Skip to content
Saturday, August 29, 2026
USA POST 21BUSINESS LAW · CORPORATE GOVERNANCE
S&P 500−0.35%FTSE 100−0.17%Euro/Dollar+0.22%Brent Crude+1.25%10-Year US+1.40%
USA POST 21BUSINESS LAW · CORPORATE GOVERNANCE
Home / Corporate News
Corporate News

SEC Cybersecurity Disclosure Rules: What the Four-Day 8-K Requirement Demands

Since December 2023, public companies must file an Item 1.05 Form 8-K within four business days of determining a cyber incident is material.

YT
Yuki Tanaka, · February 5, 2026 · 5 min read
ShareXFacebookLinkedInTelegramEmail
Server racks in a corporate data center corridor at night

The SEC's cybersecurity disclosure rules, adopted July 2023 and effective for incidents reported on or after December 18, 2023, require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of a materiality determination — not four days from discovery. Annual reports must additionally describe risk management, strategy and governance in Item 106 of Regulation S-K. The rule's central ambiguity, what makes an incident "material," was deliberately left to the company's own qualified judgment, and enforcement through 2025 showed the SEC's focus: not failure to predict attacks, but inconsistent internal controls around disclosure decisions and, in four enforcement actions of 2023-2025, downplaying incidents that proved material.

USA Post publishes information about securities regulation, not legal advice.

What triggers the four-day clock?

The clock starts when the company determines, without unreasonable delay, that a material incident has occurred. That structure gives management an assessment window but obliges diligence in reaching the determination: the SEC stated in the adopting release that a company cannot avoid the deadline by delaying its investigation. In practice, boards convene a disclosure committee that applies the same materiality standard used for other disclosures — would a reasonable investor consider the information important — with incident-specific inputs: harm to operations, ransom demands, data exfiltration scope, litigation and regulatory exposure. Item 1.05 requires disclosing the nature, scope, timing, and material impact or reasonably likely material impact on finances and operations; if details are unknown, the rule permits stating that an investigation is ongoing and filing an amendment later.

What did the enforcement actions establish?

Four actions define the landscape. SolarWinds (settled 2025) targeted pre-incident statements: the SEC charged that public assurance about security practices was misleading given known internal gaps — a fraud theory, not a timing case. The SolarWinds settlement, with a civil penalty and a relief defendant payment, confirmed the SEC will police cybersecurity statements made outside Form 8-K. The June 2024 actions against four companies penalized disclosure timing and character: one company described an intrusion as risking unauthorized access when intruders had already accessed systems, and another disclosed without an Item 1.05 determination eight months after learning of a material incident. The lesson drawn across the bar: understatement is riskier than prompt, qualified disclosure, and internal controls must document who decided materiality, on what facts, and when.

How do companies structure the materiality decision?

  1. Adopt a written incident-response plan routing any credible incident to a disclosure committee including legal, security, finance and investor relations within 24-48 hours.
  2. Separate operational response from disclosure judgment: containment does not wait for materiality, and materiality does not wait for full forensics.
  3. Document each materiality assessment contemporaneously — the record of decisions not to file is what the SEC requests in investigations.
  4. Draft the Item 1.05 8-K to state what is known, flag the investigation, and amend on Item 1.05(a) material developments without turning each development into a new incident.
  5. Align insider-trading controls: a blackout should descend on incident knowledge the moment materiality is plausible, before the determination itself.

What do the annual disclosure requirements add?

Item 106 of Regulation S-K, effective for fiscal years ending on or after December 15, 2023, requires describing processes for assessing, identifying and managing material cyber risks, whether and how the board and its committees oversee them, and management's role and expertise. Companies without a CISO describe the function nonetheless — the rule requires disclosure of management positions responsible. The SEC emphasized that boilerplate risk factors fail the requirement: disclosures must be specific to the company's actual risks and processes. Enforcement has not yet tested Item 106 alone, but plaintiff firms read annual cyber disclosures as a standard against which incident facts are later measured.

How does the rule interact with litigation and state law?

The Item 1.05 filing is discoverable and quoted in follow-on securities class actions, which through 2025 have been filed within days of major filings and mostly dismissed at the pleading stage absent downplaying or trading. State breach-notification statutes run on separate clocks keyed to affected residents, typically 30-60 days, and cover nonpublic companies — the 8-K regime does not displace them. Ransomware presents the sharpest convergence: paying or refusing, the extortion demand itself figures in materiality, and disclosure of "reasonably likely" impact is permitted to include projected costs the company can support.

Is the rule changing?

Only at the margins. A petition for review challenged the four-day window as impractical; the court upheld the rule in 2025. The SEC's own retrospective statements have suggested openness to clarifying when repeated amendments are required, and commenters have asked whether private companies will be pulled in through a future rulemaking, but as of early 2026 the December 2023 framework stands. Boards should treat the four-day window as fixed law and invest in what it actually demands: a documented, fast, and honest materiality process.

Frequently Asked Questions

When must a public company disclose a cyber incident?
Within four business days of determining the incident is material, on Form 8-K Item 1.05 — the clock runs from the materiality determination, made without unreasonable delay, not from discovery.
What must the Item 1.05 disclosure contain?
The incident's nature, scope, timing, and its material impact — or reasonably likely material impact — on financial condition and operations; unknown elements may be flagged for later amendment.
Has the SEC enforced the cyber disclosure rule?
Yes. Actions since 2023 have penalized delayed determinations, understated descriptions of intrusions, and misleading pre-incident security statements, including the SolarWinds settlement resolved in 2025.
Do private companies have to file Item 1.05?
No. The rule applies to public registrants; private companies remain governed by state breach-notification statutes and contractual obligations.