A CISO needs three things in the first 24 hours of a breach: a verified fact sheet, a named owner for every outside statement, and a holding statement that claims nothing the forensics team has not confirmed. IBM's 2026 Cost of a Data Breach Report puts the global average breach at $4.99 million, so each hour spent guessing in public adds cost.
The risk is personal as well as corporate. A federal jury convicted Uber's former chief security officer in 2022 for hiding a 2016 breach from regulators.
What does a CISO own in the first 24 hours?
A CISO owns the facts and the clock during the first 24 hours, and the communications team owns the words built from those facts. The most common mistake I see is a split in ownership: the security team knows what happened but writes nothing down, and the communications team drafts statements with nothing to check them against.
The table splits the work by hour, and every row ends in a document.
| Hours | CISO owns | Communications owns | Output |
|---|---|---|---|
| 0 to 4 | Confirm the incident is real, isolate affected systems, open a decision log | Pause scheduled posts and campaigns, name one spokesperson, start the contact tree | One-page fact sheet, version 1 |
| 4 to 8 | Engage outside forensics and counsel, preserve evidence, list the open scope questions | Draft the holding statement and the employee note from the fact sheet | Approved holding statement |
| 8 to 16 | Brief the CEO and board in writing, assess whether customer data is involved | Prepare customer, partner and press questions and answers, set up one owned page for updates | Written leadership brief, Q&A sheet |
| 16 to 24 | Update the scope and mark what changed since version 1 | Publish the first update on the owned page, route every inquiry into one log | Time-stamped update with a named next update time |
Why it works: A fact sheet with a version number gives every statement one source and shows every change. The Uber record shows what the alternative looks like. According to the Department of Justice, Uber's security chief deleted from a draft summary the statement that the 2016 hack involved personal information, and a jury later convicted him of obstruction (U.S. Department of Justice, October 5, 2022).
Which deadlines start when a breach is found?
Public companies in the United States must file an Item 1.05 Form 8-K within four business days after they determine that a cybersecurity incident is material, according to the SEC's July 2023 cybersecurity disclosure rule.
The SEC allows a delay in one case: the U.S. Attorney General must determine that immediate disclosure would pose a substantial risk to national security or public safety and notify the SEC in writing. An ongoing internal investigation does not qualify.
The CISO does not make the materiality call. Counsel and the disclosure committee make it, and they make it with the CISO's fact sheet in hand. Other clocks run alongside the SEC rule.
| Clock | Who it binds | What starts it |
|---|---|---|
| SEC Form 8-K Item 1.05 | Public companies | A determination that the incident is material |
| Customer contracts | The company and each customer | The notice clause in each agreement |
| Cyber insurance policy | The policyholder | The notice window in the policy |
| State and foreign privacy regulators | Companies holding residents' data | The rules of each jurisdiction |
Read the contract and insurance notice clauses now and put the shortest window at the top of the fact sheet template. My 72-hour breach playbook goes through the regulatory clocks in more detail.
What belongs in the first holding statement?
The first holding statement says what happened, what the company is doing, what is still unknown, and when the next update arrives. It makes no claim the forensics team has not confirmed.
Atlassian committed to this structure in its incident communications playbook after its April 2022 outage. The company's own post-incident review lists what every update must cover: what happened, who was affected, the timeline to restoration, expected data loss with a confidence level, and how to reach support. That outage was not a breach, but the failure was the same one a CISO faces. Atlassian's first broad public message went out on April 7, about two days after 775 customers lost access on April 5, and the company wrote that it should have communicated earlier.
| Element | Write this | Leave this out |
|---|---|---|
| What happened | The date and time of detection, in plain words | The attacker's name or a guess at motive |
| What you are doing | Containment steps, an outside forensic firm, law enforcement notified | Claims such as "the threat is eliminated" |
| What you do not know | Whether customer data was involved | Any number you have not verified |
| Who is affected | The groups under review | A promise that no one was harmed |
| Next update | A named time, on the owned page | The phrase "as soon as possible" |
Illustrative holding statement: "On Tuesday morning our security team detected unauthorized access to part of our network. We have contained the activity, hired outside forensic investigators and notified law enforcement. We do not yet know whether customer data was involved. We will publish our next update on this page by 6 p.m. Eastern today."
Why it works: A named update time gives reporters, customers and employees a date to wait for. Atlassian's review names the missing timeline as a mistake and states that even a directional restoration estimate would have let customers plan around the outage (Atlassian, April 2022).
What did the Uber breach teach about concealment?
The Uber case teaches that concealment begins in the first hours, when someone decides who is told. Hackers emailed Uber's chief security officer on November 14, 2016, and employees verified that records on about 57 million users and 600,000 driver license numbers had been stolen. Uber paid the hackers $100,000 in bitcoin in December 2016 and disclosed the breach to the public and to the FTC in November 2017, according to the Department of Justice announcement of the conviction.
