Cyber Resiliency Board Briefing 10: The Disclosure Clock: Why Regulatory Reporting Now Runs Faster Than Your Investigation

Somewhere between the fourth and the seventy-second hour of a serious incident, an organisation is now required to make a formal statement to a regulator that it cannot yet fully support with evidence. The technical team is still establishing what happened. Counsel is still establishing what it means. Operations is still establishing what has stopped. The clock, meanwhile, started the moment somebody became aware — and it does not pause while the facts catch up.

Consider the difference between a roadside statement and an accident report. The statement is given within minutes, by a shaken driver, from partial memory, under obligation. The report is produced months later by investigators with the vehicle, the telemetry and the CCTV. Both are truthful, but they’ll rarely say the same thing. When they diverge, it is the roadside statement that gets read back in court.

Regulatory reporting has become the roadside statement of cyber incidents. Most boards are still resourced and prepared to provide the accident report.

What has changed

The reporting obligations that a large organisation now sits under are no longer a single duty with a single deadline. They are a set of overlapping clocks, each started by a different event and each running to a different regulator.

Under the EU’s Digital Operational Resilience Act, a financial entity must submit an initial notification within four hours of classifying an incident as major, and in any case no later than twenty-four hours after becoming aware of it. An intermediate report follows within seventy-two hours, and a final report within one month of that.

Under NIS2, in-scope entities across a much broader set of sectors owe an early warning within twenty-four hours, a fuller incident notification within seventy-two, and a final report within a month.

Under SEC rules, a US-listed company must file an Item 1.05 Form 8-K within four business days of determining that an incident is material - a clock triggered not by the incident but by a judgement about the incident, which is a meaningfully different thing.

In the United States the federal picture is only half of it. State regulators impose their own clocks, on their own triggers, and they do not wait for a materiality judgement. New York’s Department of Financial Services requires covered entities to notify the Superintendent within seventy-two hours of determining that a cybersecurity event has occurred, whether or not it is material, and where a ransom is paid, within twenty-four hours of the payment, followed within thirty days by a written justification of that decision and the alternatives considered. The NAIC’s Insurance Data Security Model Law, now enacted in twenty-eight states and territories, carries a comparable seventy-two-hour duty to the state insurance commissioner. Beneath both sit fifty state breach notification statutes and the District of Columbia’s, each with its own definition of personal information and its own deadline. The practical consequence for a US-regulated group is that an incident can become reportable in Albany before the board has finished deciding whether it is material enough to report in Washington. And the ransom decision itself, which boards tend to treat as the most closely held judgement they will ever make, becomes a disclosable event on a one-day clock.

The UK’s Cyber Security and Resilience Bill, which completed its House of Lords second reading in July and enters committee stage this month, brings the same two-stage structure to operators of essential services, managed service providers and, for the first time, data centre operators. Twenty-four hours for a light-touch initial notification, seventy-two for the full report, with penalties reaching £17 million or four per cent of global turnover.

A multinational of any complexity will be inside several of these at once, for the same incident, with different definitions of what triggers them.

The governance problem arises because three timelines that once moved broadly in step have now diverged.

The forensic clock is set by evidence. Establishing the initial access vector, dwell time, lateral movement and data exfiltration in a mature environment takes days at best and frequently weeks. This clock has, if anything, slowed because environments are larger, attackers are better at living off the land, and AI-enabled attacks can leave considerably more forensic debris behind. Agentic models can pursue multiple attack paths in parallel, abandoning unsuccessful approaches and rapidly trying alternatives. Investigators may therefore have to distinguish the attack path that ultimately succeeded from numerous failed reconnaissance, exploitation and lateral-movement attempts, making an already complex environment even “dirtier” from a forensic perspective.

The operational clock is set by the business. It is the one the board feels most immediately, because it is measured in unshipped orders, unpaid staff and unanswered customers. It has its own logic and its own priorities, and it competes directly for the same handful of people the forensic clock depends on.

The regulatory clock is set by statute and runs from awareness. It has accelerated sharply over the past three years and shows no sign of slowing.

