Building a Board-Ready OT Materiality Framework Before You Need It
Hillstrong Group Security ·
A practical framework for pre-defining OT incident materiality thresholds across production impact, safety, environmental, regulatory, and financial dimensions. Build it now, or build it during a crisis. Your choice.
Author: Roger Hill
The Framework You Wish You Had
Three weeks into this series, I have laid out the problem from multiple angles. The SEC’s four-day materiality clock was not built for OT incidents. Annual 10-K disclosures systematically omit OT risk. OT forensic timelines are incompatible with the speed the disclosure process demands.
Now it is time to build something.
This week, I am going to walk through a practical framework for OT incident materiality determination. Not a theoretical model. Not a compliance checklist. A working framework that a disclosure committee can use when someone calls at 2 AM and says the plant floor has a problem.
The core principle is simple: you cannot build this framework during a crisis. Every decision you make about materiality thresholds, impact scoring, escalation triggers, and communication protocols needs to be made before the incident. During the incident, you execute the framework. You do not design it.
I have built variations of this framework for manufacturers across chemicals, automotive, food and beverage, and heavy industry. The structure is consistent. The thresholds are specific to each organization. What follows is the architecture.
The Five Dimensions of OT Materiality
IT materiality is essentially one-dimensional: financial impact (including the cost of reputational damage, regulatory fines, and remediation). You can argue that IT materiality has qualitative dimensions, and the SEC says it does, but in practice, the analysis comes down to dollars.
OT materiality is five-dimensional. Each dimension must be assessed independently and then aggregated, because an incident can be material along one dimension but not others, and the combination of sub-material impacts across multiple dimensions can itself be material.
Dimension 1: Production Impact
This is the most intuitive dimension for manufacturing leaders. The questions are straightforward:
- How many production lines are affected?
- What is the revenue impact per hour of downtime on each affected line?
- What contractual obligations (delivery schedules, just-in-time commitments, penalty clauses) are at risk?
- What is the restart timeline? (In continuous processes, this can be days or weeks, not hours.)
- What is the downstream supply chain impact if production is interrupted?
Pre-define your thresholds. For each major production line, calculate the materiality threshold in terms of downtime duration. At what point does a production stoppage become material? For some manufacturers, losing a single line for a shift is a nuisance. Losing it for a week is material. For others, a single shift of downtime on a critical line triggers contractual penalties that cross the materiality line immediately.
Document these thresholds now. Your disclosure committee should be able to look at a table and know, within minutes of learning which production assets are affected, whether the production impact alone could be material.
Dimension 2: Safety Impact
This is where OT materiality diverges most sharply from IT materiality. Cybersecurity incidents in IT do not physically harm people. Cybersecurity incidents in OT can.
The safety dimension requires a different kind of threshold:
- Did the incident create a condition that could have resulted in worker injury or fatality?
- Was a safety instrumented system (SIS) compromised, bypassed, or degraded?
- Did an evacuation occur? Was emergency response activated?
- Were there near-miss events that triggered safety investigation?
The materiality question for safety is not purely financial. A near-miss with no injuries may not have direct financial impact, but it is exactly the kind of qualitative factor the SEC says companies should consider. A reasonable investor would absolutely want to know that a cyberattack created conditions that could have killed workers, even if nobody was actually hurt.
Pre-define the safety thresholds in collaboration with your EHS (Environment, Health, and Safety) team. Any event that triggers an OSHA-recordable investigation, any compromise of a safety instrumented system, and any worker evacuation due to a cyber-related process upset should be treated as presumptively material pending full assessment.
Dimension 3: Environmental Impact
Environmental liability from an OT cyber event can be the largest single financial exposure, exceeding the cost of the cyber incident itself by orders of magnitude.
- Did the incident cause or contribute to a release of regulated substances?
- Were environmental permits violated?
- Were environmental reporting thresholds triggered (CERCLA, EPCRA, state equivalents)?
- What is the potential remediation cost?
- What is the community impact exposure?
Environmental materiality has a long tail. The initial release may be quantifiable, but the remediation costs, consent decree obligations, and litigation exposure can extend for years. Your framework needs to account for both the immediate impact and the reasonably likely future costs.
