Cyber Incident Reporting Duties: Who You May Need to Tell and When

Contracts and regulations can require fast notice of a cyber incident. Learn how to map your reporting duties before an incident forces the question.

3 min readBy Ironfield Cyber Team

When a cyber incident hits, the first hours are consumed by containment and recovery. Reporting obligations can feel like an afterthought, but many of them run on short clocks and are set by contracts, regulations and insurance policies. Missing a deadline can create a second problem on top of the first.

The time to figure out who you must notify is before anything happens. This post outlines the typical categories and how to build a simple reporting map. It is general information, not legal advice. Check with counsel for your specific situation.

Common Sources of Reporting Duties

Government contracts

Contractors that handle covered defense information are subject to DFARS requirements that include rapid reporting of cyber incidents to the Department of Defense, with a 72-hour timeframe from discovery. Contractors also generally need to preserve images and relevant data and may need to provide access for analysis. If you are a subcontractor, you typically must also notify the prime contractor. Check your specific contract clauses, because additional agency requirements may apply.

Prime contractor and customer agreements

Even outside government work, customer contracts commonly include notification clauses. A utility or pipeline operator may require prompt notice if an incident could affect its systems or data. These clauses vary widely in timing and definitions.

Pipeline operators

TSA security directives for designated pipeline owners and operators have included requirements to report certain cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency on short timelines. If you are a designated operator, follow the directive that applies to you. If you are a vendor, expect your customer to require that you notify them quickly.

Electric sector

Entities subject to NERC CIP have incident reporting and response obligations that include identifying reportable incidents and notifying appropriate bodies within defined timeframes. Covered entities should rely on their compliance staff, and vendors should expect to support them.

State laws

Most states have data breach notification laws requiring notice to affected individuals, and sometimes to the state attorney general, when personal information is compromised. Requirements and timelines differ, so a company operating in several states may face multiple rules.

Insurance

Cyber insurance policies typically require prompt notice of incidents and often require using approved response vendors. Failing to follow the policy's process can jeopardize coverage. Know your carrier's reporting contact and hotline.

Law enforcement

Reporting to law enforcement, such as the FBI, is often voluntary but strongly encouraged, especially for fraud and ransomware. For payment fraud, a rapid IC3 report and bank contact can improve the chance of recovering funds.

Employees and other parties

If employee data is affected, you may have duties to notify them. Banks, lenders and bonding companies may also expect to hear about material events under their agreements.

Build a Reporting Map

Create a one-page document with these columns, in plain text or a simple list:

  1. Who: the party to notify.
  2. Trigger: what kind of incident requires notice.
  3. Deadline: the timeframe, and when the clock starts.
  4. Method: the contact, portal or hotline.
  5. Owner: the person at your company responsible for sending it.
  6. Source: the contract clause, law or policy that creates the duty.

Gather the details from your contracts, insurance policy, customer agreements and counsel. Review it annually and whenever you sign a significant new contract.

Define What Counts as an Incident

Sort events into categories, such as suspected, confirmed, and involving personal or controlled information. Different reporting duties kick in at different thresholds. Agree on who decides, usually a designated incident lead with counsel's input, and avoid hesitating because the facts are not complete. Many clauses allow supplemental updates.

Prepare Before Anything Happens

  • Keep contact numbers available offline, since email may be down.
  • Preserve logs and evidence from the start, which you may need to provide.
  • Pre-negotiate with counsel and a response firm if your insurance allows it.
  • Decide who speaks for the company externally.
  • Include reporting steps in your incident response plan and tabletop exercises.

Practice

In a tabletop, ask: ransomware has encrypted a server holding project files. What clocks start? Who calls whom? Which contracts do we need to open? Gaps in the map will show up.

Keep Messages Factual

When you notify others, share verified facts, avoid speculation and keep a log of what was sent and when. Update as you learn more.

Getting Organized

Ironfield Cyber helps contractors and energy companies build reporting maps, update incident response plans and run tabletop exercises with counsel and insurers. If you have never listed your notification duties in one place, that is a good first project.