Reporting Cyber Incidents: When a Non-Event Becomes a Reportable One
The alert lands in the middle of an ordinary afternoon: a phishing email cleared the first filter, someone clicked, and a credential was captured. Within minutes the security stack catches the login, locks the account, and ends the session before anything moves laterally.
The team confirms containment and the cyber threat is gone. Everyone exhales and moves on to the next ticket.
But something is still sitting there. Stopping the attacker settled the security question in those few minutes. Whether anyone is owed a report is a separate question, and it runs on rules most teams don’t check until an alert forces them to.
A cyber incident can be an opportunity for your business, too: The Cyber Incident Near-Miss as a Free Cybersecurity Audit

The Security Question and the Reporting Question
When an incident hits, two clocks start, and they measure different things.
- The security question asks whether the security controls worked. Did detection fire? Did containment hold? Is the threat out?
- The reporting question asks what was exposed. Did an unauthorized party reach protected data or systems? Can you show the extent of it?
Interception answers the first one, but it says nothing definitive about the second.
Access and theft are also separate events. An attacker can touch a system, read a directory, or hold a valid credential for a short window without ever moving data out. Several frameworks start their clock at that point of access or reasonable likelihood of compromise. Waiting for proof of stolen data can mean the reporting window has already been running.
How Security Frameworks Define Incident Response
The specific triggers vary by regime, and a pattern runs through them. Most modern rules key on unauthorized access or a reasonable probability of compromise.
HIPAA Breach Notification Rule
An impermissible use or disclosure of protected health information is presumed to be a data breach unless a documented four-factor risk assessment shows a low probability that the information was compromised. One of those four factors is whether the PHI was acquired or viewed, and a blocked attack does not answer that on its own.
Skip the assessment and the presumption stands, leaving you with both a breach and a failure to notify. Individual notice is due no later than 60 days from discovery.
SEC Cyber Disclosure (Item 1.05)
Public companies must disclose a material cybersecurity incident on Form 8-K within four business days of determining that the incident is material, a deadline tied to the materiality determination rather than to discovery. The SEC has stated that paying the ransom or being reimbursed by insurance does not by itself make an incident immaterial.
DFARS 252.204-7012
Contractors handling covered defense information must report a cyber incident to the DoD within 72 hours of discovery through the DIBNet portal. The window opens when you discover an incident that has occurred or may have occurred, before you confirm it. Federal guidance is explicit that an incident report is not by itself evidence that you failed, which removes the reason many teams stay quiet.
GLBA Safeguards Rule
FTC-regulated firms must notify the FTC within 30 days of a notification event, which is defined as unauthorized acquisition of unencrypted information for 500 or more consumers, with encrypted data counting when the key was also accessed. The FTC standard here turns on acquisition rather than mere viewing, so downloaded or copied data clearly counts while unauthorized viewing is a closer call.
State Breach Notification Laws
Every state has one, and the triggers differ. Kentucky’s breach notification law sets a risk-of-harm threshold: notice is not required if you reasonably believe the incident has not caused and will not cause identity theft or fraud to a resident. That belief is a judgment you have to reach and document, which puts the assessment back at the center.
The Near Miss That Still Counts
Some blocked attacks leave an obligation behind. The block stopped the outcome, but access, even brief, may have already met a trigger.
- Malware quarantined after it had already landed on a server holding regulated records. The tool caught it, and it sat on that system first.
- A harvested credential used to sign in once before the account was locked. The login succeeded, which means something reached what that account could see.
- Ransomware halted partway through encryption, after it had already enumerated file shares. Encryption failed, and the reconnaissance read the layout.
- A misconfiguration flagged and closed after an outside party pulled a directory listing. The exposure window was short, and it was open.
In each case, the security team did its job. Whether sensitive data was accessed still needs an answer, and that answer belongs in a documented assessment.
Do you know your business risk profile? You might be surprised: The Security Gaps Many Businesses Don’t Know They Have
Documentation is What Protects You
After a near-miss, the strongest position is a clear record of what happened and why you concluded what you did. Regulators and insurers rarely penalize a sound assessment; they penalize its absence. Under HIPAA, for example, the point is direct: if OCR asks for your four-factor analysis and you cannot produce it, the presumption reverts to breach.
A defensible record generally includes:
- A timeline with timestamps for detection, access, and containment.
- The scope of systems and data reachable during the window.
- The risk assessment itself, mapped to the framework’s own factors.
- The determination, the reasoning behind it, and who signed off.
- The logs and evidence supporting all of it, retained per the applicable rule.
The record is what turns a decision not to report into a defensible one. Keep it, and a later inquiry finds its answers already prepared.
Cyber Insurance Raises the Stakes
Cyber insurance adds a second set of deadlines to the same event, and they often run shorter and stricter than the regulatory ones.
- Policies carry their own notice conditions. Late notice can reduce a claim or void coverage for it.
- Insurers ask for the same evidence regulators do: the timeline and the assessment behind your call.
- A near-miss closed quietly can resurface. If a related event appears later, “we handled it internally” can become a coverage problem.
The useful part: the discipline that satisfies a regulator also protects the policy. One record serves both readers.
Prepare Your Records Before a Cyber Incident Strikes
The firms that handle this well share one habit: they decide in advance how they would judge and record an event, so the incident response plan runs on a set process when the alert arrives.
That decision is easier to make on a calm afternoon than during an active incident. Making it early is what keeps a stopped attack from becoming an open question months later.
Louisville Geek works as the in-house IT and security partner for regulated organizations. Our work includes mapping your cyber incident response reporting obligations against the frameworks you operate under, and standing up the incident assessment and documentation process that keeps a near-miss defensible.
We’ll help you find where your reporting line sits before an alert asks the question, so you walk into your next risk assessment with the records already in hand.




