The Clock Nobody Planned For

Hillstrong Group Security ·

Author: Roger Hill

Four business days…

That is the window the SEC gives a publicly traded company to file a Form 8-K under Item 1.05 after determining that a cybersecurity incident is material. Four business days to describe the nature, scope, timing, and material impact of the event. Four business days to tell the investing public what happened, what it means, and what it might cost.

For IT incidents, this is tight but workable. A ransomware attack encrypts your ERP system. Your IR team images servers, scopes the breach, and your legal counsel runs the materiality analysis. The damage is measurable in familiar units: records compromised, systems offline, recovery cost estimates. You file. You amend later if needed.

Now move that scenario to the plant floor.

A threat actor compromises a programmable logic controller managing a chemical batch process. The PLC sends incorrect temperature setpoints to a reactor vessel’s control loop. Before operators catch the deviation, the process exceeds safe parameters. Production shuts down. A pressure relief valve actuates, releasing regulated compounds. Three workers are evacuated from the affected unit. The environmental response team is mobilized. Your safety investigation launches in parallel with your cyber investigation. OSHA wants to know what happened. Your state environmental agency wants air monitoring data.

And somewhere in the corporate office, your disclosure committee is asking: “Is this material?”

The honest answer, in most manufacturing organizations today, is that nobody in that room has a framework for answering that question when the incident is physical, operational, safety-related, environmental, and financial all at once.

This is the first article in a five-part series called “The Disclosure Trap: Why SEC Cyber Rules Will Break Manufacturing First.” My thesis is straightforward: most manufacturers will fail their first material OT incident disclosure. Not because of the incident itself, but because they built their entire disclosure apparatus around a type of cyber event that looks nothing like what actually happens when operational technology is compromised.

Why This Matters Now

The SEC’s cybersecurity disclosure rules took effect on December 18, 2023. In the first full year, roughly 55 cybersecurity incidents were reported on Form 8-K across all industries. Of those, about 51% were filed under the mandatory Item 1.05, with the remainder filed voluntarily under Items 8.01 or 7.01.

Here is what is striking about those filings: virtually all of them describe IT-centric incidents. Data exfiltration. Ransomware on business systems. Unauthorized access to customer databases. The materiality analysis in every case I have reviewed centers on data loss, business interruption to IT systems, and estimated remediation costs.

None of them describe what happens when a cyberattack hits a physical process.

That is not because OT incidents do not happen. Manufacturing has been the number one target for ransomware for four consecutive years, with a 355% increase in ransomware targeting the sector. ICS vulnerabilities doubled in 2025, with 2,451 new vulnerabilities disclosed across 152 vendors. State-sponsored actors are increasingly targeting operational technology directly, not just pivoting from IT.

The reason OT incidents have not shown up in Form 8-K filings is simpler and more concerning: most manufacturers do not yet have a process for connecting an OT cyber event to a materiality determination. The people who understand the plant floor impact are not in the room with the disclosure committee. The people running the materiality analysis do not understand what a compromised PLC actually does to a production process.

That disconnect is going to cost someone a lot of money and credibility when it finally breaks into the open.

The Materiality Problem, Broken Apart

The SEC defines materiality using the standard established in TSC Industries v. Northway (1976): information is material if there is a “substantial likelihood that a reasonable shareholder would consider it important” in making an investment decision. The Commission has explicitly stated that materiality assessments for cybersecurity incidents should not be limited to financial condition and results of operation, and that companies “should consider qualitative factors alongside quantitative factors.”

That guidance sounds reasonable until you try to apply it to an OT incident.

Consider the dimensions of impact when operational technology is compromised:

Production Impact

A compromised PLC or DCS can halt a production line, a batch process, or an entire facility. The financial impact depends on what was being produced, the contractual obligations tied to that production, the cost of restarting (which in continuous processes can take days or weeks), and the downstream supply chain effects. Estimating this within four days of the materiality determination requires production economics data that most disclosure committees have never seen.

Safety Impact

OT incidents can injure or kill people. A manipulated safety instrumented system (SIS) can fail to prevent a dangerous condition. An altered setpoint can cause an overpressure, thermal runaway, or mechanical failure. The safety impact of an OT cyber event is not a theoretical risk. It is the reason these systems exist in the first place. How do you quantify the materiality of a near-miss that could have resulted in fatalities? The SEC’s guidance says to consider qualitative factors. A worker evacuation is qualitative until someone gets hurt, and then it is the only thing anyone cares about.

Environmental Impact

Process disruptions caused by cyber events can lead to uncontrolled releases of regulated substances. Those releases trigger EPA reporting obligations, potential consent decrees, remediation costs, and community impact. Environmental liability from a single release event can dwarf the cost of the cyber incident that caused it. But the environmental investigation timeline operates on a completely different clock than the SEC’s four-day window.

Regulatory Cascade

An OT cyber incident that causes a safety event triggers OSHA investigation. An environmental release triggers EPA or state agency involvement. If the facility handles certain chemicals, the Chemical Safety Board may get involved. Each of these regulatory processes has its own timeline, its own reporting requirements, and its own definition of what matters. The SEC disclosure sits on top of all of this, requiring a materiality determination while the other investigations are still in their earliest stages.

