US public companies must disclose material cybersecurity incidents within four business days of determining that an incident is material. Insider incidents qualify. Boards are expected to oversee the risk, and the determination is an accountable judgement rather than a formality.
This desk reads a great many filings made under this rule, and the tension in them is consistent.
Materiality Precedes Understanding
Four business days from a materiality determination is a workable window for drafting. It is not a workable window for knowing what happened.
At the point a company concludes an incident is probably material, a typical investigation has established that unauthorised access occurred and roughly where. It has usually not established what was taken, over what period, or how many people are affected — the Conduent file in 26-0731 took fifteen months to settle its count.
Which Is Why Filings Read The Way They Do
The resulting language — "unauthorised access to certain systems", "the investigation is ongoing", "no material impact on operations to date" — is frequently criticised as evasive. Some of it is. Much of it is an accurate description of what is known on day four.
The genuine problem is that the determination itself can be deferred. The clock starts on a judgement the company makes, and a company that has not yet determined materiality has not yet started the four days.
What We Do With These Filings
We treat a filing as evidence of what the company was prepared to state on a date, not as a description of the incident. We record the date, the language, and later revisions — because the drift between an initial filing and a final count is frequently the most informative thing in a file.
This is a standards file. Compiled from published regulatory analysis, listed below. It is not legal advice and we are not characterising any specific company’s compliance. Corrections: corrections@forensicpost.com.