CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◍ Incident Response & DFIR Aug 09, 2026

5 CISO principles for navigating cybersecurity incident disclosure - InformationWeek

InformationWeek Archived Aug 09, 2026 ✓ Full text saved

5 CISO principles for navigating cybersecurity incident disclosure InformationWeek

Full text archived locally
✦ AI Summary · Claude Sonnet


    INCIDENT RESPONSE CYBER RESILIENCE CYBERSECURITY IT STRATEGY COMMENTARY 5 CISO principles for navigating cybersecurity incident disclosure Don't wait until you're in a cyber event to figure out a customer notification plan. Zscaler's CISO explains how to establish triggers and protocols before crises force decisions. Sam Curry,Zscaler August 6, 2026 3 Min Read GETTY IMAGES If you've been a CISO long enough, you've probably learned the same lesson I have: The hardest part of incident response often isn't detection, containment or eradication. It's deciding when and how to tell customers what's going on, especially when the facts are still emerging. Disclose a cybersecurity incident too early, and you risk being wrong, creating unnecessary disruption or boxing your legal team into a corner. Disclose too late, and you may deprive customers of the time and information they need to protect themselves and meet their own disclosure obligations. The worst time to create your notification philosophy is during an incident, when certainty doesn't exist. This work should be done in advance, in collaboration with key stakeholders across the leadership team. Context shapes incident disclosure decisions Your priorities will not be the same as mine. At Zscaler, we process roughly 500 billion transactions a day to block attacks and enforce our customers' policies. We don't store customers' content as many platforms do, but we do handle sensitive data and operational signals to deliver the service. That shapes how I think about when and how to communicate during a cyber event. Related:AI disaster recovery planning is years behind AI adoption Your reality is likely to be different: the data you hold, the promises you've made to customers and third parties, your jurisdictions, your industry, your business model, your size and maturity, and whether you're public or private. That all shapes decisions about when you notify customers, what you can say and what you must say. But here are three broad priority truths I think most CISOs recognize, even if we don't always say them out loud: Human safety comes first. Law comes before contract. Protecting customers comes before protecting shareholder value. Five CISO principles for incident disclosure We should move away from asking whether we notify, and instead ask what customers need to do their job. In the first 24 to 72 hours of an incident, you may have hypotheses, partial telemetry and a messy timeline, but you will rarely have a clean story. Meanwhile, your customer is probably running their own war room, trying to answer questions like: Do we need to take action right now? Are we at risk? What can I credibly tell my CEO, board or regulators? Customers understand you can't speak with absolute certainty, but they do need quality information they can act on. With this context in mind, I'll share five CISO-to-CISO principles for deciding when (and how) to tell customers: Make decisions in peacetime. Agree ahead of time on triggers, decision rights, escalation paths and who can send customer communications. If you don't, your priority order becomes whatever is loudest in the room when pressure spikes. Let harm reduction — not a narrative — drive timing. Don't wait for perfect attribution or root cause. If customers can materially reduce risk by acting, timeliness beats a polished story. That action might include patching, changing credentials, monitoring for indicators, or temporarily changing how they use your service. Treat legal reality as a forcing function. This is where "law before contract" becomes practical. Regulatory and cross-border obligations can force earlier decisions than the business would naturally choose. Bring legal in from the start, not as a brakes-only function, but as a partner in accurate, defensible, useful communication. Don't make the customer's trade-offs for them. Customers optimize for different missions. Response options can create real customer impact, including forcing resets, disabling integrations, shutting down features, or rotating keys. So, give them decision-quality information and let them choose in their own context. Be disciplined and humane, and build a cadence. Overconfident sentences cause irreversible damage. Lead with tight facts, clear caveats, specific actions, and predictable updates. Always pair professionalism with empathy; it reduces confusion, escalation, and mistrust. Related:Why disaster recovery plans fail in geopolitical crises Why this matters beyond cybersecurity As CISOs, incident notification is governance under time pressure. You can't expect great outcomes if you haven't done the alignment work early, including priorities, thresholds, decision rights, escalation paths and rehearsal. Related:How CIOs can build an evolving crisis strategy The fog of battle is guaranteed. The only question is whether you walk into it with a shared operating model across security, legal, comms and business leaders, or try to invent a model while the incident is already unfolding. What's your customer notification strategy during incidents? Share it with editors@informationweek.com. About the Author Sam Curry Zscaler Sam Curry is chief information security officer (CISO) at Zscaler and a fellow at the National Security Institute. Prior to joining Zscaler, Sam was chief security officer and chief product officer at Cybereason, CTO and CSO at Arbor, CISO at MicroStrategy and an executive at McAfee and CA. He spent seven years at RSA as general manager, CTO, head of RSA Labs (MIT) and senior vice president of product. With dozens of patents, he teaches at the Wentworth Institute of Technology and Nichols College. He is a board member of the Cybersecurity Coalition and CyberTrust Massachusetts, with degrees in physics, English, philosophy and counterterrorism. Want more InformationWeek stories in your Google search results? ADD US NOW Editor's Choice AI INNOVATIONS The real heat behind OpenAI's new Jalapeño chip CYBERSECURITY Poor UX undermines security policies, says Texas A&M University System CIO CLOUD OUTAGES, CYBERSECURITY, AGENTIC AI & FEDERAL POLICY GET AWARD-WORTHY INSIGHTS Want more InformationWeek stories in your Google search results? Get a snapshot of the issues affecting CIOs, three times a week in your inbox. Subscribe to our newsletters today. SIGN UP
    💬 Team Notes
    Article Info
    Source
    InformationWeek
    Category
    ◍ Incident Response & DFIR
    Published
    Aug 09, 2026
    Archived
    Aug 09, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