The SEC's cybersecurity disclosure rules, adopted July 2023 and effective for incidents reported on or after December 18, 2023, require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of a materiality determination — not four days from discovery. Annual reports must additionally describe risk management, strategy and governance in Item 106 of Regulation S-K. The rule's central ambiguity, what makes an incident "material," was deliberately left to the company's own qualified judgment, and enforcement through 2025 showed the SEC's focus: not failure to predict attacks, but inconsistent internal controls around disclosure decisions and, in four enforcement actions of 2023-2025, downplaying incidents that proved material.
USA Post publishes information about securities regulation, not legal advice.
What triggers the four-day clock?
The clock starts when the company determines, without unreasonable delay, that a material incident has occurred. That structure gives management an assessment window but obliges diligence in reaching the determination: the SEC stated in the adopting release that a company cannot avoid the deadline by delaying its investigation. In practice, boards convene a disclosure committee that applies the same materiality standard used for other disclosures — would a reasonable investor consider the information important — with incident-specific inputs: harm to operations, ransom demands, data exfiltration scope, litigation and regulatory exposure. Item 1.05 requires disclosing the nature, scope, timing, and material impact or reasonably likely material impact on finances and operations; if details are unknown, the rule permits stating that an investigation is ongoing and filing an amendment later.
What did the enforcement actions establish?
Four actions define the landscape. SolarWinds (settled 2025) targeted pre-incident statements: the SEC charged that public assurance about security practices was misleading given known internal gaps — a fraud theory, not a timing case. The SolarWinds settlement, with a civil penalty and a relief defendant payment, confirmed the SEC will police cybersecurity statements made outside Form 8-K. The June 2024 actions against four companies penalized disclosure timing and character: one company described an intrusion as risking unauthorized access when intruders had already accessed systems, and another disclosed without an Item 1.05 determination eight months after learning of a material incident. The lesson drawn across the bar: understatement is riskier than prompt, qualified disclosure, and internal controls must document who decided materiality, on what facts, and when.
How do companies structure the materiality decision?
- Adopt a written incident-response plan routing any credible incident to a disclosure committee including legal, security, finance and investor relations within 24-48 hours.
- Separate operational response from disclosure judgment: containment does not wait for materiality, and materiality does not wait for full forensics.
- Document each materiality assessment contemporaneously — the record of decisions not to file is what the SEC requests in investigations.
- Draft the Item 1.05 8-K to state what is known, flag the investigation, and amend on Item 1.05(a) material developments without turning each development into a new incident.
- Align insider-trading controls: a blackout should descend on incident knowledge the moment materiality is plausible, before the determination itself.
What do the annual disclosure requirements add?
Item 106 of Regulation S-K, effective for fiscal years ending on or after December 15, 2023, requires describing processes for assessing, identifying and managing material cyber risks, whether and how the board and its committees oversee them, and management's role and expertise. Companies without a CISO describe the function nonetheless — the rule requires disclosure of management positions responsible. The SEC emphasized that boilerplate risk factors fail the requirement: disclosures must be specific to the company's actual risks and processes. Enforcement has not yet tested Item 106 alone, but plaintiff firms read annual cyber disclosures as a standard against which incident facts are later measured.
How does the rule interact with litigation and state law?
The Item 1.05 filing is discoverable and quoted in follow-on securities class actions, which through 2025 have been filed within days of major filings and mostly dismissed at the pleading stage absent downplaying or trading. State breach-notification statutes run on separate clocks keyed to affected residents, typically 30-60 days, and cover nonpublic companies — the 8-K regime does not displace them. Ransomware presents the sharpest convergence: paying or refusing, the extortion demand itself figures in materiality, and disclosure of "reasonably likely" impact is permitted to include projected costs the company can support.
Is the rule changing?
Only at the margins. A petition for review challenged the four-day window as impractical; the court upheld the rule in 2025. The SEC's own retrospective statements have suggested openness to clarifying when repeated amendments are required, and commenters have asked whether private companies will be pulled in through a future rulemaking, but as of early 2026 the December 2023 framework stands. Boards should treat the four-day window as fixed law and invest in what it actually demands: a documented, fast, and honest materiality process.
For more context, read Related-Party Transactions: Item 404 Disclosure and the Audit Committee's Gatekeeping Role.
For more context, read clawback policy rule 10d-1.
For more context, read rule 13e-3 going private.
