The 2026 InfoSec Playbook · Daniel Ramos

#Chapter 15 — Communications, Legal and Regulatory Notification

Who says what, to whom, on which clock — and the legal machinery that decides whether your incident becomes a footnote or an exhibit.

Who needs this: General Counsel, CISO, Communications Lead, Privacy Officer, DPO, Incident Commander, CFO, board | Read time: 35 min | Maps to: CSF 2.0 GOVERN (GV.OC, GV.RR), RESPOND (RS.CO, RS.MA), RECOVER (RC.CO) | CIS v8.1 Control 17 | ISO/IEC 27001:2022 A.5.5, A.5.24, A.5.28, A.5.29, A.6.6

Welcome to the chapter your general counsel will read twice, cyber-friends. Read it with them.

Here is the shape of the problem. Almost every notification obligation in this chapter runs from a subjective state — "becomes aware," "reasonably believes," "determines," "discovers" — not from the moment the attacker got in and not from the moment your EDR lit up. GDPR runs 72 hours from awareness. The SEC's four business days run from a materiality determination you make. NYDFS runs 72 hours from determining an incident occurred. CIRCIA, when it exists, will run 72 hours from reasonable belief. Those states arise on different days, sometimes a week apart, and the only evidence of when each one arose is a contemporaneous log written by a tired person at 3am. Regulators reconstruct your clock from that log. So does plaintiffs' counsel.

The second shape of the problem is that these clocks are not queued politely. A ransomware attack on an EU bank that exfiltrates customer data and ends in a payment can simultaneously trigger DORA at four hours, NIS2 at twenty-four, the CRA at twenty-four if a product is involved, GDPR at seventy-two, NYDFS at seventy-two plus twenty-four more for the payment, an SEC 8-K, a dozen US state attorneys general, and an Australian filing if you have operations there. There is no queue. They all run at once, from slightly different starting guns, to different recipients, in different languages, with different content requirements. The EU's own Digital Omnibus proposal for a single reporting entry point exists precisely because this is unmanageable — and that proposal is not law (Bird & Bird). Plan for duplication.

The third shape of the problem is the one nobody puts in the plan: the deadlines you actually miss are usually contractual, not statutory. A business associate agreement that compresses HIPAA's sixty days to seven. A customer MSA demanding notice in twenty-four hours. A cyber insurance policy that says "as soon as practicable" and means it. Those clocks belong in the same matrix as the statutes, because the statutes are the ones you have rehearsed.

Everything here is written against what is in force on 5 September 2026. Several items are genuinely in flux, and I have said so rather than picking a comfortable answer. Appendix C holds the at-a-glance matrix for the war room wall; this chapter holds the reasoning, the sequencing and the templates. Re-verify quarterly, and re-verify before you rely on any single line of it.


#Internal communications: who leads, who supports, who authorises

Comms during an incident fails in exactly two ways. Either nobody is saying anything and the vacuum fills with rumour, or five people are saying five things and one of them is speculating about cause in a channel that will later be produced in discovery. The fix for both is the same: one voice, one cadence, one named owner, and an authority table that existed before the incident. The role names below are Chapter 13's six command roles plus one addition this chapter defines — the Notification Owner. Use these and no parallel set.

FunctionRoleWhat they ownWhat they may not do
LeadCommunications LeadAll message drafting, the cadence, the stakeholder map, the Q&A document, the single external voiceApprove external release; determine materiality; characterize cause
Authorize (external)Executive SponsorSign-off on any statement leaving the organization, on notification spend, on public disclosureOverrule a determination that notification is legally owed
Authorize (legal content)Legal LiaisonWording review of every regulator filing and customer notice; privilege posture; law enforcement interfaceDraft technical fact statements without Operations Lead verification
Own the clocksNotification OwnerThe deadline register, the four timestamps, filing and proof of filingDetermine breach status alone; act as Incident Commander
Supply factsOperations LeadThe verified factual basis — what is observed versus assessedSpeak externally; estimate record counts before verification
RecordScribeContemporaneous timeline to the minute, decisions and rationale, UTCEditorialize; summarize away uncertainty

The Notification Owner is a distinct person from the Incident Commander, and that is not organizational tidiness. The IC is running containment against an adversary still in the estate; the clocks do not pause for that, and asking one person to do both means one of them gets done badly. In a small organization these can be two people who also do four other things — but they are two people, and they are named in the plan.

#The executive briefing cadence

Set the cadence at declaration and publish it. The single largest drain on an incident team is executives asking for status individually; a published cadence converts eleven interruptions into one meeting.

AudienceFirst briefingThenFormat
Executive SponsorT+1hEvery 2h for SEV-1, every 4h for SEV-2, until stableVerbal on the bridge, written summary after
Full executive teamT+4hTwice daily at fixed timesWritten; same document every time
Board / audit committeeOn SEV-1 declaration, or on the first credible indication of materialityDaily while the materiality question is openWritten, through counsel, with the Legal Liaison present
All staffT+4h, or immediately if staff are being asked to change behaviorDaily at a fixed time, even when there is no newsWritten, sent on the out-of-band channel if primary mail is affected

Two rules make the cadence survive contact. Ship the update even when there is nothing new — "no change since 08:00, next update 14:00" is a complete update, and silence is the thing that generates the rumours you will spend a day correcting. And staff see external statements before the public does. The British Library's review documents exactly this discipline: staff always saw updated external communications first, so they could digest developments before fielding user questions (British Library). Your employees will be asked by customers, journalists and their own families. Sending them to the press release at the same time as the press is how you get eleven unofficial spokespeople.

Actionable takeaway: Write the authority table and the cadence into the plan today, with named deputies and out-of-hours numbers, and print it. Both fit on one page. Neither can be invented at 03:00.


#Out-of-band communications: stand it up before you need it

The scenario is not exotic. Your identity provider is compromised, or your file servers are encrypted, or you are about to isolate the segment your ticketing system lives in — and the tool you were going to coordinate the response with authenticates against the thing you just declared untrustworthy. Worse, the adversary may be reading it. CISA's ransomware guidance is direct: use out-of-band methods such as phone calls, because failing to do so "could cause actors to move laterally to preserve their access or deploy ransomware widely prior to networks being taken offline," and attackers "may monitor your organization's activity or communications to understand if their actions have been detected" (CISA — I've Been Hit By Ransomware).

Mid-incident is the wrong time to discover that account creation requires an email to a domain you have just taken offline. Build it in peacetime.

#ActionWhoDone whenEvidence to capture
1Select a messaging platform that does not authenticate against the production identity provider and is not federated to it. Personal-device install, separate credential.CISOPlatform selected and documented in the planWritten statement of the authentication dependency, signed off
2Provision a conference bridge with a static dial-in number and static PIN that does not require a portal login or a calendar invite to joinIT OperationsNumber and PIN issued and tested from an external lineTest call log
3Create the responder roster on the platform, including deputies, Legal Liaison, Executive Sponsor, external counsel, forensics retainer, insurer's after-hours line and PR firmCommunications LeadAll roles joined and have posted onceMembership export, dated
4Print the contact list — names, roles, mobile numbers, bridge number, bridge PIN, insurer policy number and notification line, counsel after-hours numberNotification OwnerEvery named responder holds a physical copy at home and at workSigned distribution list
5Stand up an alternate email path on a separate domain and separate tenant from production, for regulator and customer correspondenceIT OperationsTest message sent and received from an external addressMessage headers proving path independence
6Pre-stage a static status page on infrastructure with no dependency on your production DNS, hosting or CDN accountCommunications LeadPage resolves and is editable from a personal deviceURL, edit-path documentation
7Segment SOC and IR tooling — SIEM, case management, credential vault, backup catalog — so they are managed separately from enterprise ITCISODocumented and validatedArchitecture diagram, access-path review
8Join the channel and dial the bridge from a personal device, cold, with no laptop, at least every six monthsIncident CommanderAll named responders have completed within the periodAttendance record with date

Step 8 is the one that gets skipped and the one that matters. A channel nobody has ever joined is not a channel; it is a license. The British Library, with website and intranet down, fell back to social media and email and WhatsApp cascades — which worked, because people already had each other's numbers (British Library).

