9filers, current period
9the period before
84controls it touches
44frameworks
Ransomware in 10-K and 10-Q filings, by month.
The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.
Companies disclosing it
9
wrote this into a filing with the SEC
What it obligates
84
controls across 44 frameworks whose text speaks to it
Employers hiring for it
843
open US roles name it, and the ones below are hiring now
The long view, in 8-K filings
An 8-K is filed within four business days of an event, so this counts filings made because something happened.
Every month since 2008. The last point is the current month and is still
filling, so it always looks lower than it will be.
2008
peak 98 in February 2023
2026
The long view, in annual and quarterly filings
A 10-K or 10-Q is a periodic report, so this counts how often the phrase appears in routine annual and quarterly reporting. It moves far more slowly and the numbers are larger.
Every month since 2008. The last point is the current month and is still
filling, so it always looks lower than it will be.
2008
peak 1,277 in February 2026
2026
In annual and quarterly filings the same phrase appears 907 times this quarter, against 861. A 10-K moves slowly: a company changing what it writes there has changed its mind about what is material, rather than reacting to one event.
Who disclosed it
From SEC full-text search over 8-K filings. Every row links to the filing itself.
| Company | Form | Filed | |
| NOMAD POWER SOLUTIONS, INC. NMAD | 8-K/A | 2026-09-17 | filing |
| FB Financial Corp FBK | 8-K | 2026-09-17 | filing |
| Sixth Street Lending Partners | 8-K | 2026-09-21 | filing |
| USA Rare Earth, Inc. USAR | 8-K | 2026-09-15 | filing |
| Flag Ship Acquisition Corp | 8-K | 2026-09-15 | filing |
| Public Storage | 8-K | 2026-09-16 | filing |
| Mistras Group, Inc. MG | 8-K | 2026-09-18 | filing |
| ACP Holdings Acquisition Corp. | 8-K | 2026-09-16 | filing |
The full search on EDGAR
Who is hiring for it
A sample of the open roles naming this phrase. An employer paying a salary
against something is the least ambiguous demand signal there is, and every row links to the
posting so the claim can be checked rather than believed. The total above is the whole US
market; these are the ones we hold the posting for.
| Role | Posted |
| Technical Architect Okta, Inc. · Bengaluru, India | 2026-09-17 |
| Staff Cloud Security Engineer Xometry, Inc. · Denver, CO | 2026-09-17 |
| Solutions Architect (Germany or Austria) COMMVAULT SYSTEMS INC · Frankfurt, Germany | 2026-09-15 |
| Sr. Analyst, Enterprise Service Desk Abacus Life, Inc. · Portland, Oregon, United States | 2026-09-10 |
| Sr. Analyst, Enterprise Service Desk Abacus Life, Inc. · Las Vegas, Nevada, United States | 2026-09-10 |
| Sr. Analyst, Enterprise Service Desk Abacus Life, Inc. · Reno, Nevada, United States | 2026-09-10 |
| Senior Sales Engineer, Brisbane Rubrik, Inc. · Brisbane, Australia | 2026-09-10 |
| Solutions Architect (Italy) COMMVAULT SYSTEMS INC · Italy | 2026-09-08 |
| Senior Security Research Engineer Elastic N.V. · Canada | 2026-08-27 |
| Senior Security Research Engineer Elastic N.V. · Spain | 2026-08-27 |
| VP, Government & Legal Affairs Rubrik, Inc. · Reston, VA | 2026-08-27 |
| Senior Security Research Engineer Elastic N.V. · United States | 2026-08-26 |
| Client Executive, SLED Cloudflare, Inc. · Hybrid | 2026-08-25 |
| Senior Counsel, Cyber Security and Incident Response CoreWeave, Inc. · Livingston, NJ | 2026-08-25 |
How it actually arrives
An 8-K's meaning is in its item number, not its text. These are the items the filings
containing this phrase were filed under. The first group is something that happened to the
company. The second is the phrase turning up in the ordinary course of reporting, most often in
an earnings release, which is a very different thing and is usually the larger number.
| Filed because something happened |
Companies |
| Other material event Item 8.01 | 559 |
| Director or officer departure Item 5.02 | 227 |
| Change of accountant Item 4.01 | 25 |
| Delisting or listing rule failure Item 3.01 | 22 |
| Bankruptcy or receivership Item 1.03 | 14 |
| Material cybersecurity incident Item 1.05 | 6 |
| Material impairment Item 2.06 | 4 |
| Financial statements no longer reliable Item 4.02 | 2 |
| Mentioned in routine reporting |
Companies |
| Financial statements and exhibits Item 9.01 | 1343 |
| Entry into a material agreement Item 1.01 | 1115 |
| Regulation FD disclosure Item 7.01 | 708 |
| Results of operations, the earnings release Item 2.02 | 225 |
| Completion of an acquisition Item 2.01 | 166 |
| Shareholder vote Item 5.07 | 42 |
This is why a headline count on its own overstates the case.
Where the routine number dominates, the phrase is being tracked as language rather than as
events.
