The Materiality Call Nobody Has Made Yet
Key Intel / TL;DR
  • The disclosure clock does not start at detection or containment. It starts when somebody determines the incident is material.
  • That determination is a judgment call most organizations have never defined, staffed, or rehearsed.
  • Deciding late looks like delay in hindsight, and deciding early commits you to a public statement built on incomplete facts.
  • Write the criteria, name who decides, and put the reasoning in a contemporaneous memo, because the memo is what gets examined.
  • Run the determination as its own tabletop, separate from the technical exercise, with the people who would actually be in the room.

Somewhere in your incident response plan there is a section about notification. It lists regulators, it lists timelines, and it almost certainly contains a sentence about disclosing material incidents within four business days. Somebody wrote that sentence because it is accurate.

Now ask the harder questions underneath it. Who, by name, decides that an incident is material, what do they need to see before they can, and what is the threshold they are measuring against?

In most organizations I have looked at, the honest answer is that nobody has decided, and the plan is quietly assuming the answer will be obvious when the time comes.

The Clock Does Not Start Where People Think

The thing that trips organizations up is that the four days do not run from detection. They do not run from containment either. They run from the determination of materiality, which means the clock is controlled by a judgment your own people make rather than by an event the attacker caused.

That sounds like it gives you room, and it does the opposite. A determination you make on day nine looks, from the outside and in hindsight, exactly like a determination you should have made on day two and delayed. The reasonableness of the timing is assessed by people reading a timeline after the fact, and the only thing standing between you and their inference is a contemporaneous record of what you knew and when.

So the real exposure sits in the interval before those four days begin, where nobody is formally on a clock and every hour is being graded retroactively by somebody reading a timeline.

Why the Decision Is Genuinely Hard

I want to be fair about this, because the obvious response is that companies should simply disclose promptly and stop overthinking it. That response underestimates two things, and the first is what the word actually means.

Materiality is a question about whether a reasonable investor would consider the information important, which is a different thing entirely from a severity rating and which has almost nothing to do with how bad the incident feels to the people working it. A ransomware event that takes out a business unit for a week may be immaterial to a company of a certain size. An unauthorized access to a small amount of the right data may be highly material. Your CISO’s instinct about severity and your general counsel’s read on materiality will diverge, and both of them will be reasoning correctly inside their own frame.

Then there is the timing problem. Early in an incident you have partial facts, and the facts frequently get worse. Disclosing on day three commits you to a public characterization you may have to correct on day ten, and a correction is its own event. Waiting for certainty means waiting past the point where the timing looks defensible. There is no option that removes the risk, which is precisely why it needs a decision procedure rather than a judgment in the moment.

And the people who have to make the call are, at that moment, the same people managing the incident. The general counsel is on three calls, the CISO is trying to establish scope, and the chief executive is being asked by the board what happened. Asking that group to also perform a careful securities analysis, for the first time, at that hour, is asking for the wrong answer.

We wrote recently about who actually carries the exposure when a security leader signs off on a risk decision, and the materiality call is the sharpest version of that question. Somebody’s name goes on it.

What to Decide Before You Need It

None of this requires a large project. It requires a few decisions made calmly, in a quarter when nothing is on fire.

Write down what would make an incident material here

Not a definition copied from a filing. Specific criteria for your business, with numbers where numbers apply.

Revenue at risk over a stated threshold, duration of disruption to a named critical process, categories of data whose exposure would matter regardless of volume, customer counts, contractual commitments you would breach, and whether a particular system going down stops you invoicing.

The list will be imperfect and arguing about it in advance is the entire value. The people who would be in the room discover, in a low-stakes conversation, that they disagree about something fundamental. Better then than at 2 AM.

Name the decider and the room

One person makes the determination, and a defined small group advises. In most organizations that is the general counsel deciding with the chief executive, the CISO, and the chief financial officer in the room. Whoever it is, write the names and the deputies, because the incident that forces this will happen while somebody is on a plane.

Give that group a standing meeting cadence during an incident. Not a meeting when somebody thinks it is time, a meeting on a schedule, so the question gets revisited as facts change and each revisit is recorded.

Write the memo as you go

The contemporaneous record is the single most valuable artifact in this entire process, and it is the one nobody produces because everybody is busy. It also takes about ten minutes per sitting.

Each time the group meets, somebody writes down what was known at that point, what was still unknown, what the group concluded about materiality, and why. Three paragraphs. If the conclusion is not yet material, the memo says what would change that.

This memo is what demonstrates, later, that the determination was made carefully instead of delayed conveniently. Our guidance on documenting a deferred patch so it reads as a decision makes the same argument at a smaller scale, and the principle is identical. An undocumented judgment and an avoided judgment look the same from outside.

Rehearse the determination separately from the technical response

Most tabletop exercises are technical. The scenario runs, the team contains it, everybody agrees it went well, and the materiality question either never arises or gets waved through in a sentence.

Run a separate exercise where containment is assumed and the only question on the table is whether this is material and when you would say so. Use a genuinely ambiguous scenario instead of an obvious one, since the obvious cases were never the problem. Put the actual decision-makers in the room and let them work through it with incomplete facts, because the skill you are building is reaching a defensible answer without certainty.

What the Board Needs to Know Now

The conversation worth having at the next board meeting is short, and it runs to about four sentences rather than a presentation. Directors do not need the incident response plan, they need to know that this particular decision has an owner.

Tell them the clock is controlled by a determination the company makes, not by the attack. Tell them who makes it and who is in the room. Tell them criteria exist and that the board has seen them. And tell them that the record of the decision is being kept in real time, because that record is what protects the people making the call, the directors, and the company in roughly that order.

Directors are increasingly asked whether they exercised oversight, and what a board’s fiduciary duty looks like under current enforcement turns on whether the question was ever put to them. A board that has reviewed the materiality criteria has an answer. A board that has never seen them is relying on the executives to have thought of it.

The incident will not wait for the decision to get easier, and the four days are the part everybody plans for because it is the part with a number attached.

Jeff Welch is CEO of Grab The Axe.

Distribute Intel
Jeff Welch
Chief Executive Officer
Jeff Welch
Architect of the 'Cognitive Firewall.'

A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.

View Author Page →