Three cautions belong in the plan, not a footnote. Out-of-band does not mean unrecorded — you still owe regulators a contemporaneous record, and NCSC is explicit that decision-making should be recorded offline or on systems unaffected by the incident (NCSC); assign the Scribe to the out-of-band channel. The same discoverability rules follow you there — moving to a phone bridge does not create privilege and does not delete an obligation to preserve. And the cheap version works: a group chat on a consumer messaging app, a dial-in bridge, and a printed card in everyone's wallet costs approximately nothing and beats an unbuilt enterprise solution every time.

Actionable takeaway: Print the contact card this week. Dial the bridge from your own phone before you leave the office. If you cannot join in ninety seconds with no laptop, it does not exist.


#What not to write in Slack or email during an incident

Every message in your incident channel is potentially discoverable, and internal messages are increasingly the primary evidence rather than the corroborating detail. In the SEC's action against SolarWinds and its CISO, the complaint leaned on internal presentations, emails and instant messages — including a description of the product as "riddled" with vulnerabilities, a 2018 internal presentation stating the remote-access setup was "not very secure" and that an attacker "can basically do whatever without us detecting it until it's too late," and internal statements that the "current state of security leaves us in a very vulnerable state for our critical assets" (SEC press release 2023-227). None of those messages were written to be read by a regulator. All of them were.

State the rule aloud whenever the bridge opens: facts and timestamps in the incident channel; opinions, blame, speculation and legal characterizations nowhere. Then make it concrete, because "be careful what you write" is advice nobody can follow at 3am. Give people the sentence patterns.

Do not writeWrite insteadWhy
"This is definitely APT29.""TTPs observed are consistent with publicly reported activity; attribution not assessed."Attribution is a conclusion you cannot yet support and may have to retract publicly
"Looks like ~2 million customer records gone.""Result set not yet enumerated. Upper bound of the entitlement set is 2,000,000; confirmed acquisition count is 0 pending log review."An unverified count becomes the number in the headline and in the complaint
"We should have patched this in March.""The affected host was running version X. Patch availability and deployment history to be established in the post-incident review."A self-assessment of negligence, written before the facts, by someone unqualified to make it
"Legal says we probably have to notify, so we're exposed."Nothing in this channel. Raise it with the Legal Liaison on the counsel-directed channel.Characterizing legal exposure in a general channel is the single fastest way to lose the benefit of the conversation
"Nothing sensitive was touched.""No evidence of access to <system> as of <timestamp>, based on <log source> with <retention window>."NCSC's rule: avoid saying anything you may have to retract. "No known impact" ages badly (NCSC)
"Contained.""Containment actions X, Y, Z applied at <time>. Monitoring continues; scope not closed.""Contained" is a word regulators and plaintiffs will hold you to

Two habits carry most of the weight. Label every statement observed or assessed — observed means it is in a log you can produce; assessed means it is a judgement. And never state a number without its basis and its confidence. A record count with a source and a stated upper bound is a professional statement. The same number bare is a liability.

Actionable takeaway: Put the six sentence patterns above on a card, pin the observed/assessed rule and the line this channel is a business record to the top of the incident channel, and read both aloud every time the bridge opens. Then stand up the informal channel alongside it, and place legal hold at declaration. The rule people can follow at 3am is the one they have already heard a hundred times.


#Attorney-client privilege and running IR under counsel

The theory is straightforward: outside counsel directs the investigation so the forensic work product is prepared in anticipation of litigation and for the purpose of legal advice, and is therefore protected. The practice is that courts have repeatedly declined to protect it. If your plan assumes otherwise, fix the plan. Three decisions define the landscape:

(Davis Wright Tremaine)

The pattern is not subtle. Privilege over a forensic report is a position you build, with facts, from day one. It is not a label you apply afterwards by copying a lawyer on the email.

The practitioner consensus on how to build it (Morrison Foerster, Six Considerations to Preserve Privilege):

  1. Outside counsel retains the forensics firm, under a separate engagement agreement for each incident, scoped explicitly to legal advice or anticipated litigation. Instructing an existing vendor under an existing MSA to "report to counsel" is not sufficient and has failed in litigation.
  2. Be deliberate about report contents. Reports focused primarily on business or technical matters lack protection. Do not reuse the investigative report for business purposes. If you need a remediation roadmap — and you do — commission it as a genuinely distinct piece of work, not a summary derived from the protected one, or you risk waiver by derivation.
  3. Watch agency disclosure. Sharing privileged material with a federal agency can trigger broad waiver under FRE 502. Use a confidentiality agreement, or seek a Rule 502(d) order. A report created primarily for regulatory compliance is not privileged; you need a genuine dual purpose, and "genuine" is a finding of fact.
  4. Account for jurisdictions that do not extend privilege to in-house counsel — Austria, the Czech Republic, France, Italy, Luxembourg and Sweden among them. Structure so that outside counsel communicates with internal staff about the breach.
  5. Structure on day one. Retroactive structuring is what the three cases above were about.
  6. Discipline the team's writing, per the previous section.

Now the honest part. Privilege protects the legal advice and sometimes the analysis. It does not protect facts. It does not stop a regulator asking what happened, and it does not excuse a notification. It does not protect a report that reads like an IT assessment. And it does not create a safe space to write things you would not otherwise write — the SolarWinds messages were not improved by lawyers being on the distribution list.

Actionable takeaway: Decide the privilege posture now, in writing, with outside counsel: who retains forensics, under what engagement, which channel carries legal-strategy discussion, and who may invoke it. Put the retainer template and counsel's after-hours number on the printed contact card. Structuring on day one is free. Structuring on day thirty is not available.


#The notification decision tree: the first 24 hours

This is a fact-establishment sequence, because you cannot know which clocks are running until you know a short, specific list of facts — and the art is establishing them in the right order. Two governing rules first.

Run these branches in parallel, not in sequence. The tightest clocks here are twelve and twenty-four hours. A serial process — investigate, then classify, then decide, then draft — fails by construction. Assign the branches to different people at T+0.

File incomplete rather than late. GDPR, NIS2, DORA, the CRA and the AI Act all expressly contemplate phased or incomplete initial reports. A twenty-four-hour early warning saying "we are investigating, cause not yet established, cross-border impact possible" is compliant. Silence is not. And under GDPR a late notification must carry the reasons for the delay — a mandatory element of the filing, not an excuse offered afterwards (Art. 33 GDPR).

#T+0 — Three things that happen before analysis

  1. Start the written timeline. To the minute, in UTC. When detected, by whom, what was known at each point, and — separately flagged — the moment each legal state arose. This log is the evidence of your clock.
  2. Preserve. Legal hold on channels and mailboxes. Export logs approaching retention expiry first. Do not reimage before imaging. If you handle CUI, DFARS 252.204-7012 requires ninety-day media preservation; PCI forensic-investigator and law-enforcement holds follow their own rules.
  3. Engage counsel before the first substantive written assessment, so the privilege structure exists before there is anything to protect. Appoint the Notification Owner, distinct from the IC.

#T+0 to T+2h — Establish the six facts

Ask all six. They are independent — an incident can be positive on all six at once, and each has its own clock, recipient and content requirement.