Which industries file it
Companies grouped by the industry classification on their own filing. A count, not a
survey.
| Industry | | Companies |
|---|
| Holding and investment offices | | 174 |
| Software and IT services | | 148 |
| Chemicals and pharmaceuticals | | 141 |
| Banking | | 93 |
| Electronics and electrical equipment | | 75 |
| Instruments and medical devices | | 72 |
| Industrial machinery | | 63 |
| Services and entertainment | | 55 |
| Mining and extraction | | 54 |
| Pipelines and communications | | 50 |
What it obligates
Our corpus holds 84 controls across
44 frameworks whose text speaks to this. Not a judgement:
these controls say so, and each is one lookup from its source document. Ordered by how much each
framework has to say about it, so the one that will cost you the most work is first. Every name
opens that framework in the corpus.
What an auditor will ask you to produce
The artefacts named on those controls, most frequently cited first.
- Pipeline + emerging risk readiness
- Multi-framework alignment + crosswalk
- FISMA reporting + CyberScope submission
- OMB Memo M-24-04 compliance
- FISMA 2.0 reform tracking
- Annual FISMA Report inclusion + agency score
- Backup policy
- Restoration test reports
How it usually fails
Recorded when each control was verified against its source. This is where programmes
that think they are covered turn out not to be.
- Pipeline not tracked
- International alignment weak
- Adoption monitoring weak
- Incomplete CMDB
- Multi-framework alignment ad-hoc
- FISMA reporting overdue or incomplete
114If you already run ISO 27001:2013, that is the 114 controls behind this disclosure, already evidenced.
691And ISO 27701:2019 is not a separate programme. 691 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
542And ISO 27002:2022 is not a separate programme. 542 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
369And ISO 22301:2019 is not a separate programme. 369 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
Run as two programmes
805 controls
ISO 27001:2013 and ISO 27701:2019 scoped separately, each with its own
evidence, its own owner and its own budget line. This is how almost everybody does it.
Run once, counted twice
691 already done
691 of ISO 27701:2019's controls are controls you evidenced for
ISO 27001:2013. Same artefacts, same owner, no second effort. The mapping is the
only reason anybody knows.
Ransomware in 10-K and 10-Q filings, by month.
The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.
What this actually means
- Why now
- 9 public companies wrote this into an 8-K in the last seven days, 0% fewer than the seven before. That is not sentiment or a survey. It is a count of companies choosing to put a phrase into a document they are legally accountable for.
- Who already cares
- 843 open US roles name this work today, which suggests increased attention to it beyond what any filing says. A job advertisement clears a budget holder and a filing clears legal, so the two answer to different people. We have not measured which moves first, only that both are moving.
- What comes into scope
- Once the phrase is on the record it maps to obligations within ISO 27001:2013, ISO 27001:2022, NIST Cybersecurity Framework 2.0. 374 controls behind those, and the difference between asserting them and evidencing them is the whole of the work.
- Who is quietly ahead
- Anyone already running ISO 27001:2013 has done 691 of the controls that carry ISO 27701:2019 too. Same evidence, second standard. Most organisations run those as two programmes with two budgets because nobody told them the mapping existed.
- Who is exposed
- 102 companies disclosed this for the first time in the last ninety days, out of 4005 in total. A first mention is a company deciding it can no longer not say it. Whoever has not yet is either genuinely unaffected or has not looked, and nothing here distinguishes the two.
What this obligates
The instruments in our corpus that govern this disclosure, and how many controls sit
behind each. This is not a filing count. It is what applies once a company has written the
phrase down.
5 frameworks, 374 controls between them.
What closing it also moves
The same controls appear in other frameworks through mappings held in our corpus. Work
done here is already progress there. This is the part that is not in EDGAR and not in any public
dataset: it comes from mappings built and verified by hand, control by control.
ISO 27701:2019691
ISO 27002:2022542
ISO 22301:2019369
ISO/IEC 42001:2023343
NIS2 Directive201
PCI DSS 4.0183
COBIT 2019148
Counted as controls reached through cross-framework mappings. It measures
overlap of work, not compliance with the named framework.
Run as two programmes
805 controls
ISO 27001:2013 and ISO 27701:2019 scoped separately, each with its own
evidence, its own owner and its own budget line. This is how almost everybody does it.
Run once, counted twice
691 already done
691 of ISO 27701:2019's controls are controls you evidenced for
ISO 27001:2013. Same artefacts, same owner, no second effort. The mapping is the
only reason anybody knows.
114If you already run ISO 27001:2013, that is the 114 controls behind this disclosure, already evidenced.
691And ISO 27701:2019 is not a separate programme. 691 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
542And ISO 27002:2022 is not a separate programme. 542 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
369And ISO 22301:2019 is not a separate programme. 369 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
Tell me when Ransomware files something new
One email when a public company newly discloses this, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.
Where this comes from
The left half is public record: SEC full-text search over 8-K filings, counted across a
7 day window against the equivalent window before it. You can check
every row.
The right half is ours: 723 frameworks and
20,473 controls, 531 of those frameworks verified against
their source documents, with the auditor evidence and common failure modes recorded control by
control. Controls appear here because their own text names this term.
Cite this
The Art of Service Signals. Ransomware corporate disclosure activity: 9 filers against 9 in the prior period, in 8-K filings over seven days against the seven before. Accessed 23 September 2026. https://signals.theartofservice.com/t/ransomware/
Free to use with attribution, no permission needed. The chart downloads as an SVG
with the source printed on it. If you cite it we would like to know, but you do not need to
ask.
Today's edition ·
How programmes fail ·
The obligation index