Stage 1

After a breach, the fix is bigger than the incident

A disclosed breach starts a security program that runs for years. Here's how a services firm reads the signal without chasing the ambulance.

Kevin French
· 3 min read

A breach gets a week of headlines. The program that follows runs for two or three years and carries real budget.

That program is the signal. The incident is how you find out about it.

Why the program is the buy

The incident response is usually handled before you'd ever hear about it. A forensics firm on retainer, outside counsel, the insurer's panel. If you're not already on that list, you're not getting that work, and you shouldn't try.

What comes after is different. The board asks how this happened and what keeps it from happening again. The answer is almost never one tool. It's identity cleanup, logging that actually covers the estate, a segmentation project that's been deferred for years, a vendor risk review, tabletop exercises, new policies that someone has to write and someone has to roll out.

The security team that missed the attack is the same team now running the response. They don't have room for a two-year program on top of it. That gap is where outside services work lives.

Where it shows up

Public companies have to disclose material cyber incidents on an 8-K under Item 1.05, within four business days of deciding the incident is material. Search SEC EDGAR for 8-Ks with that item. I covered the wider list in the 8-K items every services seller should watch.

Follow-up filings matter more than the first one. A company often files an amended 8-K once it knows more, and the next 10-Q or 10-K tends to describe the response. That's where you read about the investment, the new controls, and sometimes the new leadership.

State attorney general breach notification lists and trade press cover private companies. So do the company's own customer notices.

What's strong and what's noise

A first-day disclosure is noise for your purposes. Nobody knows the scope yet, and nobody's buying anything but response.

Language about "improvements to our security program" in a later filing is the strong part. So is a line about engaging third parties to assess controls, a new security committee at the board level, or a disclosed increase in security spend.

A leadership change is the strongest. A new CISO, or a CISO who now reports to the CEO instead of the CIO, means someone has been given a mandate and a deadline. See selling to a CISO for how that seat thinks.

Who carries it

The CISO carries the program, whether they're new or newly under pressure. A new one is building a plan. A sitting one is defending one. Both need help, and they need it to look like progress by the next board meeting.

The CIO owns much of the remediation work, since the systems that need fixing are usually theirs. The general counsel cares about what's disclosed next. The CFO watches the cost and the insurance renewal. The board's audit or risk committee wants a date.

Each one reads your message through a different lens. Sell to the committee, not the contact.

How to reach out without chasing the ambulance

Wait. The first two weeks belong to response. A message in that window reads as opportunism, and it's remembered.

Then lead with the program, not the incident. Never mention the breach in a subject line. Never open with the attacker or the headline. The person reading has lived that story for a month and doesn't need a stranger retelling it.

Say a regional logistics company called Bramwell Freight disclosed an incident in the fall, and its 10-Q this quarter names a new CISO and a multi-year security program.

Bramwell's latest 10-Q describes a multi-year security program, and you're the one building it as the new CISO. The first board update has a date, and the team is still stretched. My guess is the identity work is the piece that has to move first, and it touches more systems than anyone expected. Is that where the pressure is, or is it somewhere else?

The hook is the filing about the program. The trigger is the seat and the board date. The hypothesis names the hard work and invites a correction. The binary exit keeps it a two-second reply.

Nothing in that note mentions the breach. It doesn't have to.

Timing and stacking

The window opens a few weeks after disclosure and stays open for a year or more. The next 10-K is the point where plans tend to become funded line items.

Stack it with a new CISO, security job posts, or a board committee change and you have a funded program with a named owner. That's a reason to reach out this month.

The breach tells you where to look. The program tells you what to say. Lead with what they're building, never with what went wrong.

See which of your accounts are moving.

Stage 1 reads your site, finds accounts that fit and checks their filings and news. Your first Board in about two minutes. Free for 14 days, no credit card.