never formally determining at all, letting the question drift, and hoping the clock never starts because nobody started it. The rule closes that door on its own terms. The determination has to be made "without unreasonable delay" after discovery, so a company that sits on ambiguity to keep the countdown from beginning is running the exact play the rule was written to catch.

So the disclosure committee owns the determination timestamp: the date and time the group concluded "material," recorded, with the basis for the call. That one artifact is what makes the four-day math defensible instead of something reconstructed a year later under subpoena.

The SEC's is not the only clock, and none of them sync. The banking agencies' interagency rule gives a supervised institution 36 hours to notify its primary federal regulator once an incident rises to a "notification incident." The FTC's amended Safeguards Rule (opens in new tab) puts a 30-day window on certain events. State breach-notification laws add their own triggers on their own terms. Pre-wire a clock matrix: which obligations apply to us, what event starts each one, who owns each countdown. The stopwatch that catches you is almost never the one you were watching. It is the fastest one you forgot about. Which clock legally binds you is counsel's call, not mine. My narrower point is that you should know which stopwatches exist, and who is watching each, before you are mid-incident trying to read all of them at once.

A ransom is a sanctions decision before it's a recovery decision

If you are being extorted, the instinct at hour three is to treat "do we pay" as a business tradeoff: the cost of the ransom against the cost of the outage. That framing skips the first gate. OFAC's advisory on ransomware payments makes facilitating a payment to a sanctioned person or region a potential sanctions violation, and sanctions liability is strict. Intent is not a defense. Not knowing who was on the other end is not a defense. Before "should we pay" is even a business question, it is a legal one: who is receiving this money, are they or their jurisdiction sanctioned, and can anyone in this company lawfully move it.

Pre-decide the gates. Nobody negotiates or pays without counsel and OFAC screening in the loop, and the screening happens before the finance conversation rather than after it. Pre-choose whether you notify law enforcement, because OFAC treats prompt reporting and cooperation as a mitigating factor if a payment later proves problematic. None of these are calls to make for the first time while an attacker runs a visible countdown.

The cleanest way to take a ransom apart is to make encryption a non-event. Tested, immutable, isolated backups turn "we will just restore" into a sentence you can actually say. But modern extortion is rarely only encryption. It is stolen data, and no backup un-steals a file. So pre-wire the payment decision even when your recovery is airtight, because the extortionist's second lever does not care that your restore works. And assign the authority narrowly. The list of people who can even say yes should be short, and it should not include whoever is under the most operational pressure to make the pain stop.

One voice, drafted before you need it

External communication in a breach fails in one of two ways: silence that reads as evasion, or a dozen improvised voices that contradict each other by lunch. Both are avoidable with drafts and a matrix written while nothing is on fire.

Pre-write the holding statements for the handful of shapes an incident actually takes, confirmed breach, suspected breach, contained event, third-party incident, and hour-three comms becomes editing instead of composing. You will never predict the specifics. You can pre-decide the tone, the disclosures you will and will not make, and above all the promises you refuse to make under pressure. "No customer data was affected," declared in hour two and walked back in hour twelve, is how credibility dies.

Then the notification matrix: who hears, from whom, in what order. Regulators on their statutory clocks, affected customers, partners with contractual notice rights, employees, and the market — sequenced so that nobody who should hear it from you first learns it from a reporter. The order is a judgment call, and you do not want to be making it while the phone is ringing. One authorized voice speaks externally. Sales does not reassure a nervous customer with a scope claim the incident team has not confirmed. Support does not speculate. In the tactical runbook the comms lead shields the responders; at this altitude the disclosure committee shields the message.

Stand up the committee before the breach

The thread through all four decisions is one body: a standing disclosure committee that owns them in peacetime and convenes them in the incident. Many public companies already have the seed of one — the SOX-era disclosure committee that vets what goes into financial filings — and extending its remit to cyber materiality is a smaller step than building a new body from scratch. If you are private, the same handful of people can hold the same charter without an 8-K anywhere in sight. What matters is that the seats and the decision rights exist before the breach, not that they carry a particular name.

  • Counsel owns the determination and the privilege. Legal runs the materiality call and the clock, and keeps the analysis under privilege so your candid internal debate does not become someone else's exhibit later.
  • Finance owns the quantitative side and the ransom money. The CFO's org sizes the impact and is the right seat to gate any payment, because a ransom is a treasury and sanctions act rather than an IT purchase.
  • Security owns the facts and the translation. My job in that room is to turn technical scope into business impact accurately — no minimizing to calm people, no catastrophizing to be safe — so the judgment built on top of me stands on real ground.
  • Comms owns the single voice. One drafter, one approver, one spokesperson, one matrix.
  • A business owner owns the customer view. Someone who can say what a given disclosure does to the relationships that pay the bills, because materiality is qualitative too.
  • A board liaison keeps oversight in the loop. Directors do not run the incident, but they govern the company that had it, and they should learn of a material event from management on a cadence, not from the filing.

The committee's real work happens when nothing is wrong. It writes the charter, pre-assigns those decision rights, drafts the holding statements and the clock matrix, and then it rehearses. Run the disclosure decisions as their own tabletop, separate from the technical one. Hand the group a scenario and make them actually determine materiality, start the right clock, and reach the ransom and comms calls against the artifacts they will really have at hour three — partial, contradictory, and thin. The gaps you find in that room are free. The ones you find during the real thing are billed at the worst possible rate.

Pre-wire it while it's boring

Name the people who determine materiality before you need them, and make it a decision on the record rather than a feeling. Build the clock matrix and know which stopwatch is fastest, because it is rarely the one you were watching. Gate the ransom decision behind counsel and OFAC screening, and keep the authority to say yes off the desk of whoever hurts the most. Draft the holding statements and the notification order now, in a quiet week, so hour three is editing and not inventing.

Either your company has a body that owns these four decisions, or it has four executives who will meet for the first time on the worst day. If you have ever run a disclosure tabletop separate from the technical one, tell me what broke. The disclosure layer is the one I see rehearsed least and improvised most.

Incident ResponseDisclosureGovernanceCrisis Leadership