Method, sources and neutrality
cisonews.net is the Incident & Disclosure Desk of the CISO Tribune network. It answers one question per entry: what did a company formally disclose about a security incident, and when? The site went live on 2026-09-27. It holds 77 incident entries, 75 of them compiled after the fact from public records.
What goes in the log
The core set is every SEC Form 8-K filed under Item 1.05, Material Cybersecurity Incidents, since the item took effect on December 18, 2023, found through EDGAR full-text search and checked against the item codes EDGAR records for each filing. Amendments (8-K/A) are tracked on the original entry. We add earlier or parallel disclosures made under Items 7.01 and 8.01 when a company used them to report an incident. Incidents that are specific to AI systems are covered by our sibling site cisonews.ai and are not duplicated here.
Two Item 1.05 filings found in the September 2026 EDGAR sweep are not in the log: one describes customer data handled through an unauthorized AI application, which is cisonews.ai territory; the other attributes the disruption to an individual's actions and is held for review by a human editor under the reputational rule below. Item 1.05 filings that EDGAR indexes only under other item codes can be missed by the sweep; tell us through the contact page if you know of one.
Sources
- Tier A: the filing itself on SEC EDGAR, the company's own press releases and newsroom statements, state attorney-general breach portals and regulator releases.
- Tier B: established press, used only alongside a tier A source or where a company has made no filing.
Every factual sentence traces to a source listed on the page. The short supporting passage for each fact sits beside it in the page source as an HTML comment, so a reviewer can check the claim against the document without leaving the file. Numbers (records affected, costs, dates) are copied as the filing states them.
Dates
Published is the day the entry first went live on this site. It is never set earlier than that. First disclosed is the filing date of the company's first 8-K about the incident. Detected is the date the filing gives for when the company identified the activity; when a filing gives none, the field says so. Entries about events more than 30 days before publication carry the line "Compiled (date) from public records." Structured data reports the publication date, not the incident date.
The neutrality rule
An incident entry describes what the company disclosed. It never assigns blame or cause to a named person. The "top security seat" field is a record fact from CISO Tribune: it names a person only where the CISO Tribune record shows who held the seat on the disclosure date, and otherwise reads "Not on the CISO Tribune record". If the only link between a person and an incident is timing, we give the dates and nothing else. Any page that says or implies someone was dismissed, sued or at fault is held for a human editor before it can publish.
The seat data was last joined from the CISO Tribune record on 2026-09-26.
How AI is used
Software agents find new filings on EDGAR each day, fetch them, and draft an entry. A model (Anthropic's Claude) writes the draft summary; code then checks that every supporting passage appears in the fetched document, and the network gate checks sourcing, dates, banned wording and duplication. Drafts arrive as pull requests. Entries that touch reputational territory wait for a person. No quote on this site is generated: quotations, where used, are verbatim from the cited document.
Corrections
Corrections are made on the entry, noted there with a date, and logged on the corrections page. Send them through contact.