#Fact to establishHow you establish itWhat it turns on
1Was personal data involved?Data map plus the systems in the intrusion scope; if unknown, assume yes pending evidenceGDPR / UK GDPR 72h; US state laws; HIPAA if PHI; sector privacy rules
2Is a regulated service or network of ours affected?Entity-scope register: are you an essential/important entity, a financial entity, NYDFS-covered, a TSA owner-operator, a UK OES/RDSP?NIS2 24h; DORA 4h; NYDFS 72h; TSA 24h; UK NIS 72h
3Is our product, in customers' hands, affected?Product security triage — is a vulnerability in a shipped product being actively exploited, or has a severe incident affected the product's security?CRA Art. 14 24h, from 11 Sept 2026
4Could this be material to investors?Disclosure committee convened; impact on operations, financial condition, resultsSEC Item 1.05 — four business days from determination
5Is there an extortion demand, and might we pay?Note or negotiation channel exists; board policy consultedNYDFS 24h on payment + 30-day narrative; AU 72h on payment; CIRCIA 24h once live
6Is an AI system involved, and in what role?AI inventory: is it a GPAI model with systemic risk that you provide, or an Annex III high-risk system?GPAI serious-incident duty to the AI Office is live; Annex III Art. 73 deferred

For each yes, record four separate timestamps. One field will not carry them, because the regimes use different words on purpose:

#T+2h to T+12h — Fire the sub-24-hour tier, tightest first

ClockWho it hitsDeadline
US federal agency reporting to CISAFederal civilian executive branch agencies1 hour from incident determination (major incidents: from declaration)
SOCI Part 2B critical incidentAU critical infrastructure responsible entities12 hours (see verification note)
DORA initial notificationEU financial entities4 hours from classifying as major; hard stop 24 hours from awareness
CRA early warning (from 11 Sept 2026)Manufacturers of products with digital elements on the EU market24 hours from awareness
NIS2 early warningEU essential and important entities24 hours from awareness
TSA Security Directive reportingDesignated pipeline and rail owner-operators24 hours from identification
NYDFS extortion paymentNYDFS covered entities24 hours from the payment
CIRCIA ransom payment (once the rule is live)Covered critical infrastructure entities24 hours from disbursement

#T+12h to T+24h — Stage the 72-hour tier and open the materiality track

Actionable takeaway: Turn this into a printed one-pager with the six facts, the four timestamp fields and the two tables. Hand it to the Notification Owner at declaration. Not a wiki page. A sheet of paper on the war room wall.


#Every regulatory clock

Appendix C has the at-a-glance matrix. What follows is the reasoning behind each entry, and the traps.

#EU GDPR — Articles 33 and 34

Who: any controller processing personal data in scope; processors owe a separate duty to the controller. Trigger: the controller "becomes aware" — a reasonable degree of certainty that a security incident occurred that compromised personal data. Deadline: without undue delay and, where feasible, not later than 72 hours after becoming aware; late notification must state the reasons for the delay. To data subjects: without undue delay where the breach is likely to result in a high risk to rights and freedoms. To whom: the competent supervisory authority (lead SA under the one-stop-shop), and affected individuals directly. Content: nature of the breach, categories and approximate numbers of data subjects and records, DPO contact, likely consequences, measures taken or proposed — and phased notification is expressly permitted. Exemptions: no SA notification if the breach is "unlikely to result in a risk"; no individual notice if data was rendered unintelligible (strong encryption), if subsequent measures eliminate the high risk, or if individual notice would be disproportionate effort — in which case a public communication is required. Penalty: up to €10m or 2% of global annual turnover, whichever is higher, under Art. 83(4). Failure to notify on time is a standalone infringement (Art. 33 GDPR; EDPB Guidelines 9/2022 v2.0).

#EU NIS2 — Directive (EU) 2022/2555, Article 23

Who: "essential" and "important" entities in the Annex I/II sectors, as implemented by each Member State. Trigger: becoming aware of a significant incident — one that has caused or is capable of causing severe operational disruption or financial loss, or considerable material or non-material damage to others. Three deadlines: early warning within 24 hours of awareness, indicating whether the cause is suspected unlawful or malicious and whether cross-border impact is likely; incident notification within 72 hours, updating the early warning with an initial severity and impact assessment and IoCs where available; final report not later than one month after the incident notification. An intermediate report may be requested by the CSIRT; if the incident is still ongoing at one month, a progress report then and a final report one month after the incident is handled. Also: a duty to inform recipients of your services of significant incidents likely to adversely affect service. Penalty floors under Art. 34: essential entities at least €10m or 2% of global turnover, important entities at least €7m or 1.4%, whichever is higher; Member States may go higher, and management bodies can be held personally liable and temporarily barred (Directive (EU) 2022/2555). Those floors are drawn from secondary reproductions of the directive rather than the primary Art. 34 text — they are widely and consistently reported, but check them before they go in front of a regulator or a board (see the verification notes in Appendix C).

The operationally important part is not the directive. It is the transposition, which is still incomplete two years past the 17 October 2024 deadline: the Commission opened infringement proceedings against 23 Member States in November 2024, issued reasoned opinions to 19 in May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the CJEU, seeking financial sanctions (EC).

#EU DORA — Regulation (EU) 2022/2554

In application since 17 January 2025. Who: roughly twenty categories of financial entity — credit institutions, payment and e-money institutions, investment firms, insurers and intermediaries, crypto-asset service providers, CSDs, CCPs, trading venues, fund managers — plus designated critical ICT third-party providers. Trigger: classification of an ICT-related incident as major under the RTS criteria. Initial notification: within 4 hours of classifying the incident as major, and in any event no later than 24 hours from becoming aware of the incident. Intermediate report: within 72 hours of submitting the initial notification, plus an updated report without undue delay once regular activities are recovered. Final report: no later than one month after the intermediate report. Weekend relief: where a deadline falls on a weekend or bank holiday, submission by noon the next working day — except for entities identified as significant by the competent authority. Significant cyber threats may be notified voluntarily. To whom: the national competent authority; significant credit institutions file nationally and the NCA transmits to the ECB (Commission Delegated Regulation (EU) 2025/301; Regulation (EU) 2022/2554).

#EU Cyber Resilience Act — Regulation (EU) 2024/2847, Article 14

The biggest new obligation landing in 2026, and the one most enterprise IR plans have no lane for.

Who: manufacturers of products with digital elements placed on the EU market — hardware and software, including operating systems, applications, libraries and components — wherever established. Importers and distributors have derived duties. Excluded: medical devices, motor vehicles, civil aviation, and non-commercial open source. Trigger: becoming aware of either (a) an actively exploited vulnerability in the product, or (b) a severe incident having an impact on the security of the product. Early warning: 24 hours from awareness. Notification: 72 hours. Final report: for an actively exploited vulnerability, within 14 days of a corrective or mitigating measure becoming available; for a severe incident, within one month of the 72-hour notification. To whom: the CSIRT designated as coordinator in your main establishment and ENISA simultaneously, through the CRA Single Reporting Platform — one submission, with the platform due operational 11 September 2026. Penalty: breach of Annex I essential requirements or of Articles 13 and 14 attracts up to €15,000,000 or 2.5% of global annual turnover, whichever is higher; other operator obligations €10m/2%; false or misleading information to a market surveillance authority €5m/1% (EC — CRA reporting; Regulation (EU) 2024/2847). Those Art. 64 amounts come from the Commission's reporting page and secondary reproductions of the article rather than the operative text — same caution as the NIS2 floors above, and same verification note in Appendix C.

Application dates: entry into force 10 December 2024; notified-body provisions 11 June 2026; Article 14 reporting from 11 September 2026; full application 11 December 2027.

Two traps. It applies to products already on the market, not only new placements, and it continues after the support period ends. And the trigger has nothing to do with your network — it is exploitation of a vulnerability in your product, in someone else's environment, which your enterprise IR path will never see. You need a separate product-security triage lane, and it is the tighter of the two: twenty-four hours, with no "where feasible" softener.

#EU AI Act — Article 73, and what is actually live

Status changed materially in July 2026, and most published guidance is now stale.

The Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744, was published in the OJ on 24 July 2026 and entered into force 27 July 2026 — days before the original 2 August 2026 high-risk deadline. It deferred Chapter III high-risk obligations, including the Art. 73 serious-incident regime, to 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products (Gibson Dunn; Cooley).

Still live today: Art. 5 prohibited practices (since 2 February 2025); GPAI provider obligations including Art. 55 serious-incident reporting to the AI Office (since 2 August 2025, with Commission enforcement powers over GPAI from 2 August 2026); and Art. 50 transparency and AI-content disclosure on the original 2 August 2026 schedule, with a narrow watermarking grace period to 2 December 2026.

When Art. 73 does apply, the shape is: a serious incident under Art. 3(49) — death, serious harm to health, serious and irreversible disruption of critical infrastructure, breach of fundamental-rights obligations, serious property or environmental damage — reported immediately after establishing a causal link and in any event not later than 15 days, compressed to 2 days for widespread infringement or serious and irreversible disruption of critical infrastructure, and 10 days where death is involved, to the market surveillance authority of the Member State where the incident occurred. Penalties under Art. 99 reach €15m or 3% of global turnover for provider/deployer obligations (AI Act Art. 73).

#SEC — Item 1.05 of Form 8-K and Item 106 of Reg S-K

Who: SEC reporting companies; foreign private issuers have a 6-K analogue. Trigger: the registrant determines that a cybersecurity incident is material. The determination itself must be made "without unreasonable delay" after discovery — the clock is not from discovery. Deadline: four business days after the materiality determination. Content: material aspects of the nature, scope and timing of the incident and the material impact or reasonably likely material impact, including on financial condition and results of operations. You are not required to disclose technical detail on systems, vulnerabilities or remediation that would impede response. Delay is available only where the U.S. Attorney General determines that disclosure poses a substantial risk to national security or public safety and so notifies the Commission in writing. Annually, Item 106 requires description of processes for assessing, identifying and managing material cyber risk, whether risks have materially affected or are reasonably likely to materially affect the registrant, and board oversight and management's role (SEC press release 2023-139; SEC small-entity compliance guide).

One clarification that saves a filing error: SEC staff have made clear that Item 1.05 is for incidents determined material. Voluntary disclosure of an incident you have not determined material belongs under Item 8.01 (Gerding statement, May 2024).

Also live and frequently missed: amended Regulation S-P incident-response and customer-notification requirements began phasing in for covered advisers, funds and broker-dealers across 2025 to June 2026.

#CIRCIA — the honest status

Who it will apply to: covered entities across the sixteen critical infrastructure sectors — CISA estimated more than 300,000 entities under the NPRM. Trigger: a covered cyber incident — substantial loss of confidentiality, integrity or availability; serious impact on the safety and resiliency of operational systems; disruption of business or industrial operations; or unauthorized access via a third-party or supply chain compromise or by a nation-state actor. Deadlines: 72 hours from the time the entity reasonably believes the covered cyber incident occurred, and 24 hours after a ransom payment is disbursed — including where the underlying incident is not itself reportable. Supplemental reports promptly on learning substantially new information, until the incident is fully mitigated and resolved. Enforcement: request for information, then subpoena, then referral to DOJ, with 18 U.S.C. §1001 false-statement exposure and contractor consequences (CISA CIRCIA; CIRCIA NPRM, 89 FR).

#HIPAA Breach Notification Rule — 45 CFR §§ 164.400–414

Who: covered entities — providers, health plans, clearinghouses — and business associates. Trigger: discovery of a breach of unsecured PHI, where discovery is the first day the breach is known, or by exercising reasonable diligence would have been known, to any workforce member other than the person who committed it. There is a presumption of breach unless a documented four-factor risk assessment shows a low probability of compromise. To individuals: without unreasonable delay and no later than 60 calendar days after discovery. To HHS/OCR at 500 or more individuals: contemporaneously with individual notice, no later than 60 days. Under 500: an annual log, within 60 days after the end of the calendar year in which discovery occurred. Media: prominent media serving the state or jurisdiction where 500 or more residents of that single state are affected, within 60 days — counted by residence, not by your location. Business associate to covered entity: without unreasonable delay, no later than 60 days after discovery — and BAAs routinely shorten this to five to fifteen days, so check yours. Law enforcement may request delay: a written request for the stated period, an oral request for up to 30 days. Penalty: tiered civil money penalties adjusted annually for inflation, plus resolution agreements and multi-year corrective action plans; state attorneys general may also sue under HITECH (HHS).

Sixty days is a ceiling, not a target. Several state laws run shorter and are not preempted where more stringent. Notifying at day 58 under HIPAA can breach a dozen state statutes on the same facts.

On the proposed HIPAA Security Rule overhaul — NPRM published 6 January 2025, comment period closed 7 March 2025 with more than 4,000 comments — it has not been finalized. OMB's Unified Agenda now targets July 2027 for final action, pushed back from a spring 2026 target (HIPAA Journal). OCR enforces the existing Security Rule. Nothing in the NPRM is enforceable today.

#PCI DSS v4.0.1

v4.0.1 is the only active version. v3.2.1 retired 31 March 2024; v4.0 retired 31 December 2024. On 31 March 2025 the 51 future-dated requirements became mandatory — the transition period is over, and every assessment conducted in 2026 is against the full v4.0.1 with no future-dated allowance (PCI SSC).

For this chapter, the key point is what PCI does not do: PCI DSS itself sets no external notification clock. Requirement 12.10.1 requires your IR plan to define roles, communications and notification of payment brands and acquirers — the brands' own programs govern timing, which in practice means immediately on suspected compromise, and may compel a PCI Forensic Investigator engagement. Exposure is contractual rather than regulatory: acquirer and brand fines, per-card assessments, forensic and reissuance costs, escalated merchant level, and at the extreme loss of card acceptance. Requirements 12.10.4.1, 12.10.5 and 12.10.7 now mandate IR training frequency, alert coverage and a defined response to PAN detected outside expected storage.

#US state breach notification laws

All 50 states plus DC, Puerto Rico, Guam and the US Virgin Islands. The trigger is unauthorized acquisition of usually-unencrypted, usually-computerized personal information — name plus SSN, driver's license or financial account, with most states now adding medical, health-insurance, biometric and online-account credentials. Most have an encryption safe harbour and a risk-of-harm exception. Most require notice to individuals plus, above a threshold, the state attorney general and the consumer reporting agencies, typically at 500 or 1,000 residents. Substitute notice is allowed above cost and volume thresholds. Where you are a HIPAA covered entity or GLBA-regulated, many states deem compliance with the federal rule sufficient — but not all, and often not for the AG notice.

The tight ones:

JurisdictionDeadline
Puerto Rico (Act 111)10 days to DACO from detection — non-extendable; DACO makes a public announcement within 24 hours. Shortest in the US
Vermont14 business days to the AG (individuals: 45 days)
Colorado, Florida, Maine, Washington, Texas, New York, California30 days
Texas30 days to individuals; 30 days to the AG at 250+ residents — one of the lowest AG thresholds
Many states60 days, or "the most expedient time, without unreasonable delay"

Changed recently, and worth encoding. New York S2659B (effective 21 December 2024) imposed a hard 30-day deadline to notify individuals, replaced the old "most expedient time possible" standard, required vendors to notify the data owner within 30 days, and added DFS as a required regulator recipient; S2376B (effective 21 March 2025) added medical and health-insurance information to "private information" (Hunton). California SB 446 (approved 3 October 2025) replaced the open-ended standard with 30 calendar days from discovery to notify residents, plus a sample notice to the AG within 15 calendar days of notifying consumers where more than 500 California residents are affected (leginfo.ca.gov).

Practical rule: build to a 30-day floor for multistate incidents, with a 10-day Puerto Rico carve-out and a 14-business-day Vermont AG carve-out.

#United Kingdom

UK GDPR / DPA 2018. Notify the ICO without undue delay and not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to rights and freedoms; reasons are required if late. Data subjects without undue delay where high risk. Report through the ICO's online form or its 24-hour helpline. Penalties reach £17.5m or 4% of global turnover at the higher tier; Art. 33/34 failures sit in the lower £8.7m / 2% tier (ICO).

