Can Security Give Leadership What It Needs to Make a Decision?
McKesson discovered a cybersecurity incident on August 25, 2026. Three days later, the company told investors that its investigation remained in its early stages and that it had not determined that the incident was material.
A lot has to happen between those two moments.
Security may still be establishing what was accessed and what data may have left. At the same time, operations may need to decide whether systems stay online, legal has to assess disclosure obligations, and executives have to determine what they can confidently say publicly.
The investigation may still be developing, but the business can’t always wait.
That’s the challenge for security: giving leadership enough context to make a critical decision before every technical question has an answer.
What McKesson Had to Decide
McKesson disclosed a cybersecurity incident involving third-party applications, unauthorized access, and data exfiltration. The company warned of possible service degradation, said it was not proactively disconnecting systems, and had not yet determined whether the incident was material.
ShinyHunters claims it took roughly a terabyte from McKesson’s Salesforce and Snowflake environments, totaling about 284 million records. McKesson has confirmed exfiltration occurred, but not the platforms, volume, or data involved.
Leadership still needed enough clarity to act while key details remained unresolved. Security’s job is to quickly establish what is known, what is still uncertain, what the business could face, and what options leadership has available.
The 5 Questions Security Should Be Ready to Answer
When a critical exposure or active incident reaches leadership, security should be able to move quickly through five questions.
01 What business operation is exposed? +
Connect the affected technology to the operation the business actually depends on. Leadership needs to understand what stops, slows down, or becomes exposed if the asset is compromised.
02 What can actually happen? +
Move beyond the initial technical finding and establish the realistic outcome. Determine what an attacker can reach, what actions are possible, and whether sensitive systems or data are accessible.
03 What is the potential business impact? +
Connect the possible technical outcome to consequences the organization cares about: disruption, revenue, customers, regulatory obligations, contractual exposure, or reputation.
04 How urgent is the decision? +
An incomplete investigation does not mean leadership can wait. Establish what is known, what remains uncertain, and when a business decision actually needs to be made.
05 What are our options? +
Don't stop at identifying the problem. Give leadership the available actions and make the tradeoffs clear enough to support an informed business decision.
Build the context before leadership needs it.
The middle of an incident is too late to start connecting assets, exposures, and business consequences. Build that context into the way exposures are managed.
Connect critical assets to owners, business processes, and sensitive data.
Add attacker access, business dependencies, and potential impact as incidents and exposures are assessed.
Define which conditions trigger leadership, legal, or operational involvement before an incident occurs.
Use real scenarios and tabletop exercises to test how quickly your team can answer the five questions.
The goal isn’t to give leadership more security data. It’s to make sure that when a decision has to be made, security can quickly explain what is at risk, what could happen, how urgent it is, and what choices the business has.
Test Your Program
Pick one of your highest-priority exposures and imagine the CEO, CFO, or general counsel asks: “What happens to the business if this is exploited?”
If answering the questions above requires several teams, multiple spreadsheets, and a few days of investigation, you may not have a security data problem. You have a context problem.
Finding exposures matters. Prioritizing and fixing them matters. Validating that risk actually went down matters. But the next step is being able to explain what that work protected and what the business should do next.
Because when the next critical decision reaches leadership, they won’t be asking for another vulnerability score. They’ll be asking: “What does this mean for us?”
Sources: McKesson Form 8-K | BleepingComputer