Since September 11, companies have been subject to the 24-hour reporting requirement for IT security vulnerabilities and cyber incidents. While the deadline has been known for some time, there is still heated debate over how practical such a short reporting window really is.