The SEC cybersecurity disclosure rules require public companies to report a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining it is material, and to describe cybersecurity risk management, strategy and governance annually under Regulation S-K Item 106 (Form 10-K Item 1C). The clock runs from the materiality determination, made without unreasonable delay.
Two obligations, one rule
The SEC adopted the rules on July 26, 2023 (Release No. 33-11216), published at 88 Fed. Reg. 51896, effective September 5, 2023. They create two distinct duties that are routinely conflated.
Incident disclosure — Form 8-K Item 1.05. If a company experiences a cybersecurity incident it determines to be material, it must describe the material aspects of the incident's nature, scope and timing, and its material impact or reasonably likely material impact, including on financial condition and results of operations. The filing is due within four business days after the company determines the incident is material.
Periodic disclosure — Regulation S-K Item 106. Each Form 10-K carries a new Item 1C describing the company's processes, if any, for assessing, identifying and managing material risks from cybersecurity threats; whether such risks, including from prior incidents, have materially affected or are reasonably likely to materially affect it; the board's oversight; and management's role and expertise. Item 106(b)(1) specifically asks whether the company has processes to oversee cybersecurity risks associated with its use of any third-party service provider.
The second obligation is where a company's own words become evidence about the first: a description of controls the internal record does not support is the gap regulators and plaintiffs look for, and it is what the SolarWinds litigation below was about.
Which filing, when
| Situation | Form and item | Deadline |
|---|---|---|
| Incident determined to be material (domestic filer) | Form 8-K, Item 1.05 | Four business days after the materiality determination |
| Required Item 1.05 information not yet determined or unavailable | Form 8-K/A under Item 1.05 | Four business days after it is determined or becomes available (Instruction 2) |
| Incident not yet assessed, or determined immaterial, that the company chooses to disclose | Form 8-K, Item 8.01 (Other Events) | Voluntary; an Item 1.05 filing follows within four business days if it later becomes material |
| Attorney General finds disclosure poses a substantial risk to national security or public safety | Item 1.05, delayed | Up to 30 days, an additional 30 days, and in extraordinary circumstances a final 60 days; beyond that only by Commission exemptive order |
| Foreign private issuer, material incident | Form 6-K | Promptly, once the incident is disclosed in a foreign jurisdiction, to an exchange or to security holders |
| Foreign private issuer, annual disclosure | Form 20-F, Item 16K | With the annual report (annual reports only, not registration statements) |
| Annual risk management, strategy and governance (domestic filer) | Form 10-K, Item 1C (Regulation S-K Item 106) | Fiscal years ending on or after December 15, 2023 |
Compliance with Item 1.05 began December 18, 2023 for most registrants; smaller reporting companies were given until June 15, 2024.
The determination clock is the hard part
The four business days run from the materiality determination, and Instruction 1 to Item 1.05 requires that determination to be made "without unreasonable delay after discovery of the incident." A company cannot extend the deadline by declining to decide.
This creates real pressure, because materiality frequently depends on facts the forensic investigation has not yet established — principally what data was taken and whose. The rule anticipates that: Instruction 2 lets a company file with a statement that required information is not yet determined or unavailable, then amend within four business days of learning it. What it does not permit is waiting for the investigation to finish before deciding.
The Division of Corporation Finance addressed the opposite problem in May 2024. Because an Item 1.05 filing signals a conclusion that the incident is material, the Division encourages companies disclosing an unassessed or immaterial incident to use a different item, such as Item 8.01 — otherwise "there is a risk that investors will misperceive immaterial cybersecurity incidents as material, and vice versa."
What the materiality determination needs from the forensic investigation in the first four business days
The determination is a judgment for counsel and the board, but it is made on facts only the examination can supply. The disclosure committee needs answers, or documented non-answers, to five questions within the first days:
- Scope of access. Which systems, accounts and environments the intruder reached, and whether the evidence supports a boundary. "We have found no evidence of" is a very different finding from "the logs needed to answer this do not exist."
- Exfiltration. Whether data left the environment, in what volume, and of what kind. Confirmed outbound transfer, staged archives and a known exfiltration tool each carry different weight; missing egress logging is itself a fact the determination must account for.
- Systems affected and their business function. Materiality turns on impact, so the inventory of affected hosts has to be mapped to what those hosts do — production, finance, customer data, source code.
- Containment status. Whether the intruder's access has been cut off and how that is known. An unresolved intrusion changes both the impact analysis and what Instruction 4 lets the company withhold.
- Timing. First evidence of compromise, first detection, and the interval between — the interval is what a regulator later tests against "without unreasonable delay."
