The Clean OpinionGet your score
Cybersecurity7 min readUpdated 2026-08-26

A breach is now a financial-reporting problem. Here’s what the CFO owns.

Four business days to disclose a material cyber incident, ransomware attacks up sharply in 2026, and regulators treating a breach that touches the books as a control deficiency. The CISO/CFO wall is gone.

Carl GrifkaCISSP, CISA, CISM, PMP · Principal, Alpha Secure LLP

For most of my career, a breach was the CISO’s problem and the CFO found out at the board meeting. That division is over, and the companies still running on it are the ones that get hurt twice — once by the attacker, and once by the disclosure.

Three things converged this year.

1. The four-business-day clock is real, and it is being enforced

Public companies must disclose a material cybersecurity incident on Form 8-K, generally within four business days of determining that the incident is material. The key word is determining. The clock doesn’t start when the attacker gets in; it starts when management concludes the incident is material — and regulators have made clear that the determination itself cannot be unreasonably delayed.

The first year of enforcement showed what that looks like in practice: a dedicated enforcement unit, and actions against companies whose disclosures were late, incomplete, or framed to understate the impact. The materiality determination is a financial-reporting judgment. It belongs to the disclosure committee and the CFO, informed by the security team — not the other way around.

What this means for you: if your incident-response plan does not include a defined path for the materiality determination — who convenes, what information they need, who signs — you do not have an incident-response plan that works for a public company. Tabletop it with the CFO and counsel in the room, not just the security team.

2. Ransomware in 2026: more attacks, fewer payments, more disruption

The first half of 2026 saw victim counts rise sharply over the prior year, while the share of victims paying fell to a historic low. That sounds like good news and partly is. But it changes the nature of the risk: when payment isn’t on the table, the damage is operational and financial — days or weeks of disruption, restoration cost, lost revenue, and, for a public company, the question of whether the books can be closed on time.

Two patterns from this year’s incident reports matter for mid-market companies specifically:

  • Vendor and supply-chain entry. Compromise of a software vendor’s build pipeline, or a widely used component with a remote-code-execution flaw, is now a mainstream initial access route. Your perimeter is your vendors’ perimeter.
  • Automation on the attacker’s side. Model-assisted tooling is shortening the time from initial access to encryption. Detection windows that were adequate two years ago are not adequate now.

What this means for you: the backup and recovery question on our cyber scorecard is not theoretical. Can you restore the general ledger, the billing system, and the identity provider from backups the attacker could not reach, within a time that lets you close the quarter? If you have not tested a full restore in the last year, the honest answer is “we don’t know.”

How would you score today?Ten questions on governance, access, detection, response, and recovery. A score and the gaps an assessor would flag first.
Get your score

3. A breach that touches the books is a control deficiency

Here is the piece that has caught several CFOs off guard. When an incident impairs a system that supports financial reporting — the ERP is encrypted, the billing platform is offline, journal-entry approvals are bypassed during recovery — regulators and auditors are increasingly evaluating that as a deficiency in internal control over financial reporting, not only a security event.

That has consequences:

If the incident…Then…
Impairs a system behind a key controlThe control didn’t operate for that period; the deficiency has to be evaluated for severity
Forces manual workarounds during recoveryThose workarounds are compensating controls and need evidence, precision, and review
Alters or destroys financial data or logsCompleteness and accuracy of the affected period has to be re-established
Is materialIt is disclosed on Form 8-K and considered in the quarterly Section 302 certification and the annual 404(a) assessment

The CISO cannot make those evaluations alone. The controller cannot make them without the CISO. This is why the wall is gone.

What the CFO owns, concretely

  1. The materiality determination process. Written, rehearsed, with named participants and a defined information set. This is a disclosure control.
  2. The link between the IT asset inventory and the financial control matrix. Which systems support which key controls — so that when the security team says “system X is down,” finance immediately knows which controls are affected.
  3. Recovery objectives for financial systems. Recovery time and recovery point objectives for the ledger, sub-ledgers, billing, payroll, and identity — set by finance, delivered by IT, tested at least annually.
  4. Deficiency evaluation after an incident. A standing agenda item in the post-incident review: which controls didn’t operate, for how long, what compensated, and what goes to the audit committee.
  5. Board and audit-committee reporting that ties security to financial risk. Not a slide of vulnerability counts — a statement of which financial processes are exposed, what the recovery posture is, and what has changed since last quarter.

The uncomfortable summary

Surveys this year show most CISOs are worried about personal liability and a large share can’t tie their spending to risk reduction. The way through both is the same: treat cybersecurity as part of the financial control environment, evaluated with the same discipline, evidenced the same way, and reported to the same committee. It is more work for the CFO. It is also the only structure in which a breach is a bad week rather than a restatement.