A cybersecurity incident does not care where your data lives.
It does not care that the affected application is vendor-managed. It does not care that the logs are in a SaaS console your team cannot access. It does not care that the data-flow diagram is maintained by procurement, that customer-impact details live with a managed service provider, or that the outage timeline depends on a third-party support ticket.
But your materiality decision may care very much.
Public companies must disclose material cybersecurity incidents on Form 8-K within four business days after determining that the incident is material. The SEC’s rule also requires disclosure of the material aspects of the incident’s nature, scope, timing, and impact or reasonably likely impact, and the materiality determination must be made without unreasonable delay after discovery.
That creates a practical problem many organizations have not fully internalized:
The disclosure clock may be yours, but the evidence may belong to someone else.
That is not just a legal nuance.
It is an operational design problem.
It is a governance problem.


