When a cyber incident hits, the technical response competes with a second problem: deciding who must be told, by when, and how. Reporting duties are often tucked into contracts and regulations that nobody has reread since signing. Discovering them in the middle of a crisis is stressful and can lead to missed deadlines.
This article gives a general orientation to common reporting obligations for defense subcontractors and energy operators. It is not legal advice. Confirm your specific obligations with counsel and the contracts and regulations that apply to you.
Defense Contractors and DFARS
Contractors that handle covered defense information generally fall under the DFARS cyber incident reporting clause. In broad terms, it expects contractors to rapidly report cyber incidents that affect covered defense information or the contractor's ability to perform operationally critical support, and to preserve images and relevant data for a defined period so investigators can examine them.
Practical points to prepare:
- Know whether your contracts include the clause and whether you handle covered information
- Understand that the clock is short, measured in days rather than weeks, and confirm the exact timeframe in your contract language
- Be aware that reporting generally goes through a designated government portal and that you may need a specific type of credential to use it, which is much easier to obtain before an incident
- Understand your obligations to notify the prime contractor or higher-tier contractor when you are a subcontractor, since flow-down clauses often impose their own timelines
- Preserve evidence: images of affected systems, relevant logs, and malicious software, if found
With CMMC 2.0 now phasing into contracts, incident response and reporting also feature in the underlying NIST SP 800-171 requirements, so your documented plan should reflect them.
Energy and Utility Operators
Entities subject to NERC CIP standards have requirements around identifying, classifying, and reporting cyber security incidents, including defined processes and notification to designated bodies. The specific thresholds and timelines depend on the entity's classification and the applicable standards, so rely on your compliance team's reading of the current requirements.
Pipeline Operators
Pipeline owners and operators covered by TSA security directives have been required to report certain cybersecurity incidents to CISA within a short window. If you are in scope, confirm the current directive language and your designated contact, and make sure someone is assigned to submit reports.
Other Common Obligations
Beyond sector rules, think about:
- State data breach notification laws, which may apply if personal information of employees or customers is involved
- Contract clauses with owners, primes, or customers requiring notice of security events
- Cyber insurance policies, which often require prompt notice and may limit which responders or vendors you can use, so read yours before an incident
- Lender or surety agreements that include covenants about material events
- Law enforcement, where reporting a crime to the FBI or its Internet Crime Complaint Center is often recommended, particularly for payment fraud, since early reporting can improve the chance of recovering funds
Build a Notification Matrix Now
Create a one-page matrix listing, for each audience:
- Who must be notified and what triggers the duty
- The deadline or expected timeframe
- The method or portal
- The internal owner responsible for notifying
- Contact details that work if email is down
Store a copy offline. Have counsel review it.
Pre-Stage the Practical Pieces
- Obtain any required credentials for government reporting portals in advance
- Identify a forensic and legal resource, ideally through your insurer's panel
- Define who decides that an event qualifies as a reportable incident
- Establish a template for initial notices that states known facts and avoids speculation
- Practice the process in a tabletop exercise
Be Careful With Communication
Stick to facts. Do not guess at causes or scope in early notices, and update as you learn more. Route external statements through a designated person. Keep a log of who was told what and when.
Review Annually
Obligations change with new contracts, rule updates, and corporate structure. Review the matrix at least yearly and whenever you sign a contract with new security terms.
Ironfield Cyber helps contractors and operators build incident response plans and notification matrices, and run tabletop exercises that test them. If you would like help mapping your duties, we can work with your counsel to put it on one page.