Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should public companies handle cybersecurity disclosure after…
Cyber Security

How should public companies handle cybersecurity disclosure after a major incident like SolarWinds?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Cyber Security

Public companies should disclose incident impact in clear, specific terms as soon as they can reasonably assess materiality, rather than relying on vague or hypothetical language. When files, credentials, or cloud data are known to be accessed, the disclosure should say so plainly. The goal is to give investors a truthful picture of scope, not to minimize uncertainty with broad wording.

What Public Disclosure Needs to Accomplish After a Major Cyber Incident

For public companies, the disclosure problem is not just “what happened,” but whether investors can understand the scale, timing, and likely business effect of the incident. After a major event, management should move from generic risk language to concrete facts as soon as materiality can be assessed. If files, credentials, cloud data, or systems were accessed, the disclosure should say that plainly.

That principle matters because vague statements can obscure whether the issue is a theoretical exposure, a contained event, or an active compromise with real confidentiality or integrity impact. Investors do not need false certainty, but they do need an accurate picture of what was actually reached, what remains uncertain, and what the company knows today.

Good disclosure also distinguishes incident scope from remediation progress. A company may still be investigating root cause, persistence, or downstream exposure, but that uncertainty does not justify hiding confirmed impact. The right standard is specificity where facts are known, paired with disciplined language where facts are still being verified.

  • Use concrete terms for confirmed access, affected data, and compromised systems.
  • Separate known facts from open questions instead of blending them into one cautious statement.
  • Avoid wording that sounds protective but leaves investors unable to judge severity.

Why Vague Language Creates Market and Governance Risk

After a significant incident, vague disclosure can create a second problem beyond the breach itself: it can distort investor judgment about materiality. If the company knows credentials were exposed, cloud resources were accessed, or sensitive files were copied, then language that merely references a “security event” or “possible exposure” can understate the actual risk profile.

This is especially important when the incident may affect financial reporting, operational continuity, customer trust, or legal exposure. Once an event crosses the threshold into material information, the company’s obligation is to communicate clearly, not to preserve ambiguity until every investigative question is answered.

Failure mechanism: The company frames confirmed compromise in tentative terms, so the market cannot distinguish verified loss from speculative risk. That weakens governance oversight and can leave disclosure decisions too dependent on legal caution rather than factual completeness.

Impact: Investors may misprice the event, analysts may draw the wrong conclusions about scope, and later updates may appear inconsistent or misleading when fuller facts emerge.

One practical lesson is that disclosure quality should be judged by precision, not tone. A statement can be careful without being evasive. The more directly the company can describe what was accessed and what was not, the more credible the disclosure becomes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyMaterial cyber incidents require governance choices on how risk and impact are communicated.
RS.CO — CommunicationsIncident disclosure is a communications discipline that must convey confirmed facts clearly.
GV.OV — OversightBoard and executive oversight should ensure public statements are accurate and materially complete.
Recommendation — Align disclosure timing and detail to the company’s risk management process and materiality judgment. Coordinate internal and external incident communications so confirmed impact is stated precisely. Use oversight reviews to challenge vague wording and confirm disclosure matches known facts.
CIS Controls v817 — Incident Response ManagementMajor incidents need disciplined response communication and post-incident handling.
8 — Audit Log ManagementConfirmed access claims should be supported by logs and investigation evidence.
Recommendation — Apply incident response governance to ensure disclosures track verified investigation findings. Retain logs and investigation evidence that substantiate the facts disclosed to investors.
NIST SP 800-63IAL — Identity Assurance LevelIf credentials were exposed, the disclosure depends on understanding the trustworthiness of identity proofing and access risk.
Recommendation — Assess whether exposed credentials materially change assurance and access risk in the incident.

Practitioner Guidance

What to verify: Confirm that management’s public language matches the investigative record on access, exfiltration, and affected asset classes. If the team knows files, credentials, or cloud environments were accessed, that fact should not be hidden behind a generic incident description.

Decision rule: If the company has confirmed material access or compromise, prioritize clear disclosure of scope first, then continue refining root-cause and remediation detail in later updates. Do not wait for perfect attribution before stating what is already known.

What practitioners underestimate: The biggest disclosure failure is often not an inaccurate technical statement, but an overly cautious one that prevents investors from understanding the real business consequence of the incident.

Practitioner takeaway: The goal is not to eliminate uncertainty, it is to make sure uncertainty is clearly bounded and never used to soften facts that are already known.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org