THE DEEP TAKE
The clock you report on is not the clock you learn on
A billing vendor called Unlimited Technology Systems told the federal government in late July that 3.8 million patients were exposed. The intrusion happened between October 5 and October 10 of last year. HHS posted it to its public breach portal on August 6. That is roughly ten months between the attack and the public record.
The company runs revenue cycle management for more than 4,500 oncology practices and 6,500 specialty providers. None of those practices set that timeline. They learned when the vendor decided they would learn. Social Security numbers, diagnosis and treatment detail, and scanned insurance cards were in the exposed set. It is the second largest healthcare breach reported to HHS this year.
Now put that next to what regulators are about to require of you. CISA's incident reporting rule under CIRCIA is expected to be finalized in September. Covered entities will get 72 hours to report a substantial incident. Ransom payments get 24 hours. More than 300,000 organizations across 16 critical infrastructure sectors fall inside the rule.
The two clocks do not connect. Your reporting obligation starts when you become aware. Your awareness is governed by a contract you probably signed years ago. Most of those contracts say the vendor will notify you "promptly" or "without unreasonable delay." Neither phrase contains a number. A vendor can take ten months and stay inside the wording.
That gap is a procurement problem before it is a security problem. Regulators are compressing the clock you control. Nobody is compressing the clock your vendors control. Your fastest possible response is capped by your slowest supplier's legal review, and no amount of internal readiness fixes it.
Pull the notification clause from your five highest data volume vendor contracts this week. Look for one thing: a number of hours, counted from discovery rather than from confirmation. If the clause says "promptly," you do not have a notification term. You have a hope. Put a fixed hour count in the next renewal and make it a condition of the data processing addendum.
Powered by the DoGood network
The data in this issue came from priority submissions by 5,000+ enterprise IT leaders. If you run IT or security at a $100M+ company and want to see what your peers are funding — and earn rewards for participating in vetted meetings with the vendors worth your time — apply to join DoGood.
QUICK HITS
The federal clock on your load balancer started 64 days after the patch
Progress patched a command injection flaw in LoadMaster on June 4. Researchers published working technical detail on June 29, and exploitation attempts began the same day. CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on August 7 and gave federal agencies until August 10. More than 790 exploit attempts were reported before that listing. The flaw needs no credentials, rates 9.6, and lets an attacker run shell commands on the appliance. Load balancers sit in front of the applications you care most about. If your patch program tracks appliances separately from servers, check this week whether that track has an owner.
Only one in nine enterprises can forecast its AI bill
A survey of 396 enterprises published this month found that 11% can forecast AI spending within 10% either way. Last year the figure was 15%. The governance consequences are already visible. Among organizations hit by an AI cost surprise, 40% escalated it to the board, a third imposed an emergency spending freeze, and a quarter delayed or cancelled an AI initiative. The problem is not that AI is expensive. It is that AI spend is unpredictable, and unpredictable spend gets frozen. If your agent workloads bill on tokens or per run compute, set a hard cost ceiling on each one before the next board cycle.
Moody's just told your board about your AI supplier list
Moody's published a warning on August 12 that banks adopting proprietary AI models are building a systemic dependency on a small group of loss making suppliers. It named OpenAI and Anthropic. The argument is not about model quality. It is about concentration. Firms are embedding these models in credit scoring, fraud detection, anti money laundering, identity verification and regulatory filing, and a handful of providers sit under all of it. Financial services draws this scrutiny first because it is regulated first, and the framing travels. When a rating agency describes your supplier concentration, that assessment reaches your board through a channel you do not control. Worth knowing which of your production AI workloads has a second supplier that could actually run it.
THE NUMBER: 275 million
One incident accounts for roughly 275 million of the 471 million breach victim notices issued in the first half of 2026, according to the Identity Theft Resource Center. That is 58% of the total, from a single compromise at one education platform. The other 1,802 tracked compromises split the rest. This matters because the aggregate figure is about to show up in board decks and vendor pitches as proof that breach exposure is climbing everywhere. It is not that clean. The victim notice number measures how large the largest incident was, not how much more often organizations are being breached. When someone hands you the 471 million figure this fall, ask what the median incident looked like.
Every story this week turned on the same thing: the information arrived after the decision window closed. The DoGood network exists so the people running these environments can compare notes before that happens rather than after.
The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.
Know a CIO who needs this? Forward it and they can subscribe here.
Enterprise IT leader at a $100M+ company? Apply to join DoGood.
