For an NYSE-listed company facing ransomware, treat response, SEC disclosure, and exchange coordination as related but separate workstreams. Do not let a ransom payment, apparent recovery, or ongoing negotiation substitute for a timely materiality assessment. For a domestic SEC registrant, Form 8-K Item 1.05 is generally due within four business days after the company determines the incident is material; coordinate material-news handling with the NYSE under the issuer’s applicable rules and current procedures.
First, separate the decisions that run in parallel
A ransomware incident can require urgent operational choices while the company is still determining what happened and how serious the consequences are. Keep these workstreams connected through a coordinated response, but do not treat one as a proxy for another:
- Containment and recovery: protect people and operations, preserve evidence, assess exposure, and identify viable restoration options.
- SEC disclosure: assess materiality based on the incident’s facts and effects, then meet the applicable filing requirements if it is material.
- NYSE material-news coordination: work through the exchange’s current procedures when material news is involved. This is not a substitute for the SEC analysis.
Assign clear owners for each track. Security and incident-response leaders should establish the operational facts; legal and disclosure teams should lead the materiality analysis; executives should make and document decisions; and communications and investor relations should coordinate accurate external messaging. Involve the insurer and appropriate outside incident-response and legal support as applicable.
What does a ransomware payment mean for SEC disclosure?
For domestic registrants, the SEC’s small-entity compliance guide says a company must file Form 8-K Item 1.05 within four business days after determining that a cybersecurity incident is material. The deadline runs from the materiality determination, and the company must not unreasonably delay making that determination. The SEC adopted its cybersecurity disclosure rules on July 26, 2023; they became effective September 5, 2023.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
The SEC’s Form 8-K interpretations address ransomware directly. They make clear that payment, restoration, insurance reimbursement, or the amount paid does not decide materiality by itself:
- Payment or apparent resolution before the assessment: If the company pays and disruption ends or data is returned before it determines materiality, it still must make that determination. Resolution alone does not establish that the incident was immaterial (SEC Form 8-K C&DI Q104B.05).
- Payment or recovery after a materiality determination: If the company has determined the incident is material, later payment or restoration does not eliminate the Item 1.05 filing obligation (Q104B.06).
- Insurance reimbursement: Reimbursement of all or a substantial portion of a ransom payment does not necessarily make the incident immaterial. Consider the relevant quantitative and qualitative effects, including longer-term impacts (Q104B.07).
- Payment size and related events: The payment amount alone does not determine materiality. Depending on the facts, related incidents may need to be considered together (Q104B.08–Q104B.09).
Materiality analysis should reflect the incident’s actual and reasonably understood effects on the company, not a single metric or a negotiation outcome. Consider operational disruption, business and customer consequences, data exposure, financial effects, and longer-term impacts as facts develop. Document the basis and timing of the determination.
The four-business-day Item 1.05 framework described above is for domestic registrants. Foreign private issuers follow a different Form 6-K framework, so they should not assume the domestic deadline applies to them; consult the SEC compliance guide and company-specific counsel.
How should an NYSE-listed issuer coordinate with the exchange?
NYSE Regulation’s Market Watch and Corporate Actions group enforces the Exchange’s Timely Alert Policy, monitors listed issuers’ material-news disclosure obligations, and can implement regulatory trading halts. The exchange also describes timely-alert policies for material news releases. This establishes NYSE’s role in material-news coordination; it does not establish that every ransomware incident automatically requires a specific exchange notification.
When a ransomware incident may involve material news, coordinate with NYSE Market Watch under the current procedures and rules applicable to the issuer and event. Check the applicable Listed Company Manual and current exchange process rather than relying on a blanket rule inferred from the incident type. Keep this exchange coordination distinct from the company’s SEC materiality assessment and any Item 1.05 filing.
| Workstream | What it addresses | Key point |
|---|---|---|
| SEC disclosure | Whether the incident is material to investors and whether a filing is required | For domestic registrants, the four-business-day Item 1.05 period begins after the materiality determination. |
| NYSE coordination | Exchange timely-alert and material-news procedures | Coordinate with Market Watch under current issuer-specific rules and procedures; ransomware alone does not establish a universal notification trigger. |
What to do before deciding whether to negotiate or pay
Federal guidance does not offer a guaranteed bargaining script or a reliable promise that an attacker will decrypt systems or keep stolen data private. CISA, MS-ISAC, NSA, and FBI’s #StopRansomware Guide recommends a planned, coordinated response, evidence preservation, reporting, and checking for available recovery options. A CISA/FBI/NSA advisory strongly discourages payment: paying does not guarantee recovery and may embolden attackers or fund further illicit activity.
Rank #4
- Activate the incident-response and communications plans. Bring together security, executive leadership, legal, communications, investor relations, insurance, and appropriate incident-response specialists. Establish who can make operational and payment decisions and who owns disclosure analysis.
- Contain the incident and preserve evidence. Follow the response plan to limit further harm. Preserve volatile evidence and system artifacts, and keep records of decisions and communications. Avoid actions that could destroy evidence or impair investigation and recovery.
- Report and seek assistance. The joint federal guide recommends reporting to CISA, the FBI, or other relevant authorities. Consult law enforcement: decryptors may exist for some ransomware variants, and official assistance may inform the response.
- Assess recovery paths before weighing a payment. Determine what can be restored from backups, whether a known decryptor may apply, what systems remain compromised, and what business or safety consequences could follow from each option. Evaluate separately the possibility of restoring encrypted systems and the risk of data publication; a payment cannot guarantee either outcome.
- Evaluate the decision with company-specific advice. Consider operational restoration prospects, ongoing compromise, data exposure, customer and business impacts, legal and disclosure consequences, insurance terms, and applicable payment constraints. Obtain advice from qualified company counsel on legal issues; the cited federal guidance does not resolve sanctions or payment legality for a particular company.
- Keep communications accurate and coordinated. Align internal, customer, investor, regulator, law-enforcement, and exchange communications through the response plan. Do not promise that payment will recover systems or prevent disclosure of stolen information.
When can an SEC disclosure be delayed?
Negotiations, system restoration, an incomplete investigation, or contact with law enforcement do not by themselves pause the SEC deadline. The FBI describes a narrow, agency-mediated process for requesting a delay when disclosure poses a substantial risk to national security or public safety. It is not a general-purpose extension or a unilateral company decision. A company may consult DOJ, the FBI, CISA, or other agencies at any point, including before it completes its materiality assessment, but that consultation is distinct from obtaining an authorized delay.
The SEC compliance guide also clarifies that an Item 1.05 filing need not expose technical details about planned response, systems, networks, or vulnerabilities at a level that would impede response or remediation. That limit is not a blanket exemption from disclosing material information.
Best Value
Build readiness before an incident
Negotiation pressure is a poor time to decide who can authorize a payment, how the company will assess materiality, or who communicates with the exchange. The #StopRansomware Guide recommends maintaining and exercising incident-response and communications plans. For an NYSE-listed company, readiness should also make the handoffs between operations, legal, disclosure, investor relations, and exchange coordination explicit.
- Define decision authority and escalation paths for operational response and any payment consideration.
- Include materiality assessment and disclosure ownership in incident exercises.
- Prepare a process for preserving evidence, reporting to authorities, and engaging incident-response support.
- Identify who will coordinate accurate communications with investors, customers, regulators, and the exchange.
- Review the issuer’s current NYSE procedures and its SEC reporting obligations with company-specific counsel.
SEC Chair Gary Gensler said on July 26, 2023: “Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors.” The practical implication for an incident team is to assess consequences rather than assume that the technical label, payment decision, or eventual recovery settles the disclosure question.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

