If it's a public company, it's securities fraud. IMHO, securities law is the most effective tool at the moment in encouraging improved security engineering, best practices, and posture.
https://www.sec.gov/news/press-release/2021-154
""As the order finds, Pearson opted not to disclose this breach to investors until it was contacted by the media, and even then Pearson understated the nature and scope of the incident, and overstated the company's data protections," said Kristina Littman, Chief of the SEC Enforcement Division's Cyber Unit. "As public companies face the growing threat of cyber intrusions, they must provide accurate information to investors about material cyber incidents."
The SEC's order found that Pearson violated Sections 17(a)(2) and 17(a)(3) of the Securities Act of 1933 and Section 13(a) of the Exchange Act of 1934 and Rules 12b-20, 13a-15(a), and 13a-16 thereunder. Without admitting or denying the SEC's findings, Pearson agreed to cease and desist from committing violations of these provisions and to pay a $1 million civil penalty."
I can understand companies being worried that a compromise of a test system with no access to sensitive data -- which they normally wouldn't be required to disclose -- could make them look bad. But at the same time they're all being required to disclose this info so at least there's safety in numbers.
https://www.reuters.com/technology/hackers-demand-70-million... (July 2021: Up to 1,500 businesses affected by ransomware attack, U.S. firm's CEO says)
(disclosure: infosec practitioner)
So even if a system with absolutely no information was breached if your other system(s) use(s) the same or similar security then it doesn’t really matter that nothing was taken. The breach could still material (and require disclosure) because it’s exposed a material security vulnerability.
That's just a fucking sad state of affairs. Apparently they owe nothing to their customers.
A public corporation has a legal and fiduciary duty to its owners other than hiding what happened.