Insurance and Liability

The SEC has specifically stated that insurance coverage does not negate materiality. If your cyber insurance policy reimburses a ransomware payment, the incident can still be material. In OT, the insurance picture is even more complex. Cyber insurance, property insurance, general liability, environmental liability, and workers’ compensation may all be triggered by a single event. The coverage analysis alone can take weeks.

Now stack all five of these dimensions on top of each other. That is what a materiality determination looks like for a manufacturing OT incident. And the people currently responsible for making that determination at most publicly traded manufacturers have never thought about any of this.

What Most Companies Get Wrong

The most common mistake I see is treating OT cybersecurity materiality as an extension of IT cybersecurity materiality. Companies that have done good work building materiality frameworks for IT incidents assume those frameworks stretch to cover OT. They do not.

Here is why:

IT materiality frameworks center on data. How many records were exposed? What type of data? Was it encrypted? These are answerable questions with relatively well-understood cost models (per-record breach cost estimates, notification costs, regulatory fine ranges). OT incidents rarely involve data exposure. The damage is physical, and the cost models for physical damage from cyber events barely exist.

IT materiality frameworks assume rapid forensic capability. You can image a server in hours. You can pull logs from a SIEM in minutes. You can scope an IT breach within days in most cases. You cannot image a running PLC. Many industrial controllers do not produce forensic-grade logs. The OT environment may need to keep running during the investigation because shutting it down safely requires the same expertise as starting it up, and that expertise may be exactly what is compromised. Forensic timelines for OT incidents stretch into weeks or months.

IT materiality frameworks assume the impact is contained to information systems. The SEC’s definition of “information systems” does include infrastructure controlled by information resources, which would encompass OT. But the practical frameworks companies have built focus on business process interruption, not physical process disruption. The difference is not semantic. When your email system goes down, people find workarounds. When your reactor control system is compromised, you evacuate the building.

Nobody has stress-tested these frameworks. Nearly 40% of companies surveyed identified materiality determination as the most challenging element of the SEC’s new rules, even for straightforward IT incidents. Add the multi-dimensional complexity of OT, and you have a process that will collapse under the weight of its first real test.

A Different Way to Think About This

The manufacturers who will navigate this successfully are not going to do it by extending their IT materiality playbook. They are going to need a fundamentally different approach.

First, the disclosure committee needs OT literacy. Not deep technical knowledge, but enough operational context to understand what it means when someone says “the PLC controlling Line 3 was compromised.” They need to know what Line 3 produces, what the safety implications are, what the environmental permits require, and what the production loss costs per hour. This is not information you gather during an incident. This is information you build into your disclosure readiness program before the incident happens.

Second, the materiality framework needs to be multi-dimensional from the start. Production impact, safety impact, environmental impact, regulatory cascade, and insurance/liability exposure need to be scored independently and then aggregated. A single-axis materiality test (“did we lose data?”) is useless for OT.

Third, the bridge between the incident response team and the disclosure committee needs to be engineered, not improvised. In most manufacturers, the people who understand the plant floor and the people who file 8-Ks have never been in the same room. That has to change before the incident, not during it.

Fourth, the four-day clock needs to be understood for what it actually is. The SEC requires filing within four business days of the materiality determination, not four days after the incident. Companies have some control over when the determination is made, but the SEC has also said the determination must be made “without undue delay.” Deliberately slow-walking a materiality determination is not a strategy. It is a liability.

What You Can Do This Quarter

  1. Audit your current materiality framework for OT blind spots. Pull the framework your disclosure committee uses today. Ask a single question: does this framework account for an incident where the primary impact is physical process disruption, not data loss? If the answer is no, you have a gap that needs to close before your next annual risk factor disclosure.
  2. Map your top five OT assets to materiality dimensions. Pick the five most critical production processes in your organization. For each one, document what happens if control is lost: production cost per hour, safety implications, environmental release potential, regulatory notification triggers, and insurance coverage gaps. This exercise alone will change how your disclosure committee thinks about OT risk.
  3. Run a tabletop exercise with your disclosure committee and your OT team in the same room. Give them a realistic OT incident scenario and ask them to walk through the materiality determination process. I have never seen this exercise fail to reveal fundamental gaps in preparedness.
  4. Review your 10-K cybersecurity risk factor disclosure. Does it accurately describe the risk profile of your OT environment? Or does it use generic IT language that would leave a reasonable investor with no understanding of your actual exposure? We will dig into this in next week’s article.
  5. Designate an OT liaison to your disclosure committee. This does not need to be a permanent seat. But someone with operational technology context needs to be reachable within hours, not days, when a cyber event touches the plant floor.

What Comes Next

This is the first article in a five-part series examining how SEC cybersecurity disclosure rules intersect with the reality of manufacturing OT environments. Next week, we will look at what your 10-K annual risk factor disclosures are missing when it comes to OT, and what regulators are starting to notice.

The companies that figure this out early will not just avoid regulatory problems. They will build a disclosure capability that becomes a genuine strategic advantage. The ones that wait will learn the hard way that a four-day clock runs faster than anyone expects when the plant floor is involved.

Thank you for reading! What is your experience? Has your organization ever tried to run a materiality determination for an OT-related cyber event? What fell apart first? We want to hear from people who have been in that room.

Connect with the Author: https://www.linkedin.com/in/rogerlhill

Want this as a playbook?

Every guide we publish has a companion eBook with templates you can use today.