NIS Regulations 2018 remain the operative UK network-and-information-systems law: operators of essential services and relevant digital service providers notify the competent authority without undue delay and not later than 72 hours after becoming aware of an incident with a significant or substantial impact on service continuity (ICO).

PECR: the telecoms and ISP personal data breach deadline moved from 24 hours to 72 hours on 20 August 2025, aligning with UK GDPR.

Cyber Security and Resilience (Network and Information Systems) Bill — in Parliament, not law. It cleared all Commons stages, entered the Lords on 25 June 2026, had its Second Reading on 14 July 2026, and began Grand Committee on 1 September 2026. Royal Assent is expected late 2026, but substantive effect comes through secondary legislation after an implementation consultation — realistically 2027–2028. When it lands it is expected to bring medium and large data centres and managed service providers into scope, introduce 24-hour initial notification and 72-hour full reporting with simultaneous NCSC notification, and add a customer-notification duty for data centres and digital and MSP providers (UK Parliament Bill 4035; gov.uk summary). Do not encode the 24/72 duty as live. Encode it as a 2027–28 readiness item, and note that the reported penalty figures circulating in commentary are not confirmed from the Bill text.

#NYDFS — 23 NYCRR Part 500

72 hours to notify the Superintendent, "as promptly as possible but in no event later than 72 hours after determining that a cybersecurity incident has occurred" at the covered entity, its affiliates, or a third-party service provider (§500.17(a)) — that third-party trigger catches a great many entities who think they are out of scope. 24 hours to notify after making an extortion payment (§500.17(c)), followed by a 30-day written description of why payment was necessary, what alternatives were considered, the diligence performed on those alternatives, and the diligence performed on sanctions and OFAC compliance. Annually by 15 April, a certification of material compliance or a written acknowledgement of non-compliance with a remediation plan, signed by the highest-ranking executive and the CISO, with supporting documentation retained five years. The final Second Amendment phase took effect 1 November 2025: MFA for any individual accessing any information system, subject to a limited small-entity exemption, plus written policies producing a documented asset inventory (23 NYCRR 500.17; NYDFS — How to report an extortion payment).

That 30-day narrative is the reason your OFAC screening must be documented as it happens. You cannot reconstruct diligence you did not perform.

#TSA and other sector directives

The TSA Security Directives — the SD Pipeline-2021-01 series and the rail equivalents — remain the operative law and require reporting cybersecurity incidents to CISA within 24 hours of identification, plus a Cybersecurity Coordinator available 24/7, an incident response plan and an annual assessment. TSA ratified the directives in a Federal Register notice of 17 January 2025. The "Enhancing Surface Cyber Risk Management" NPRM, published 7 November 2024 with comments closed 5 February 2025, would codify a permanent program and 24-hour CISA reporting; the final rule has not been issued as of September 2026 (Federal Register; Ratification of Security Directives).

If you are a TSA-designated owner-operator, the 24-hour CISA clock is live today — and it is shorter than CIRCIA's 72 hours will be.

FCC rules for telecoms, VoIP and TRS providers (47 CFR 64.2011, 64.5111) took effect 13 March 2024, extended beyond CPNI to customer PII, and cover inadvertent as well as intentional breaches. They require notification of the Commission and federal law enforcement as soon as practicable and no later than seven business days after a reasonable determination of a breach, and notification of customers as soon as practicable and no later than 30 days, subject to a harm-based exception. The Sixth Circuit upheld the rules in August 2025 in Ohio Telecom Ass'n v. FCC, with rehearing litigated into 2026. Contested but operative (Federal Register, 89 FR; Cooley).

#CMMC and DFARS

The 32 CFR CMMC Program rule became effective 16 December 2024. The 48 CFR acquisition rule was published 10 September 2025 and took effect 10 November 2025 — from that date DFARS 252.204-7021 and related CMMC language appear in new DoD solicitations and awards. Phase 1 runs 10 November 2025 to 10 November 2026: CMMC Level 1 and Level 2 self-assessment requirements in selected solicitations at the Program Office's discretion, phasing in DoD-wide over three years (48 CFR CMMC final rule; DoD CIO).

The reporting duty is separate and older, and it is live today for anyone handling CUI: DFARS 252.204-7012 requires rapid reporting of a cyber incident to DoD at https://dibnet.dod.mil within 72 hours of discovery, plus 90-day media preservation and malicious-software submission. Penalty exposure runs beyond contract termination to False Claims Act liability through DOJ's Civil Cyber-Fraud Initiative for false affirmations of compliance.

#Australia — ransomware payment reporting

In force since 30 May 2025. Who: a "reporting business entity" — an entity carrying on business in Australia with annual turnover of AUD 3 million or more in the last financial year, or a responsible entity for a critical infrastructure asset under the SOCI Act regardless of turnover. Trigger: making, or another entity making on your behalf, a ransomware or cyber extortion payment — any benefit, with no minimum threshold. Deadline: within 72 hours of making the payment or becoming aware of it. To whom: the Australian Signals Directorate through the ACSC online portal, with the Department of Home Affairs as joint recipient. Content includes the demand, the amount paid, the payment method and your communications with the actor. Penalty: a civil penalty of up to 60 penalty units — deliberately modest, because the policy aim is visibility rather than deterrence (Home Affairs factsheet; cyber.gov.au).

Actionable takeaway: Do not adopt this list. Take it to counsel and cut it down to the regimes that actually bind your entity, your data and your products, then record for each survivor the trigger, the deadline, the recipient, the portal and the local contact. Put a named owner and a quarterly re-verification date against every regime flagged in flux here — CIRCIA, the AI Act deferral, the UK Bill, the HIPAA Security Rule, the TSA surface rule, the next PCI version. A matrix nobody re-verifies does not stay right; it just stops telling you when it went wrong.


#Where the deadlines conflict

Six real conflicts, and what to do about each.

1. Speed versus accuracy. A 24-hour early warning is due long before forensics can support a materiality narrative or characterize a breach for GDPR. Anything you tell a CSIRT at hour 24 can be quoted back at you in securities litigation. Sequence: maintain two separate document sets — a regulator-facing factual early warning with explicit "preliminary, subject to change" framing, and a distinct disclosure-committee record. Never let a technical team file a regulatory early warning without disclosure counsel reviewing the wording. Twenty minutes of review has prevented a great many bad quarters.

2. Awareness versus determination. GDPR, NIS2 and the CRA run from awareness; the SEC from determination of materiality; CIRCIA from reasonable belief; NYDFS from determination that an incident occurred. These diverge by days. Sequence: the four-timestamp discipline above, set by named roles with recorded evidence.

3. Public disclosure versus an ongoing investigation. SEC Item 1.05 delay requires an Attorney General national-security determination — a very narrow door, and not available for ordinary law-enforcement convenience. Meanwhile the FCC, HIPAA and most state laws all permit law-enforcement-directed delay of customer notice. You can end up legally required to disclose publicly on Form 8-K while the FBI is asking you to hold customer notification. These are not the same obligation and the FBI cannot waive the securities one. Sequence: escalate to counsel the moment law enforcement is engaged, and get the delay request in writing with its scope stated. Never let the law-enforcement relationship silently override a securities obligation.

4. Twelve, twenty-four and seventy-two hours in the same incident. Sequence by deadline, tightest first, and parallelize the drafting. The 12-hour and 24-hour filings are short factual early warnings and should be drafted from a template by the Notification Owner. The 72-hour filings are substantive and need the Operations Lead. If you serialize, you will miss the tight ones while perfecting the loose ones.

5. Contractual clocks beat regulatory ones. BAAs compress HIPAA's 60 days to five or fifteen. Cyber policies require notice "as soon as practicable" and can deny coverage for late notice. Customer MSAs increasingly demand 24 to 48 hours. DFARS 252.204-7012 flows down to subcontractors. These are usually the first deadlines you actually miss, because they are in a contract repository nobody has indexed. Sequence: inventory them into the notification matrix alongside the statutes, keyed by counterparty, before you need them.