A federal jury convicted Joseph Sullivan on October 5, 2022 of obstructing the FTC's proceedings and of misprision of a felony. The Department of Justice said Sullivan told a subordinate that the story outside the security group was that "this investigation does not exist." It also said he never mentioned the breach to the Uber lawyers who were handling the FTC inquiry. I covered the company's later disclosure in my 2017 to 2019 Uber archive.
Three rules follow from the record.
- Tell counsel in hour one, including counsel who work on unrelated regulatory matters.
- Write the CEO brief down and date it.
- Treat any payment to attackers as a legal and disclosure decision made by the executive team, not a security-team decision.
Why it works: Prosecutors judge a breach response by what the company said and when. A hidden decision in hour one became a criminal exhibit years later (U.S. Department of Justice, October 2022).
How do you brief the CEO and board in hour eight?
Brief the CEO and board with a one-page written document that lists what is known, what is unknown, what decision is needed and when the next update arrives.
| Section | Content | Test |
|---|---|---|
| Known | Facts confirmed by forensics, each with a time | Could an outside investigator verify each line? |
| Unknown | Open questions, each with a named owner | Does every question have a deadline? |
| Decision needed | Notify regulators, notify customers, engage law enforcement, respond to a ransom demand | Is the decision-maker named? |
| Next update | A clock time and a channel | Will the CEO know when to expect it? |
The Department of Justice said Sullivan told Uber's new chief executive that the hackers had been paid only after they were identified, which was false. Do not soften a number or a date to make the call easier. The next people to read the brief may be the board, a regulator or a court.
Why it works: A one-page brief with a version number forces the CISO to separate what is confirmed from what is assumed.
Who speaks to customers, employees and the press?
One named spokesperson speaks for the company, and every other leader sends inquiries to a single log. Employees hear the facts at the same time as the public, or before, because every employee is a potential source for a reporter.
Keep a copy of the contact tree outside the network under attack. Atlassian's 2022 incident deleted its customers' site administrator contacts, and the company spent days rebuilding a contact list from billing systems, earlier support tickets and backups. Its review lists an action item to back up authorized account contacts outside the product instance. Store phone numbers for the board, counsel, the insurer, law enforcement and top customers on paper or on a separate service.
Name one owned page for every official statement, and tell employees that anything not on that page is not official. IBM's 2026 report found that AI-driven attacks rose 56 percent over the previous year, led by deepfake impersonations and AI-enabled malware. A fake statement in the CEO's name is now a planning scenario, so give reporters and employees one place to confirm what is real. Security teams that want outside help building this kit can start with 5W's cybersecurity PR practice.
Why it works: A fixed page and a fixed spokesperson give every reader one place to verify a claim, which makes a fake statement easy to spot. Atlassian's review recorded that customer escalations arrived by email, phone, social media and support tickets at once, and that scattered tools slowed the response (Atlassian, April 2022).
What should a CISO prepare before a breach happens?
A CISO should prepare six documents before a breach happens, and each one needs a named owner.
- Fact sheet template with a version number and a time stamp on every line.
- Three holding statements: unauthorized access, ransomware and data exposure by a vendor.
- Contact tree stored outside the network, with the shortest notice window at the top.
- Decision log that records who decided what and when.
- Leadership brief template with the four sections above.
- Owned page for updates, built and tested before it is needed.
Run a two-hour tabletop with the CISO, the general counsel, the head of communications and the CEO's chief of staff. Walk through the hour table above and time each block. The exercise fails if any row has no name next to it. For wider planning, my crisis communications guide and the technology companies PR guide cover the surrounding program.
Schedule the tabletop before the next board meeting. The SEC clock, the IBM cost figures and the Uber record point the same way: the first 24 hours cost less to plan than to improvise.
Frequently asked questions
How long does a company have to disclose a data breach?
A public company must file an Item 1.05 Form 8-K within four business days after it determines the incident is material, under the SEC's 2023 rule. Contracts, insurance policies and privacy laws add their own deadlines, so counsel should confirm each one.
Who should approve the first public statement?
The CISO confirms the facts, counsel reviews legal exposure and the CEO or chief communications officer approves the wording.
Should a company confirm a breach before forensics ends?
A company should confirm that an incident occurred and state what is not yet known. It should not estimate the scope or number of people affected until investigators verify it.
Can a CISO face personal legal risk after a breach?
Yes. A federal jury convicted Uber's former chief security officer in October 2022 of obstructing an FTC proceeding and of misprision of a felony in connection with the 2016 breach, according to the Department of Justice.
Published October 2026. General information, not legal advice.
