For a NYSE-listed company, a ransomware negotiation and a disclosure decision are separate workstreams. Paying, restoring systems, or recovering data does not by itself resolve whether an incident is material or remove an SEC filing obligation. The company should activate its response plan, preserve evidence, involve the right stakeholders, and assess SEC and NYSE requirements on their own terms.
What should a company do first during a ransomware incident?
Treat negotiation as one part of incident response—not as a substitute for containment, recovery planning, or disclosure analysis. The joint CISA, MS-ISAC, NSA, and FBI #StopRansomware Guide, revised October 19, 2023, recommends a planned, coordinated response and reporting to appropriate authorities.
- Activate the incident response and communications plans. Bring together security and incident-response leads, executives, legal, communications, and other stakeholders needed to assess business and customer impact. Involve the company’s insurer and qualified external incident-response support where appropriate.
- Preserve evidence promptly. Retain volatile evidence and system artifacts relevant to the intrusion, encryption, and any data-access or publication claims. Coordinate evidence collection with incident responders and counsel so recovery actions do not unnecessarily destroy information needed to understand the event.
- Report and seek assistance. The federal guide recommends reporting to CISA, the FBI, or other relevant authorities. Consult law enforcement: decryptors may be available for some ransomware variants, and responders can help evaluate recovery options.
- Assess the available paths before deciding about payment. Consider backup and restoration prospects, the possibility of continued compromise or data publication, business and customer effects, and legal and disclosure consequences. The cited federal guidance strongly discourages paying: payment does not guarantee recovery and may embolden attackers or fund illicit activity.
- Keep the disclosure assessment moving in parallel. Do not wait for negotiations, restoration, or a final accounting of every technical detail before beginning the materiality analysis.
These sources do not establish a reliable bargaining script, a recovery rate, or that an attacker will honor an agreement. A payment decision is therefore not a dependable promise of decryption, data deletion, or silence.
Does paying a ransom affect SEC disclosure?
For a domestic SEC registrant, the relevant current-report provision is Form 8-K Item 1.05. The SEC’s Small Entity Compliance Guide, dated August 30, 2023, says the filing is due within four business days after the company determines that a cybersecurity incident is material. The clock runs from that determination, not automatically from the attack’s discovery. The company may not unreasonably delay making the determination.
#1 Best Overall
SEC staff’s ransomware-specific Form 8-K interpretations address the effect of payment and apparent recovery:
- Payment before the materiality decision: If the company pays and disruption ends or data is returned before it determines materiality, it still must make that determination. Apparent resolution alone is not a basis for finding the incident immaterial (SEC interpretation Q104B.05).
- Payment or restoration after a materiality decision: If the company determines the incident is material, later payment or restoration does not eliminate the Item 1.05 filing obligation within four business days of that determination (Q104B.06).
- Insurance reimbursement: Reimbursement of all or a substantial part of a ransom does not necessarily make the incident immaterial. The SEC staff says to consider relevant quantitative and qualitative effects, including longer-term impacts (Q104B.07).
- Payment amount and related events: Payment size alone does not decide materiality. Depending on the facts, related incidents may need to be assessed together (Q104B.08–Q104B.09).
The SEC adopted its cybersecurity disclosure rules on July 26, 2023; they became effective September 5, 2023. The rules also require annual disclosures about cybersecurity risk management, strategy, and governance. SEC Chair Gary Gensler said on July 26, 2023: “Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors.”
Item 1.05 does not require technical detail about planned response, systems, networks, or vulnerabilities at a level that would impede response or remediation. That limit is not a blanket exemption from disclosing material information.
How are SEC disclosure and NYSE material-news coordination different?
They are separate processes with different purposes. SEC analysis asks whether an incident is material to investors and whether a filing is required. NYSE Regulation’s Market Watch and Corporate Actions group enforces the Exchange’s Timely Alert Policy, monitors listed issuers’ material-news obligations, and can implement regulatory trading halts. The exchange role does not replace the company’s SEC analysis.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →| Process | What it addresses | What the company should do |
|---|---|---|
| SEC Form 8-K Item 1.05 | Current disclosure of a material cybersecurity incident by a domestic registrant; the filing deadline is tied to the materiality determination. | Assess materiality without unreasonable delay and track the four-business-day filing period after the determination. |
| NYSE Timely Alert Policy / Market Watch | Exchange oversight of listed issuers’ material-news disclosure obligations, including potential trading-halt activity. | When material news is involved, coordinate with NYSE Market Watch under the current rules and procedures applicable to the issuer and event. |
The NYSE source establishes the exchange’s oversight role; it does not establish that every ransomware incident automatically triggers a particular exchange notification. Check the applicable Listed Company Manual and current Market Watch procedure against the company’s facts.
Can a company delay disclosure while it negotiates or restores systems?
Negotiations, restoration work, or consultation with law enforcement do not by themselves authorize a company to pause an SEC deadline. SEC interpretations say a company may consult DOJ, the FBI, CISA, or other agencies at any point, including before completing its materiality assessment.
Rank #4
The FBI describes a narrow, agency-mediated process for requesting a delay when disclosure poses a substantial risk to national security or public safety. It is not a general negotiation tactic or a unilateral pause the company can invoke because negotiations or recovery are underway. A company considering the process should use the FBI’s SEC reporting guidance and obtain company-specific legal advice.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should executives and counsel keep aligned?
Use one coordinated response process, while keeping the legal questions distinct. The CISA-led guide recommends accurate, coordinated communications and involvement of appropriate internal and external stakeholders. For an NYSE-listed issuer, the working group should align operational facts and timing across response leadership, counsel, communications, and investor relations; then address the SEC filing analysis and exchange coordination through their respective channels.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- Track what is known, what remains unverified, and how the incident is affecting operations, customers, data, and longer-term business prospects.
- Record when the company assesses materiality and the basis for that assessment, so the Item 1.05 deadline can be calculated from the actual determination.
- Do not equate ransom size, insurance reimbursement, restoration, or an attacker’s promise with the materiality conclusion.
- Ask counsel to assess company-specific disclosure and payment constraints. The cited sources do not establish sanctions-specific rules or determine whether a particular payment is lawful.
For foreign private issuers, do not apply the domestic registrant’s Form 8-K deadline indiscriminately: the SEC compliance guide describes a different Form 6-K framework.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