6. HIPAA's 60 days is not a safe harbour. State laws at 30 days — and 10 in Puerto Rico — are more stringent and are not preempted. Sequence: run the state analysis on the same clock as the HIPAA analysis, not after it.

Actionable takeaway: Take your own six regimes, put them on one page in deadline order, and mark every place two clocks want different words about the same fact. Agree the wording that satisfies the tightest clock without foreclosing the others — in peacetime, with counsel in the room. You will not draft that sentence well at hour four.


#Pre-drafted templates

These are drafts to adapt and pre-approve in peacetime. Variables are in <ANGLE BRACKETS>. Every one still requires Legal Liaison review before release; the point of pre-drafting is that the review takes fifteen minutes instead of four hours.

#1. Media holding statement

<ORGANISATION> is investigating a cybersecurity incident affecting <SYSTEM OR SERVICE, PLAINLY NAMED>. We became aware of the issue on <DATE> and immediately began an investigation with the support of external cybersecurity specialists.

<IF SERVICE IMPACT: We have taken <SERVICE> offline as a precaution, and we are working to restore it safely. / IF NO KNOWN SERVICE IMPACT: Our services are currently operating normally.>

We have notified <LAW ENFORCEMENT AND/OR THE RELEVANT REGULATOR, IF TRUE> and we are keeping them informed.

Our investigation is ongoing, and it is too early to confirm what information may have been affected. We will not speculate ahead of the facts. We will provide a further update by <SPECIFIC DATE AND TIME>, and sooner if there is something material to share.

Anyone affected should <SINGLE CONCRETE ACTION, OR: no action is required at this time>.

Media enquiries: <NAME, TITLE, EMAIL, PHONE>.

Why it works: it names a next update time, it says what you do not know without apologizing for not knowing it, and it contains nothing you may have to retract. What it deliberately omits: attribution, cause, record counts, the word "sophisticated," and any claim that data was not affected.

#2. Regulator notification skeleton

Adapt the headings to the portal; most ask for these fields in some order.

1. Reporting entity. <LEGAL ENTITY NAME>, <REGISTRATION/LICENCE NUMBER>, <JURISDICTION>. Reporting contact: <NAME, ROLE, EMAIL, 24H PHONE>. DPO where applicable: <NAME, CONTACT>.

2. Report type. <Early warning / Initial notification / Intermediate / Final / Supplemental> under <INSTRUMENT AND ARTICLE>.

3. Time of awareness. <DATE, TIME, TIMEZONE>. Basis for that determination: <HOW AWARENESS AROSE>.

4. Nature of the incident. <FACTUAL DESCRIPTION, OBSERVED ONLY. Whether the cause is suspected to be unlawful or malicious: known / suspected / not yet established.>

5. Categories and approximate numbers affected. Data subject categories: <CATEGORIES>. Approximate number of data subjects: <NUMBER OR RANGE>preliminary, method: <ENTITLEMENT SET / CONFIRMED ACQUISITION>. Approximate number of records: <NUMBER OR RANGE>, same basis.

6. Likely consequences. <ASSESSED CONSEQUENCES FOR AFFECTED INDIVIDUALS OR SERVICE RECIPIENTS>.

7. Cross-border impact. <Likely / not likely / not yet established>. Other jurisdictions notified: <LIST WITH DATES>.

8. Measures taken and proposed. Containment: <ACTIONS, WITH TIMES>. Mitigation for affected individuals: <ACTIONS>. Planned: <ACTIONS AND TARGET DATES>.

9. If filed after the deadline — reasons for the delay. <FACTUAL REASONS>.

10. Statement of status. This report is based on information available as at <DATE, TIME>. The investigation is ongoing and this assessment may change. We will submit a further report by <DATE> or sooner if material new information emerges.

Item 10 is not boilerplate. It is what makes a phased notification a phased notification rather than a statement you later contradict.

#3. Customer notification (data involved)

Subject: Important security notice regarding your <ACCOUNT / INFORMATION> — action required

Dear <NAME>,

We are writing to tell you about a security incident at <ORGANISATION> that involved some of your personal information. We are sorry this happened.

What happened. On <DATE>, we <DISCOVERED / WERE NOTIFIED> that an unauthorized party gained access to <SYSTEM, PLAINLY DESCRIBED>. We immediately began an investigation with external cybersecurity specialists and <CONTAINMENT ACTION>.

What information was involved. Our investigation indicates that the following information relating to you was affected: <SPECIFIC LIST — e.g. name, email address, date of birth>. <WHERE TRUE: The following information was NOT affected: <LIST — e.g. payment card numbers, passwords>.>

What we are doing. <CONTAINMENT AND REMEDIATION, PLAINLY.> We have notified <REGULATOR> and <LAW ENFORCEMENT WHERE TRUE>. <WHERE OFFERED: We are providing <SERVICE> at no cost to you for <PERIOD>; enrolment details are below and the enrolment deadline is <DATE>.>

What you can do. <NUMBERED, SPECIFIC ACTIONS. Change your password at <URL>. Review your account activity. Be alert to emails or calls referencing this incident — we will never ask you for your password or full payment details.>

For more information. <DEDICATED PAGE URL>. <DEDICATED PHONE NUMBER>, <HOURS>, reference <CODE>.

<NAME>, <TITLE>, <ORGANISATION>

Three drafting notes. Lead with what happened and what was affected, not three paragraphs about how seriously you take security. Name the data elements specifically — vague notices generate call volume you cannot staff, and regulators read them as evasion. And warn about follow-on phishing in the notice itself, because breach notifications are a known pretext and your customers are about to receive fake ones.

#4. Employee notification (first 4 hours)

Subject: Security incident — what we know and what we need from you

Team,

We are responding to a cybersecurity incident affecting <SYSTEM>. Here is what we know as of <TIME>.

What is happening. <PLAIN FACTS. WHAT IS OFFLINE. WHAT IS WORKING.>

What we need you to do. <NUMBERED AND SPECIFIC. Do not use <SYSTEM> until told otherwise. If you are asked to re-enter your credentials anywhere unexpectedly, do not — report it to <CHANNEL>. Report anything unusual to <CHANNEL / PHONE>, even if it seems minor.>

What we need you not to do. Please do not discuss this incident outside the company, including on social media, with customers, or with family. If you are contacted by a journalist, a customer or anyone claiming to be from a partner organization, do not respond — forward it to <COMMUNICATIONS CONTACT> immediately. This is not about secrecy; incomplete information spreads fast and inaccurate information makes the situation worse for everyone, including our customers.

What happens next. We will update you at <TIME> and daily at <TIME> after that, whether or not there is news. <WHERE TRUE: If our email is unavailable, updates will come via <OUT-OF-BAND CHANNEL>.>

You have not done anything wrong by reporting something, and you will not be in trouble for reporting something that turns out to be nothing. If you think you clicked something, tell us — right now, today. That is genuinely the most helpful thing anyone can do.

<NAME>, <TITLE>

That last paragraph earns its place. CISA's guidance is to be gracious about false alarms and to reward people who come forward (CISA IRP Basics). An employee afraid of being blamed will sit on the one detail that would have shortened your investigation by two days.

#5. Media statement (substantive, post-confirmation)

<ORGANISATION> today provided an update on the cybersecurity incident first disclosed on <DATE>.

