Chapter 8 of 8
Governance and the Defender Action Plan
Executives, security teams, product owners, legal counsel, and compliance functions must now make decisions from the same rapidly changing evidence. A practical operating model connects technical exposure with accountability, regulatory reporting, and investment priorities.
1. Start with One Operating Picture
From findings to decisions
A vulnerability programme needs more than scanners and tickets. It needs one evidence-based picture that connects technical exposure, business consequence, accountable owners, and disclosure decisions.
The shared record
Connect each important finding to the affected asset, owner, exploit evidence, customer or revenue impact, mitigation status, and the decision record.
Avoid the CVSS-only trap
A CVSS score describes technical characteristics. Prioritization also needs exploit evidence, exposure, asset criticality, compensating controls, and likely business impact.
2. Separate Vulnerability Disclosure from Incident Disclosure
Vulnerability disclosure
A vulnerability disclosure policy governs how researchers report weaknesses and how the organization validates, fixes, coordinates, and may publish those findings.
Incident disclosure
A material incident disclosure concerns investor-relevant impact. For covered U.S. registrants, the SEC clock begins after a materiality determination, not at discovery.
Use separate workflows
Link the workflows through shared evidence, but do not collapse them. A vulnerability report, exploitation event, and material incident are related but distinct concepts.
3. Example: One Exploited Vulnerability, Three Decisions
The trigger
An internet-facing API gateway appears in the KEV Catalog. Eighteen production instances are affected, and exploit attempts appear in logs.
Operational decision
Security and engineering reduce exposure now: isolate, mitigate, patch safely, and verify. Product and supplier teams coordinate customer impact and vendor action.
Disclosure decision
KEV status proves urgency, not materiality. Legal evaluates incident facts and business impact; leaders retain evidence for the decision and reassess as facts change.
4. Thought Exercise: Build the Escalation Path
Map the First 24 Hours
Use the Gateway Flaw scenario. Draft a simple escalation path for the first 24 hours.
Your task
Assign a primary decision owner for each question:
- Is the asset genuinely affected, reachable, and production-critical?
- Is there confirmed exploitation, data access, or operational disruption?
- Can the service be isolated or patched without unacceptable customer harm?
- Does the event trigger contractual, regulatory, privacy, or securities-disclosure review?
- Who can authorize emergency change, risk acceptance, customer communication, and public disclosure?
Compare your answer to this operating model
- Security operations: validates technical exposure and threat evidence.
- Service or product owner: establishes business criticality and customer impact.
- Engineering or platform owner: chooses and verifies remediation.
- Legal and compliance: interpret reporting, contract, and disclosure duties.
- Executive incident sponsor: resolves trade-offs, accepts exceptional risk, and ensures resources.
- Corporate communications and investor relations: prepare approved communications only after legal and executive review.
Design rule
Create a named backup for every role. A governance process that depends on one unavailable executive, lawyer, or service owner will fail at the moment it is needed.
Deliverable: Write a one-sentence escalation trigger, such as: `Escalate to the incident sponsor and legal when active exploitation affects a critical service, sensitive data, or a revenue-generating workflow.`
5. Prioritize with KEV, NIST Data, and Local Context
KEV is an urgency signal
CISA KEV identifies vulnerabilities with evidence of exploitation in the wild. Treat it as a powerful prioritization input, especially for reachable and business-critical assets.
NVD data is evolving
NIST moved to risk-based NVD enrichment in April 2026. Some lower-priority CVEs may remain listed without immediate enrichment, so missing details are not a safety signal.
Local evidence decides
Prioritize using reachability, asset criticality, exploit path, controls, fix availability, and blast radius. External scores and catalogs cannot replace local context.
6. Checkpoint: What Starts the SEC Clock?
Choose the best answer
A U.S. domestic SEC registrant discovers ransomware at 9:00 a.m. Monday. After investigation and legal review, it determines at 3:00 p.m. Thursday that the incident is material.
When does the Item 1.05 four-business-day filing period begin?
When does the SEC Item 1.05 filing period begin?
- At 9:00 a.m. Monday, when the ransomware was discovered.
- At 3:00 p.m. Thursday, when the company determined the incident was material.
- When the investigation is fully complete.
- Only after law enforcement confirms the attacker.
Show Answer
Answer: B) At 3:00 p.m. Thursday, when the company determined the incident was material.
For a domestic registrant, the Item 1.05 deadline is four business days after determining that the cybersecurity incident is material. The materiality determination must be made without unreasonable delay; waiting for every technical detail is not the standard.
7. Prepare for the EU Cyber Resilience Act
Use the current instrument
The Cyber Resilience Act is Regulation (EU) 2024/2847. Its reporting obligations apply from September 11, 2026, before the regulation's broader application date.