Pre-define environmental thresholds based on your facility permits and the regulated substances you handle. Work with your environmental compliance team to identify which release scenarios cross the materiality line. In many chemical and pharmaceutical manufacturing operations, even a small uncontrolled release can trigger regulatory reporting obligations that, when combined with the cybersecurity incident context, create material exposure.
Dimension 4: Regulatory Cascade
An OT cyber incident that causes operational disruption can trigger multiple regulatory investigations simultaneously:
- SEC (cybersecurity disclosure)
- OSHA (workplace safety)
- EPA or state environmental agencies (environmental releases)
- Chemical Safety Board (for facilities handling threshold quantities)
- State public utility commissions (for regulated utilities)
- CISA (for critical infrastructure sectors)
- NIS2 authorities (for manufacturers with EU operations)
Each investigation carries its own costs, management distraction, and potential liability. The aggregate regulatory burden from a single OT incident can be material even if no single regulatory exposure crosses the threshold alone.
Pre-map your regulatory exposure. For each facility, document which regulatory agencies have jurisdiction, what reporting thresholds apply, and what the potential penalty ranges are. When an incident occurs, your disclosure committee should be able to immediately see the full regulatory map without having to research it under pressure.
Dimension 5: Insurance and Financial Liability
The insurance landscape for OT cyber events is complex and often poorly understood by the people making materiality determinations:
- Which insurance policies are triggered? (Cyber, property, general liability, environmental, workers’ comp, business interruption)
- What are the coverage gaps? (Many cyber policies exclude physical damage. Many property policies exclude cyber-caused damage.)
- What are the deductible and sublimit implications?
- What is the uninsured exposure?
- What is the D&O liability exposure for the board and officers?
The SEC has stated explicitly that insurance coverage does not negate materiality. But the insurance analysis matters for assessing the financial impact. If your cyber policy does not cover physical damage from a cyber event (and many do not), the uninsured loss from equipment damage alone may be material.
Work with your risk management and insurance team to pre-map coverage for OT cyber scenarios. Identify the gaps now. The middle of an incident is not the time to discover that your cyber policy excludes operational technology.
The Aggregation Problem
Here is where most frameworks fail: they assess each dimension independently but do not have a method for aggregating sub-material impacts.
Consider an OT incident where:
- Production impact: one line down for 48 hours. Significant but below your materiality threshold.
- Safety impact: one near-miss, no injuries. Concerning but below your safety materiality threshold.
- Environmental impact: minor release, below CERCLA reporting threshold. Not material on its own.
- Regulatory: OSHA opens a preliminary inquiry. Normal course.
- Insurance: deductible covers the direct costs. No uninsured loss.
Each dimension individually is sub-material. But in aggregate, you have a cybersecurity incident that caused production loss, a safety scare, an environmental release, and a regulatory inquiry. A reasonable investor would want to know about this. The aggregate picture is material even though no single dimension crosses the threshold.
Your framework needs an aggregation rule. My recommendation: if an OT cyber incident triggers assessment in three or more dimensions simultaneously, it should be treated as presumptively material regardless of whether any single dimension crosses its individual threshold. The combination of impacts across multiple dimensions creates a qualitative materiality signal that a single-dimension analysis would miss.
Operationalizing the Framework
A framework that lives in a binder on a shelf is useless. Here is how to make it operational.
The OT Materiality Card
Create a one-page reference card for each major production facility. The card should contain:
- Facility name and production profile (what it makes, annual revenue contribution)
- Top 5 critical OT assets (the PLCs, DCS systems, or SIS units whose compromise has the highest consequence)
- Production materiality thresholds (hours of downtime that cross the line, by production line)
- Safety materiality triggers (any SIS compromise, any evacuation, any OSHA-reportable event)
- Environmental materiality triggers (release thresholds, regulated substances, permit limits)
- Regulatory map (which agencies, what reporting timelines)
- Insurance coverage summary (what is covered, what is not, key exclusions)
- Key contacts (plant manager, OT security lead, EHS lead, environmental compliance, local counsel)
This card should be immediately accessible to your disclosure committee. When the call comes at 2 AM, the first thing someone does is pull the card for the affected facility. Within minutes, the committee has the context needed to begin the materiality assessment.
