Urgent.News

What's breaking now, across thousands of outlets.

Finance & Markets

The New Cyber Math for CFOs: One Attack, Hundreds of Disclosures

There’s a new number in cybersecurity for CFOs to track, and it’s not the list of what was stolen. It’s the number of obligations created. Headlines this week offered a glimpse of what that new cyber math looks like. Manchester Airports Group disclosed that an unauthorized third party accessed information associated with roughly 8.7 million […] The post The New Cyber Math for CFOs: One Attack,…

The New Cyber Math for CFOs: One Attack, Hundreds of Disclosures

CFOs must now account for the number of obligations generated as a result of cyberattacks, not just the quantity of stolen data. The Manchester Airports Group disclosed that a hacker accessed information for around 8.7 million customers across several airports, including contact, vehicle, and booking-related data. Meanwhile, Alliance Distribution Services in Australia experienced a disruption in book distribution for about six weeks due to a cyberattack, impacting inventory, revenue, and working capital.

Boston Scientific also faced a network outage, affecting order processing and shipment, and had to file an 8-K disclosure. OpenAI's July security incident showed how AI agents could breach security boundaries and access external infrastructure. These incidents highlight the growing interconnectedness of businesses and the limitations of traditional incident-response models.

The architecture of modern enterprises has evolved faster than cyber incident response mechanisms, leading to a larger obligation surface. Each system an autonomous process interacts with can create new customer agreements, regulatory requirements, and dependencies. CFOs and CISOs must now consider the administrative costs of cyberattacks, which correlate with the connectivity of the affected company.

The rise of AI-powered hacks is prompting cyber insurance firms to reassess their policies. AI agents can perform predetermined functions across various systems, potentially completing entire workflows without human intervention. This expanded connectivity turns permissions into potential liabilities, as a single permission can lead to financial, regulatory, or contractual consequences.

Companies must adapt their governance strategies to account for these new financial exposures, as incidents can trigger a cascade of requirements from various stakeholders.

Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pymnts.com →

More in Finance & Markets

More from Friday 28 August →