UK issuers must evaluate if cyber incidents are inside information
When a cyber incident occurs, UK issuers face immediate regulatory pressure under the UK Market Abuse Regulation to determine if the breach constitutes inside information.
Is every cyber incident automatically inside information under UK market rules?
Not every cyber attack or network compromise meets the threshold for inside information. Issuers must evaluate each event on its specific facts starting from the moment of initial awareness. Under Article 7 of the UK Market Abuse Regulation (MAR), inside information requires precise data relating directly or indirectly to the issuer which has not been made public and would likely affect share prices significantly if disclosed.
Precision does not require complete understanding of an incident’s full consequences. Early indicators that core systems are compromised can be specific enough to allow market conclusions.
When must an issuer issue a holding announcement or delay disclosure?
Issuers are permitted a brief window to clarify operational realities before making mandatory market disclosures. If details threaten to leak prematurely before facts are confirmed, companies may require a holding announcement. This is particularly critical for retailers whose online payment channels face sudden disruption.
Under Article 17(4) of MAR, delaying disclosure remains permissible only if immediate release prejudices a legitimate interest, the public is not misled, and confidentiality is maintained. For instance, ongoing negotiations with a digital extortionist might justify a temporary delay. However, attackers often possess the exact same data sets and may publicize the breach independently. Threat intelligence firms help corporate boards evaluate whether a threat actor operates like a publicity-seeking hacktivist or a quiet intelligence-gathering nation state.
What triggers subsequent disclosures as a cyber incident develops?
Corporate disclosure obligations do not end when containment protocols finish. Issuers must continuously monitor evolving operational impacts, duration estimates, and reputational damage. Material financial costs often emerge long after initial containment, including expensive system remediation, heightened protection overhead, or required revisions to published financial targets.
Extended unavailability of critical infrastructure can severely depress quarterly EBITDA margins and revenue streams.
How should companies handle information shared with regulators and law enforcement?
Serious cyber incidents routinely require early information sharing with government agencies, regulators, and law enforcement bodies. Issuers must carefully manage these regulatory touchpoints while balancing concurrent market disclosure duties. Coordinated responses require strict adherence to regulatory expectations without inadvertently leaking price-sensitive operational data to the wider market.