For most of the last decade, these could be managed sequentially: investigate, understand, then disclose. The regulatory clock now finishes first. Organisations are required to make binding public and supervisory statements at precisely the point in an incident when they know the least, and to do so in a form that will later be compared against what the forensics eventually establish.

Where organisations get caught

Four failure modes recur, and none of them are technical.

Nobody owns the trigger. The obligation begins on “awareness” or on “classification as major”, which sounds administrative until you ask who, at 03:00 on a Sunday, has the authority to declare an incident major. In practice, the decision drifts: the analyst waits for the manager, the manager waits for the CISO, the CISO waits for enough facts to feel comfortable. Then four hours of a twenty-four-hour window have disappeared into deference. The obligation to classify quickly is a delegation-of-authority question, and it belongs in the board’s decision-rights framework rather than in a runbook.

Materiality is treated as a legal afterthought rather than a rehearsed judgement. The variance in practice here is remarkable. One advisory review of two years of SEC filings found determination times ranging from a single day at UnitedHealth and two days at Halliburton to eighty-four calendar days at AT&T. That spread does not reflect differences in the incidents so much as differences in whether the organisation had decided, in advance, how it would make that call and who would make it.

The first statement is drafted by whoever is free. Under pressure, initial notifications get written by the person with capacity rather than the person with authority, and language enters the record that the organisation will spend the following year defending. The initial notification is a governance artefact with a long tail, and it deserves pre-agreed structure, pre-approved language and a named approver.

Disclosure competes with recovery for the same scarce people. Briefing 9 made the case that recovery capacity is bounded by people rather than technology. Regulatory reporting is a direct claim on that same bounded resource. The incident commander who is drafting the regulator submission is not directing the recovery. Unless reporting is separately staffed and separately rehearsed, every hour spent satisfying the clock is an hour taken out of restoring the business.

What readiness actually looks like

Readiness is often seen as unglamorous and mostly pre-work.

It means a written classification standard that lets a duty crisis manager decide, without escalation, whether an incident is major and the delegated authority to act on that decision at three in the morning. It means a single reporting matrix that maps every regime the organisation falls under, its trigger event, its clock and its recipient, so that nobody discovers a Nordic subsidiary’s obligation on day two. It means pre-drafted notification templates for each regime, reviewed by counsel in peacetime, with the factual gaps clearly marked as gaps rather than filled with optimism.

It also means a named disclosure lead who is not the incident commander, with their own small team, so that the two clocks are worked in parallel rather than in competition. Rehearse the reporting decision in exercises and drills, with the same time pressure and the same partial information the real thing will offer, rather than exercising only the technical recovery and assuming the paperwork will follow.

Most organisations that exercise cyber incidents exercise the parts they enjoy, repeatedly. The four-hour classification call, made on ambiguous evidence by someone who will be asked to justify it later, is not one of those parts. It is the one most worth practising.

Questions for the board

  • Who in this organisation has the standing authority to classify an incident as major at three in the morning, and have they ever done it in an exercise?

  • Can we produce, today, a single matrix of every reporting obligation we are subject to, with its trigger, its deadline and its recipient?

  • How long did our last exercise take to reach a materiality determination, and would that have met a four-business-day filing window?

  • Who drafts and who approves the first regulatory notification, and are they different people from those directing the recovery?

  • What is our process for correcting an initial notification that later proves wrong, and have we ever tested it?

  • How would we handle an incident originating at a managed service provider, where our clock starts on their disclosure to us?

The bottom line

Cyber resilience is usually framed as the ability to keep operating and to restore what has been broken. The disclosure clock adds a second obligation that runs concurrently and is judged separately: the ability to describe accurately, under statutory time pressure, an event you do not yet fully understand.

Organisations that survive a serious incident with their standing intact will be those that treated their first regulatory statement as a rehearsed capability rather than a document produced in the small hours by exhausted people. The regulators have set the pace. The board’s job is to make sure the organisation can keep it without taking those hours out of the recovery.

Next
Next

Guest on Security Insights talking Physical & Cybersecurity Convergence