What we now know. Our investigation, conducted with <EXTERNAL FIRM, IF DISCLOSED>, has determined that an unauthorized third party accessed <SYSTEM> between <DATE> and <DATE>. <WHERE CONFIRMED: The information involved includes <CATEGORIES>, relating to approximately <NUMBER> <individuals / customers>.>

Who we have told. We have notified <REGULATORS, BY NAME> and are cooperating fully. <WHERE TRUE: We have reported the matter to <LAW ENFORCEMENT AGENCY>.> <WHERE APPLICABLE: We began notifying affected individuals directly on <DATE>.>

What this means for people affected. <PLAIN-LANGUAGE IMPACT AND THE SPECIFIC ACTION. Acknowledge real-world consequences — cancelled appointments, delayed orders, disrupted service — not just data categories.>

What we are doing. <REMEDIATION, SPECIFIC AND VERIFIABLE.>

We recognize the concern this causes and we are sorry. We will continue to update <URL> as our investigation progresses.

Media contact: <NAME, EMAIL, PHONE>.

NCSC's rules apply throughout: provide accurate information about impact and avoid hyperbole; avoid saying anything you may have to retract; avoid compromising future regulatory or law-enforcement investigations through speculation or premature conclusions about cause, extent or who is responsible; and acknowledge real-world human impact, not only technical facts (NCSC).

Prepare the journalist Q&A document early too — NCSC treats it as an early priority, covering which services are affected, when they will be restored, who is behind it, whether it is ransomware, and whether regulators have been informed. You will be asked all five. Decide the answers once, in daylight.

Actionable takeaway: Pre-approve all five with counsel and your Executive Sponsor before you need them, and store the approved versions where the Communications Lead can reach them from a personal device with no corporate login. A perfect template inside an encrypted file share is a template you do not have.


Actionable takeaway: Fill in the four decide-by times and the four named authorities for your own organization, and put them on the printed contact card beside the insurer's after-hours line. Notice that every default under uncertainty on this page points the same way — escalate, engage, notify — because all four are cheap early and expensive late, and only one of them can void the money.


#Ransom payment

This section presents considerations. It does not tell you what to decide, and nothing here is legal advice. The decision is lawful to make either way in most jurisdictions today, and it belongs to your board and your counsel.

Decision authority must be pre-agreed. NCSC and insurance-industry joint guidance is clear that the ultimate decision rests with the victim, that organizations should involve the right people across the organization including technical staff, and — the line that matters most for playbook design — should "make sure the options aren't presented prematurely and that you provide the strongest possible evidence base" (NCSC).

The reason to settle it in advance is simple. At 3am, with production encrypted, a countdown running and a negotiator on the line, you are being asked to make a novel governance decision under time pressure that an adversary designed deliberately. That is the worst possible condition for a decision of that size. The board should decide, in daylight, at minimum: who holds the authority (typically the CEO with board or committee ratification — never the IC, never the CISO alone), what facts must be established before options are even presented, what the financial ceiling is and who can raise it, and whether any category will not be paid under any circumstances. Write those four answers down. Review them annually. That is the deliverable.

Facts to establish before options are presented, per the same guidance: root cause — because "making a payment without clarifying the original source for the compromise… leaves your organization open to further incidents"; the state of backups and the realistic restore time; whether a free decryptor exists through law enforcement; the separate business, data and financial impacts; and whether payment would actually solve the problem in front of you. Note also that the ICO does not consider a payment to criminals a risk mitigation, and it would not reduce a penalty.

The OFAC problem. OFAC's updated advisory of 21 September 2021 applies strict liability: a US person can face civil penalties for a transaction with a sanctions nexus "regardless of intent or knowledge," under IEEPA and TWEA. License applications to pay ransoms carry a presumption of denial. The advisory is aimed not only at victims but explicitly at financial institutions, cyber-insurance firms and forensic and incident-response firms — so your vendors have their own exposure and their own counsel telling them about it. Mitigating factors in an enforcement action include meaningful steps taken in advance to reduce ransomware risk, and prompt, complete reporting to law enforcement and CISA plus full cooperation (OFAC Updated Advisory).

The playbook consequence is concrete: the ransom node must call out to a sanctions screening step — blockchain attribution plus an OFAC SDN check, through counsel, before any negotiation concludes — a counsel gate, an insurer notification, and a law enforcement and CISA report. And it must record that the screening happened, because the mitigating-factor argument later depends on documented diligence. NYDFS will ask for exactly this, in writing, within 30 days of a payment.

Payment reporting obligations, if you pay. Payment triggers duties that non-payment does not, and the moment of disbursement is a fresh T+0:

RegimeDeadlineNote
NYDFS §500.17(c)24 hours from the payment, plus a 30-day written narrativeNarrative must cover necessity, alternatives considered, diligence on alternatives, and OFAC diligence
Australia72 hours from making the payment or becoming aware of itAUD 3m turnover or SOCI responsible entity; no minimum payment threshold
CIRCIA24 hours from disbursement — once the rule is in forceReportable even where the underlying incident is not
UKAnnounced, not in forceGovernment confirmed in July 2025 it will proceed with a targeted ban on payments by public sector bodies and CNI operators, plus a payment-prevention regime requiring other businesses to notify government of an intention to pay (Pinsent Masons)

Context for the board. Payment rates are at record lows — Sophos found 48% of encrypted victims paid, and the 2026 DBIR reports 69% of ransomware victims did not pay (Sophos). The payment rate for data-exfiltration-only cases fell to 15% in Coveware's Q2 2026 caseload, with victims citing the volatility of post-payment outcomes. One number to keep out of your reserve model: Coveware's Q2 2026 average payment was $1,880,612, up 176% quarter on quarter, while the median fell 50% to $150,000 (Coveware by Veeam). The average is distorted by a handful of very large payments. Use the median.

Actionable takeaway: Get the board's four answers in writing this quarter — who approves a payment, what facts must exist before options are even presented, what the ceiling is and who may raise it, and what will never be paid under any circumstances. Attach the sanctions-screening path and the payment-reporting clocks to the same page, and review it annually. You are not deciding here whether to pay. You are deciding who decides, on what evidence, before an adversary picks the hour for you.


#Law enforcement: what it gets you, and what it costs you

Engaging law enforcement is a real decision with real trade-offs. Treating it as an automatic reflex, or an automatic refusal, is how organizations get it wrong in both directions.

What it gets you. In the US federal model the FBI and NCIJTF lead threat response — investigation, forensics, interdiction, attribution — while CISA leads asset response. Practically: potential recovery of fraudulently transferred funds, which is time-critical and often the single largest financial argument for calling early; access to decryptors held from prior takedowns; threat intelligence you cannot obtain otherwise; a formal record supporting insurance and regulatory positions; and the OFAC mitigating-factor argument. In some sectors it is also a reporting relationship you already have.

What it costs you. You introduce a party whose priorities are legitimate and are not your recovery timeline. You may receive requests to preserve systems or delay remediation, and requests to delay customer notification — permitted under HIPAA, the FCC rules and most state laws, but not a defense to an SEC obligation, since Item 1.05 delay requires an Attorney General national-security determination. Information you provide may be discoverable. Engagement is not reversible. And it takes time from a team that has none.

How to do it well. Engage through counsel, so the relationship is managed and the privilege posture is considered. Have one named liaison, not five people talking to three agencies. Coordinate on evidence preservation before eradication — eradication destroys what they need, and this is the most common avoidable friction point. Get any delay request in writing with its scope and duration stated, and reconcile it immediately against every other clock. And build the relationship before the incident: the first call to a field office should not be your first conversation with them.

Actionable takeaway: Find your local FBI field office or national CERT contact and introduce yourself this quarter, while nothing is on fire. The pre-existing relationship is what converts a bureaucratic intake into a useful call. It costs one coffee and it is the highest-leverage thirty minutes in this chapter.


Regulatory notification is the one part of incident response where doing the work well looks exactly like doing nothing dramatic. No heroics, no clever containment, just a person with a printed sheet, four timestamps and a filing that went in on time and incomplete rather than late and perfect. Get the clocks on the wall, get the templates approved, get counsel on the call before the first assessment. Stay documented, stay on the clock, and never let a joke into the incident channel.


