TrollEye Security

Cyber News

When Leadership Has to Decide Before Security Has Every Answer

The McKesson incident shows what security needs to have ready when leadership must make critical decisions before every answer is available.

Can Security Give Leadership What It Needs to Make a Decision?

McKesson discovered a cybersecurity incident on August 25, 2026. Three days later, the company told investors that its investigation remained in its early stages and that it had not determined that the incident was material.

A lot has to happen between those two moments.

Security may still be establishing what was accessed and what data may have left. At the same time, operations may need to decide whether systems stay online, legal has to assess disclosure obligations, and executives have to determine what they can confidently say publicly.

The investigation may still be developing, but the business can’t always wait.

That’s the challenge for security: giving leadership enough context to make a critical decision before every technical question has an answer.

Three days, one public position
Aug 21–25
Roughly 1TB exfiltrated over four days, according to ShinyHunters. McKesson has confirmed exfiltration, but not the volume, dates, or data involved.
Aug 25
McKesson discovers the incident and activates its incident response protocols.
Aug 28
Form 8-K filed under Item 7.01 (Regulation FD), not Item 1.05 (Material Cybersecurity Incidents). Investigation “in its early stages”; materiality not determined.
This was the window between discovery and McKesson’s first public position.

What McKesson Had to Decide

McKesson disclosed a cybersecurity incident involving third-party applications, unauthorized access, and data exfiltration. The company warned of possible service degradation, said it was not proactively disconnecting systems, and had not yet determined whether the incident was material.

ShinyHunters claims it took roughly a terabyte from McKesson’s Salesforce and Snowflake environments, totaling about 284 million records. McKesson has confirmed exfiltration occurred, but not the platforms, volume, or data involved.

Leadership still needed enough clarity to act while key details remained unresolved. Security’s job is to quickly establish what is known, what is still uncertain, what the business could face, and what options leadership has available.

The 5 Questions Security Should Be Ready to Answer

When a critical exposure or active incident reaches leadership, security should be able to move quickly through five questions.

01 What business operation is exposed? +

Connect the affected technology to the operation the business actually depends on. Leadership needs to understand what stops, slows down, or becomes exposed if the asset is compromised.

Translate: “Unauthorized access to a third-party application” → “The affected application supports customer operations and contains sensitive data.”
Have Ready
Asset owner Business process Criticality Data classification
In the McKesson case: McKesson has confirmed the incident involved third-party applications. To assess the operational risk, leadership needs to know which business processes depend on those applications and what would be affected if access or availability were disrupted.
02 What can actually happen? +

Move beyond the initial technical finding and establish the realistic outcome. Determine what an attacker can reach, what actions are possible, and whether sensitive systems or data are accessible.

Translate: “A valid employee account was compromised” → “An attacker can access the systems and data that employee is authorized to use.”
Have Ready
Attacker access Reachable systems Access level Existing controls
In the McKesson case: ShinyHunters claims it used vishing calls and a lookalike mckesson[.]claims domain to compromise employee Okta SSO accounts, then pulled data from Salesforce and Snowflake. McKesson has confirmed unauthorized access and exfiltration involving third-party applications, but not the vector or the platforms.
03 What is the potential business impact? +

Connect the possible technical outcome to consequences the organization cares about: disruption, revenue, customers, regulatory obligations, contractual exposure, or reputation.

Translate: “Sensitive data may have been accessed” → “We may face customer notification, regulatory obligations, and contractual consequences depending on what data is confirmed.”
Have Ready
Operational dependency Sensitive data Regulatory exposure Customer impact
In the McKesson case: ShinyHunters claims the data includes names, dates of birth, Social Security numbers, patient IDs, Medicaid numbers, medical record numbers, and medication and allergy information. If those categories are confirmed to include unsecured protected health information subject to HIPAA, breach-notification obligations could follow. HIPAA generally requires individual notification without unreasonable delay and no later than 60 days after discovery of a breach, with other applicable laws potentially imposing additional requirements.
04 How urgent is the decision? +

An incomplete investigation does not mean leadership can wait. Establish what is known, what remains uncertain, and when a business decision actually needs to be made.

Translate: “The investigation is ongoing” → “We don’t have complete scope yet, but leadership needs to make a decision within the next 24 hours based on what we know now.”
Have Ready
Known facts Key unknowns Decision deadline Existing controls
In the McKesson case: Only three days separated discovery from a public filing that described the investigation as being in its early stages and stated the company had not determined the incident was material.
05 What are our options? +

Don't stop at identifying the problem. Give leadership the available actions and make the tradeoffs clear enough to support an informed business decision.

Translate: “We can restrict access or continue monitoring” → “Restricting access reduces immediate risk but may disrupt operations; keeping access available preserves operations but leaves more residual risk.”
Have Ready
Available actions Risk reduction Business tradeoff Residual risk
In the McKesson case: McKesson said it was not proactively disconnecting systems while its investigation continued. ShinyHunters also says it demanded $55,236,150 within 72 hours and that McKesson did not respond or negotiate. If accurate, that added another time-sensitive decision while the scope of the incident was still developing.
Operationalize It

Build the context before leadership needs it.

The middle of an incident is too late to start connecting assets, exposures, and business consequences. Build that context into the way exposures are managed.

STEP 01 Map

Connect critical assets to owners, business processes, and sensitive data.

STEP 02 Enrich

Add attacker access, business dependencies, and potential impact as incidents and exposures are assessed.

STEP 03 Escalate

Define which conditions trigger leadership, legal, or operational involvement before an incident occurs.

STEP 04 Rehearse

Use real scenarios and tabletop exercises to test how quickly your team can answer the five questions.

The goal isn’t to give leadership more security data. It’s to make sure that when a decision has to be made, security can quickly explain what is at risk, what could happen, how urgent it is, and what choices the business has.

Test Your Program

Pick one of your highest-priority exposures and imagine the CEO, CFO, or general counsel asks: “What happens to the business if this is exploited?”

If answering the questions above requires several teams, multiple spreadsheets, and a few days of investigation, you may not have a security data problem. You have a context problem.

Finding exposures matters. Prioritizing and fixing them matters. Validating that risk actually went down matters. But the next step is being able to explain what that work protected and what the business should do next.

Because when the next critical decision reaches leadership, they won’t be asking for another vulnerability score. They’ll be asking: “What does this mean for us?”

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated