First, since we do not know the information obtained, we can't say if the CEO or CFO should be informed.
If the scope of what they were required to deliver included information that could have an impact on the financial disclosures of the company[1] then, under Sarbanes-Oxley, they are at least required to put controls in place to communicate or prevent inaccurate financial reporting. This could also be why the CFO was not involved in the denials, because they've at least separated NTK.
As for the portal, the lowest common denominator would be an ftp server. Maybe they put it on fbiguy3@gmail.com's Google Drive so he had to log in. I'd like to think I'd encrypt it with a huge whopping GPG key, email it from a gmail to a yahoo address under my control, and ask,"Did you get that?" but I know I'd just piss down my leg and give them what they wanted.
Finally, Google is rather proud of the predictions or observations it can make based on (they say) trends in search queries. For example, it is now taken as fact that "Google can predict the flu better than the CDC/WHO/etc." I would not be surprised if Google and other companies could tell at least how many FISA requests have probably been generated by segmenting requests for related searches. (Of course, LexisNexis, FindLaw, and the like would have even better information when paying customers do their due diligence on compliance with unreasonable requests.)
[1] E.g., Send us all credit card information for customers from outside the USA.