DFIR Tech Blog – an AI playground

Deutsch English
Foto von Jakub Żerdzicki auf Unsplash.com

The Materiality Sprint: When IR Becomes a Securities Deadline

05.09.2026 sec-disclosurematerialityincident-responseregulatory-reporting

On May 7, 2026, a US pharmaceutical company determined that it had suffered a material cyberattack — data had been exfiltrated, systems encrypted. Three days earlier, on May 4, the intrusion had first been detected. In that narrow window, the company had to do more than respond technically; it had to reach a legally defensible conclusion in parallel: was this incident “material” under SEC disclosure rules? The case illustrates what has been in force for US public companies since late 2023 and has fully arrived in IR practice by 2026: upon determining it had experienced a material cybersecurity attack involving data exfiltration and system encryption, the company promptly activated its incident response protocols, took systems offline globally for containment, and engaged external forensic experts.

The Clock Starts at the Decision, Not the Discovery

The most common misconception is that the four-day clock starts at detection. It doesn’t. Public companies must provide the required disclosure within four business days after determining an incident to be material — the deadline is not four business days after the incident occurred or was discovered, since companies often cannot determine materiality the same day. That sounds like relief, but it’s a trap: the materiality determination itself must happen without unreasonable delay after discovery — companies cannot sit on an incident to avoid starting the clock.

This is exactly where a new IR discipline has to emerge, one most playbooks still lack. The most important operational change is treating materiality assessment as a concurrent process with technical investigation, not a step that happens after the investigation concludes. Playbooks should include an explicit materiality assessment step at the 24-hour mark for any P1 or P2 incident. Teams that improvise this track mid-incident lose time they don’t have.

Who Sits at the Table — and Why It Has to Be Rehearsed

Materiality determination is neither a purely legal nor a purely technical call. Among the essential groups that should establish an organized materiality-determination process are the team under the CISO, CIO, and CTO, the CFO and finance team, and the General Counsel and legal team — the new rule stress-tests how efficiently these three functions communicate and coordinate. In practice, that means: the materiality determination requires input from legal, finance, security, and executive leadership — not a meeting you can schedule without a pre-existing process. If the first time your CISO, general counsel, and CFO are in the same room discussing the incident is after it has already happened, the process is already behind.

Market practice also reveals a notable shift in behavior: voluntary Item 8.01 filings, where materiality has not yet been determined, have significantly outpaced Item 1.05 filings for material incidents, and most incidents initially disclosed under Item 8.01 have not subsequently resulted in an Item 1.05 filing. Conservative materiality analysis has become the norm rather than the exception — a defensible strategy, but one that only works if it’s a deliberate decision, not a default born of indecision.

Three Changes That Belong in the Playbook Now

Teams that don’t adapt their IR playbook for 2026 risk regulatory attention — the SEC has since stood up a dedicated enforcement unit for this space and already levied multiple penalties. Three concrete process changes deserve priority.

First, materiality assessment becomes an explicit playbook phase with a fixed time marker (24–48 hours), not an optional afterthought. Every major incident now requires a materiality assessment track involving legal counsel and the CFO within the first 48 hours, and board escalation paths must be pre-established before an incident occurs.

Second, documentation must be dual-use from the start — serving both the internal investigation and the regulatory filing. Every timeline entry, scope assessment, and impact estimate may later appear in SEC filings.

Third, board and legal communication channels need to be isolated and pre-tested. Incident response communications with the board and legal counsel should use a separate, isolated channel that is established and tested before an incident.

The pharmaceutical case shows these processes can work when they’ve been rehearsed. For everyone else: next quarter’s tabletop exercise shouldn’t just simulate containment and forensics — it should simulate the moment when the CISO, CFO, and general counsel have to negotiate a single adjective together: “material” or not.

← Back to overview