The CRA timeline
For qualifying events: early warning in 24 hours, notification in 72 hours, then a final report within the applicable vulnerability or incident timeline.
Prepare the workflow now
Map product manufacturers, EU establishment, reporting authority, approval roles, event criteria, and evidence retention. CRA reporting and SEC disclosure require separate analyses.
8. Create an Audit-Ready Evidence Trail
Evidence answers four questions
An audit-ready packet explains what the organization knew, when it knew it, who made each decision, and how it verified the result.
Capture decision-grade facts
Keep technical scope, threat evidence, business context, action records, legal assessment, approved communications, and residual-risk decisions together.
Record uncertainty
Do not manufacture certainty during an investigation. Record what is unknown, the current working assessment, the owner, and the next reassessment time.
9. Build Your 90-Day Defender Action Plan
A Practical 90-Day Plan
Create a plan that produces visible control improvements rather than a long list of aspirations.
Days 1-30: Establish control and ownership
- Publish a RACI for vulnerability, incident, disclosure, and supplier decisions.
- Define escalation triggers for KEV findings, internet-exposed critical assets, suspected exploitation, and severe product-security events.
- Create a single evidence-packet template and a decision-log standard.
- Inventory critical assets, product components, suppliers, and accountable business owners.
Days 31-60: Improve prioritization and delivery capacity
- Add KEV, reachability, asset criticality, exploit telemetry, and compensating controls to triage.
- Measure remediation capacity by team: patch throughput, emergency-change lead time, failed deployment rate, and verification coverage.
- Establish supplier SLAs for vulnerability acknowledgment, mitigation, patch availability, and evidence of completion.
- Test a deployment-ring approach for a high-risk patch.
Days 61-90: Prove disclosure readiness
- Run a tabletop exercise involving security, engineering, legal, compliance, product, executive leadership, and communications.
- Practice an SEC materiality-assessment handoff if the organization is a covered registrant.
- If the organization manufactures products with digital elements for the EU market, rehearse the CRA 24-hour and 72-hour reporting workflow before September 11, 2026.
- Present the board or executive sponsor with metrics, unresolved risks, resource constraints, and next-quarter commitments.
Success measures
- Percentage of KEV findings with an owner and decision within the target window.
- Median time from validated critical exposure to verified mitigation.
- Percentage of critical assets with accurate owners and reachability data.
- Percentage of supplier-critical findings with documented response evidence.
- Time required to assemble a decision packet and disclosure assessment.
Your task: Select one metric for each of these areas: governance, prioritization, remediation capacity, supplier coordination, evidence retention, and disclosure readiness.
10. Key Terms Review
Flip the cards to review the governance vocabulary.
- CISA KEV Catalog
- CISA's catalog of vulnerabilities known to be exploited in the wild. It is a high-value prioritization input, not a complete risk score.
- Materiality
- For SEC purposes, an investor-focused assessment of whether there is a substantial likelihood that a reasonable shareholder would consider information important.
- SEC Form 8-K Item 1.05
- For covered U.S. domestic registrants, the current-report item for a material cybersecurity incident, filed within four business days after the materiality determination.
- CRA reporting
- From September 11, 2026, manufacturers report qualifying actively exploited vulnerabilities and severe incidents affecting products with digital elements through the CRA reporting process.
- Compensating control
- A temporary or alternative safeguard that reduces risk when the preferred remediation, such as a patch, cannot yet be deployed.
- Decision packet
- A retained evidence set showing technical facts, business context, decisions, actions, approvals, verification, and disclosure analysis.
Key Terms
- CVE
- Common Vulnerabilities and Exposures: an identifier for a publicly known cybersecurity vulnerability.
- NVD
- National Vulnerability Database, maintained by NIST as a repository of vulnerability information.
- RACI
- A responsibility model identifying who is Responsible, Accountable, Consulted, and Informed.
- SSVC
- Stakeholder-Specific Vulnerability Categorization, a decision model that helps organizations prioritize vulnerability response using stakeholder context.
- CISA KEV
- The U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities Catalog.
- Decision packet
- A consolidated evidence record supporting risk, remediation, escalation, and disclosure decisions.
- Compensating control
- A safeguard that reduces exposure when a permanent fix cannot yet be applied.
- Product with digital elements
- A product category covered by the EU Cyber Resilience Act, subject to its applicable cybersecurity requirements.
- Material cybersecurity incident
- For SEC disclosure analysis, a cybersecurity incident whose actual or reasonably likely impact is material to investors.
- Actively exploited vulnerability
- A vulnerability for which there is reliable evidence that a malicious actor has exploited it.