The document that supports the determination afterwards is a written, contemporaneous forensic timeline: dated entries recording what was examined, what was found, and what could not be established and why, built from preserved forensic images and logs held under chain of custody. A determination reached on Tuesday is defended years later by showing what was known on Tuesday; without that record, the company is reconstructing its own knowledge from memory, which is where hindsight arguments are lost.
What Item 1.05 does not require
- Technical detail. Instruction 4 states that a registrant need not disclose "specific or technical information about its planned response to the incident or its cybersecurity systems, related networks and devices, or potential system vulnerabilities in such detail as would impede the registrant's response or remediation of the incident."
- A fraud finding for a late filing. Exchange Act Rules 13a-11(c) and 15d-11(c) provide that a failure to file a report required solely under Item 1.05 is not by itself deemed a violation of Section 10(b) and Rule 10b-5, and Form S-3 eligibility survives an untimely Item 1.05 report.
- A cyber-specific materiality test. The standard is the ordinary securities one: whether a reasonable investor would consider it important. The Division's May 2024 statement stresses qualitative factors alongside quantitative ones — harm to reputation, customer or vendor relationships or competitiveness, and the possibility of litigation or regulatory action.
Enforcement posture
SEC v. SolarWinds Corp. The SEC sued SolarWinds and its CISO in the Southern District of New York on October 30, 2023 over the company's statements about its cybersecurity practices before and after the December 2020 SUNBURST attack. On July 18, 2024, Judge Engelmayer granted the motion to dismiss "in large part": the securities-fraud claims based on the company's website Security Statement survived as "viably pled as materially false and misleading in numerous respects," while the claims based on other statements and filings, all claims about the post-SUNBURST Form 8-K disclosures (which "impermissibly rely on hindsight and speculation") and the internal accounting-controls and disclosure-controls claims were dismissed. The court noted the 2023 rules were not implicated because the conduct predated them. On November 20, 2025, the parties filed a joint stipulation dismissing the action with prejudice, which the Commission described as an exercise of its discretion that "does not necessarily reflect the Commission's position on any other case."
The four SolarWinds-customer settlements. On October 22, 2024, the SEC announced settled cease-and-desist orders against Unisys ($4 million), Avaya ($1 million), Check Point ($995,000) and Mimecast ($990,000) over their disclosures about intrusions connected to the SolarWinds compromise — alleging, for example, that Unisys described cybersecurity risks as hypothetical after two intrusions involving exfiltration of gigabytes of data, and that Avaya reported access to a "limited number" of emails when it knew at least 145 files in its cloud file-sharing environment had also been accessed. Each settled without admitting or denying the findings. Commissioners Peirce and Uyeda dissented from all four, objecting to hindsight review and reliance on immaterial details.
The tension with the investigation
Disclosing details of an ongoing incident can compromise the response, which is why the rule asks for nature, scope, timing and impact rather than technical specifics. There is a related conflict with trade secret protection: describing what was taken can reveal what the company treated as valuable. Both are easier to manage when the incident response team and the disclosure team have worked from the same timeline since day one.
Law & Forensics provides cybersecurity expert witness services for matters where SEC cyber disclosure rules is at issue.
From our work
Primary sources
- SEC Cybersecurity Disclosure Rules, 88 Fed. Reg. 51896 (2023)
- Regulation S-K Item 106, 17 C.F.R. § 229.106
- SEC Release No. 33-11216, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (adopting release, July 26, 2023)
- SEC Fact Sheet: Public Company Cybersecurity Disclosures; Final Rules
- SEC Small Entity Compliance Guide: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
- 17 C.F.R. § 229.106 (Item 106) — Cornell LII
- Erik Gerding, Disclosure of Cybersecurity Incidents Determined To Be Material and Other Cybersecurity Incidents (SEC Division of Corporation Finance, May 21, 2024)
- SEC Press Release 2023-227, SEC Charges SolarWinds and Chief Information Security Officer (Oct. 30, 2023)
- SEC v. SolarWinds Corp., No. 1:23-cv-09518-PAE, Opinion & Order (S.D.N.Y. July 18, 2024), ECF No. 125
- SEC Litigation Release No. 26423, SolarWinds Corp. and Timothy G. Brown (Nov. 20, 2025)
- SEC Press Release 2024-174, SEC Charges Four Companies With Misleading Cyber Disclosures (Oct. 22, 2024)
- Commissioners Peirce and Uyeda, Statement Regarding Administrative Proceedings Against SolarWinds Customers (Oct. 22, 2024)
Dealing with sec cyber disclosure rules in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