#Chapter checklist


#Sources

  1. GDPR Article 33 — https://gdpr-info.eu/art-33-gdpr/
  2. EDPB Guidelines 9/2022 on personal data breach notification, v2.0 — https://www.edpb.europa.eu/system/files/2023-04/edpb_guidelines_202209_personal_data_breach_notification_v2.0_en.pdf
  3. Bird & Bird — Digital Omnibus package and a single EU harmonized incident reporting regime — https://www.twobirds.com/en/insights/2025/digital-omnibus-package-single-eu-harmonized-incident-reporting-regime-across-cyber-and-data-protect
  4. Directive (EU) 2022/2555 (NIS2), Article 23 — https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555
  5. European Commission — Commission calls on 23 Member States to fully transpose NIS2 — https://digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive
  6. Commission Delegated Regulation (EU) 2025/301 (DORA incident reporting RTS) — https://eur-lex.europa.eu/eli/reg_del/2025/301/oj
  7. Regulation (EU) 2022/2554 (DORA) — https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
  8. DLA Piper — Divergence in administrative penalties under DORA — https://www.dlapiper.com/en-us/insights/publications/2025/10/divergence-in-administrative-penalties-under-dora
  9. European Commission — Cyber Resilience Act reporting obligations — https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
  10. Regulation (EU) 2024/2847 (Cyber Resilience Act) — https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R2847
  11. EU AI Act, Article 73 — https://artificialintelligenceact.eu/article/73/
  12. EU AI Act, Article 55 — https://artificialintelligenceact.eu/article/55/
  13. Gibson Dunn — EU AI Act Omnibus: postponed high-risk deadlines — https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
  14. Cooley — Digital AI Omnibus delays key deadlines — https://cdp.cooley.com/digital-ai-omnibus-delays-key-deadlines-introduces-new-rules/
  15. SEC press release 2023-139 — cybersecurity disclosure rules — https://www.sec.gov/newsroom/press-releases/2023-139
  16. SEC — small-entity compliance guide, cybersecurity risk management and incident disclosure — https://www.sec.gov/resources-small-businesses/small-business-compliance-guides/cybersecurity-risk-management-strategy-governance-incident-disclosure
  17. SEC — Gerding statement on cybersecurity incident disclosure (May 2024) — https://www.sec.gov/newsroom/speeches-statements/gerding-cybersecurity-incidents-05212024
  18. SEC — rulemaking activity, 2026 — https://www.sec.gov/rules-regulations/rulemaking-activity?year=2026
  19. Sidley — SEC Chair Atkins announces Regulation S-K reform initiative — https://www.sidley.com/en/insights/newsupdates/2026/01/sec-chair-atkins-announces-initiative-to-reform-regulation-s-k
  20. CISA — Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) — https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia
  21. CIRCIA NPRM, 89 FR (4 April 2024) — https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements
  22. Hunton — CISA plans to finalize cyber incident reporting regulations in September 2026 — https://www.hunton.com/privacy-and-cybersecurity-law-blog/cisa-plans-to-finalize-cyber-incident-reporting-regulations-in-september-2026
  23. HHS — HIPAA Breach Notification Rule — https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
  24. HIPAA Journal — HIPAA Security Rule update postponed — https://www.hipaajournal.com/hipaa-security-rule-update-postponed/
  25. PCI SSC — Now is the time to adopt the future-dated requirements of PCI DSS v4.x — https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x
  26. PCI SSC — Updated guidance: responding to a data breach — https://blog.pcisecuritystandards.org/updated-guidance-responding-to-a-data-breach
  27. Privacy Rights Clearinghouse — Data Breach Notification Laws 50-State Survey, 2026 edition — https://privacyrights.org/resources-tools/reports/data-breach-notification-laws-50-state-survey-2026-edition
  28. Hunton — New York data breach notification law updated — https://www.hunton.com/privacy-and-information-security-law/new-york-data-breach-notification-law-updated
  29. California SB 446 (2025) — https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB446
  30. ICO — Personal data breaches: a guide — https://ico.org.uk/for-organizations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/
  31. ICO — NIS incident reporting — https://ico.org.uk/for-organizations/the-guide-to-nis/incident-reporting/
  32. UK Parliament — Cyber Security and Resilience (Network and Information Systems) Bill, Bill 4035 — https://bills.parliament.uk/bills/4035
  33. gov.uk — Summary of the Cyber Security and Resilience Bill — https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/summary-of-the-bill
  34. 23 NYCRR 500.17 (Cornell) — https://www.law.cornell.edu/regulations/new-york/23-NYCRR-500.17
  35. NYDFS — How to report an extortion payment — https://www.dfs.ny.gov/system/files/documents/2025/09/How-To-Report-an-Extortion-Payment_0.pdf
  36. Federal Register — Ratification of Security Directives (17 January 2025) — https://www.federalregister.gov/documents/2025/01/17/2025-01243/ratification-of-security-directives
  37. Federal Register — Enhancing Surface Cyber Risk Management NPRM — https://www.federalregister.gov/documents/2024/11/07/2024-24704/enhancing-surface-cyber-risk-management
  38. Federal Register — FCC Data Breach Reporting Requirements, 89 FR (12 February 2024) — https://www.federalregister.gov/documents/2024/02/12/2024-01667/data-breach-reporting-requirements
  39. Cooley — Court of appeals upholds FCC data breach reporting and notification rules — https://www.cooley.com/news/insight/2025/2025-08-20-court-of-appeals-upholds-fcc-data-breach-reporting-and-notification-rules
  40. Federal Register — 48 CFR CMMC final rule (10 September 2025) — https://www.federalregister.gov/documents/2025/09/10/2025-17143/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
  41. DoD CIO — CMMC — https://dodcio.defense.gov/CMMC/
  42. Australian Department of Home Affairs — Ransomware payment reporting factsheet — https://www.homeaffairs.gov.au/cyber-security-subsite/files/factsheet-ransomware-payment-reporting.pdf
  43. cyber.gov.au — Report a ransomware payment — https://www.cyber.gov.au/ransomware-payment-reporting
  44. NCSC — Guidance on effective communications in a cyber incident — https://www.ncsc.gov.uk/files/NCSC-Guidance-on-effective-communications-in-a-cyber-incident.pdf
  45. NCSC — Guidance for organizations considering payment in ransomware incidents — https://www.ncsc.gov.uk/files/Guidance-for-organizations-considering-payment-in-ransomware-incidents.pdf
  46. CISA — Incident Response Plan Basics — https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf
  47. CISA — I've Been Hit By Ransomware — https://www.cisa.gov/stopransomware/ive-been-hit-ransomware
  48. British Library — Learning Lessons from the Cyber-Attack (8 March 2024) — https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf/
  49. SEC press release 2023-227 — SEC charges SolarWinds and CISO — https://www.sec.gov/newsroom/press-releases/2023-227
  50. Davis Wright Tremaine — Discovery protections for data breach investigations — https://www.dwt.com/blogs/privacy--security-law-blog/2021/08/discovery-protections-data-breach-investigations
  51. Morrison Foerster — Six considerations to preserve privilege — https://www.mofo.com/resources/insights/231010-six-considerations-to-preserve-privilege
  52. OFAC — Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments — https://ofac.treasury.gov/system/files/126/ofac_ransomware_advisory.pdf
  53. Pinsent Masons — Ransomware payments ban, UK — https://www.pinsentmasons.com/out-law/news/ransomware-payments-ban-uk
  54. Sophos — State of Ransomware 2026 — https://www.sophos.com/en-us/blog/sophos-state-of-ransomware-2026
  55. Coveware by Veeam — Cyber extortion payment trends, Q2 2026 — https://www.veeam.com/blog/cyber-extortion-payment-trends-q2-2026.html
  56. CISA — Federal Incident Notification Guidelines — https://www.cisa.gov/federal-incident-notification-guidelines
This page is one chapter of The 2026 InfoSec Playbook, a free field manual by Daniel Ramos. Checklist statuses and the live coverage model are in the full manual. Free, in full, no email wall.