When Coca-Cola disclosed the fairlife ransomware attack on July 16, I went looking for the lesson in the obvious places.
It wasn’t the third-party exposure β though a wholly owned subsidiary’s systems taking down U.S. production is a supply-chain lesson worth its own memo.
It wasn’t the production halt, with U.S. lines down and Canada still running.
It wasn’t the data question, or the ransom, or the attacker β none of which the company had pinned down when it filed, and some of which it may never disclose.
The lesson wasn’t in the attack. It was in one sentence buried inside the filing.
The fork
Every public company eventually reaches the same fork in the road. When a cyber incident hits, the disclosure goes down one of two paths β and they are not interchangeable.
Item 1.05 β “Material Cybersecurity Incident.” This one tells investors you’ve determined the incident is material. It starts a four-day clock, triggers the full disclosure apparatus, and uses the language that puts investors, regulators, and plaintiffs’ counsel on notice.
Item 8.01 β “Other Events.” This one tells investors you’re still evaluating. Item 8.01 exists precisely because not every significant event is immediately material β it lets a company communicate without prematurely reaching a legal conclusion.
Coca-Cola filed fairlife under 8.01. That was a decision. Somewhere inside the company, a disclosure committee, executives, and counsel reached a conclusion that the incident was not yet material enough to trigger 1.05. Future filings may add facts that change the picture β but the governance decision was made in real time, on a clock, with what was known that day. The machinery to make it well existed before July 16, or it didn’t.
It’s a negotiation, not a legal exercise
Here’s the part boards miss. Choosing the path isn’t really a legal question. It’s an internal negotiation under a deadline.
The CISO sees operational disruption. The General Counsel sees litigation risk. The CFO sees investor impact. Three people, three legitimate readings of the same incomplete facts β and someone has to reconcile them into one filing before the clock runs out.
So the question for your board isn’t do we understand Item 1.05. It’s: when those three views collide on a Tuesday, who owns the call β and have they ever been in the room together before the incident?
If you can’t answer that right now, that’s the work.
You can’t answer it with a number
fairlife did $4 billion in sales last year β but materiality is measured against the parent, and Coca-Cola is a ~$47 billion company. There’s no dollar threshold and no formula. The standard is qualitative: would a reasonable investor consider it important?
So you don’t pre-decide the answer. You pre-build the machinery that produces it β four things, none of which require knowing what the attack will be:
The Decider. Who owns the final call when the CFO, GC, and CISO disagree.
The Decision Criteria. The factors you weigh β operational disruption, data, regulatory and reputational exposure, duration. A checklist, not a formula.
The Clock. Four business days runs from the materiality determination, not from discovery. No framework means slow determination β and slow is what regulators notice.
Your First Public Sentence. fairlife’s “not yet determined to be material” is a position β the honest sentence that buys time without conceding or dismissing. What does yours sound like?
The takeaway
This isn’t really about SEC filings. Boards spend enormous time discussing cyber risk. Far fewer spend any time designing how cyber decisions get made under pressure. Those are different conversations. One measures preparedness. The other determines outcomes β and it applies just as much to a private company that will never file an 8-K in its life.
The most important negotiation in a cyber incident isn’t with the attacker. It’s the one your board has with itself about where the line is.
β Which path would your board take? The Cyber Oversight Card walks through the disclosure and governance calls worth settling in advance β the SEC and Board Duty sections speak directly to this one.