The Escalation Protocol
Define clear escalation triggers that connect the OT incident response process to the disclosure process:
Level 1 (Awareness): Any OT anomaly that is being investigated for potential cyber origin. Notification to the OT security lead and the CISO. No disclosure committee activation.
Level 2 (Assessment): OT anomaly confirmed or suspected to have cyber origin. Notification to the disclosure committee chair. Materiality card pulled. Preliminary dimension assessment begun.
Level 3 (Determination): Sufficient information to conduct materiality assessment across all five dimensions. Disclosure committee convenes (virtual is fine). Formal materiality determination made using the pre-defined thresholds and aggregation rules.
Level 4 (Disclosure): Materiality determination is affirmative. Four-day filing clock starts. Legal counsel engaged for 8-K drafting. Communications team briefed.
The key design principle: each escalation level has a defined trigger, a defined action, and a defined decision-maker. Nobody is improvising.
Annual Calibration
The framework is not static. Thresholds change as production profiles change, as insurance coverage changes, as regulatory requirements evolve, and as the threat landscape shifts. Calibrate the framework annually:
- Update production materiality thresholds based on current revenue and contractual obligations
- Review safety thresholds with EHS after any process changes
- Update environmental thresholds based on current permits and regulated substance inventories
- Refresh the regulatory map for any new jurisdictional requirements (especially NIS2 for EU-exposed manufacturers)
- Review insurance coverage with your broker and update gap analysis
Making It Board-Ready
The board does not need to understand PLC programming or ICS forensics. The board needs to understand the materiality framework and have confidence that it works.
Present the framework to your board risk committee with three elements:
- The architecture. Five dimensions, pre-defined thresholds, aggregation rule, escalation protocol. This should fit on two slides.
- A scenario walkthrough. Take a realistic OT incident scenario and walk the committee through how the framework would process it. Show them how the materiality card works, how the escalation triggers function, and how the determination is made. This makes the abstract concrete.
- The exercise results. Run the tabletop exercise I recommended in Week 1 (disclosure committee plus OT team, realistic scenario, real-time materiality determination). Report the results to the board, including what worked and what gaps were identified. Boards respond well to evidence that the framework has been tested and refined.
The goal is not to make the board experts in OT cybersecurity. The goal is to give the board confidence that the company has a structured, tested, and defensible process for making OT materiality determinations. That confidence is what the SEC’s governance disclosure requirements are actually asking for.
What You Can Do This Quarter
- Build materiality cards for your top five facilities. Start with the highest-consequence production sites. The exercise of gathering the data for the cards will itself reveal gaps in your preparedness.
- Define your aggregation rule. Decide how many concurrent sub-material impacts across different dimensions trigger a presumptive materiality determination. Get the disclosure committee, CISO, and general counsel to agree on the rule before an incident forces the decision.
- Map your escalation protocol. Define the four levels, the triggers, the actions, and the decision-makers. Publish it. Make sure everyone named in the protocol knows their role.
- Schedule the calibration cycle. Put the annual framework review on the disclosure committee’s calendar. Tie it to the 10-K filing cycle so the framework update informs the annual disclosure.
- Brief the board. Use the three-element presentation structure. Give them the architecture, a scenario walkthrough, and evidence that the framework has been tested.
What Comes Next
Next week is the final article in this series, and I am going to make an argument that may surprise you. I am going to argue that the manufacturers who build disclosure readiness now will gain a genuine competitive advantage, not just in regulatory compliance, but in investor confidence, insurance terms, customer trust, and operational resilience. Disclosure readiness is not a cost center. It is a strategic capability.
The companies that treat SEC disclosure as a burden will always be behind. The companies that treat it as a capability will be the ones the market rewards.
Thanks for reading! Has your organization built an OT-specific materiality framework? If so, what dimensions did you include that I missed? If not, what is the biggest obstacle to getting one built? We want to hear what is stopping people from doing this work before the first real test arrives.
Follow us for more cyber content!