Skip to content

Glossary · Privacy & regulation

SEC cyber disclosure rules

Also called: Item 1.05, Form 8-K cyber disclosure, SEC cybersecurity rules

SEC rules require public companies to disclose material cybersecurity incidents on Form 8-K, generally within four business days of determining materiality, and to describe their risk management, strategy and governance annually. The clock runs from the materiality determination, not from discovery — and unreasonable delay in reaching it is itself exposure.

Two obligations, frequently conflated

Incident disclosure. A material cybersecurity incident is reported on Form 8-K, describing its nature, scope and timing and the material impact or reasonably likely material impact. The filing is generally due within four business days of determining that the incident is material.

Periodic disclosure. Annual reporting on processes for assessing, identifying and managing cybersecurity risk, plus board oversight and management's role. This is a standing description of governance rather than an event report.

The second is where a company's own words become evidence in litigation about the first. A description of controls that the internal record does not support is the gap plaintiffs and regulators look for.

The determination clock is the hard part

The four business days run from the materiality determination, and the rules require that determination to be made without unreasonable delay. So a company cannot extend the deadline by declining to decide.

This creates real pressure, because materiality frequently depends on facts the forensic investigation has not yet established — principally what data was taken and whose. A company is expected to reach a defensible judgment on incomplete information, and to document the reasoning.

The practical implication is that the disclosure analysis has to run in parallel with the investigation from the first day, not sequentially after it. Organisations that sequence it discover the deadline has already engaged.

Materiality here is the ordinary securities standard

Not a cyber-specific test: whether a reasonable investor would consider it important. That takes in more than remediation cost — operational disruption, customer and contractual consequences, reputational effect, litigation and regulatory exposure, and the nature of the data involved.

Quantitative impact alone is a poor proxy. An incident with modest direct cost can be material because of what it reveals about a company's controls or because of the data it exposed.

The national-security delay

Disclosure may be delayed where the Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety. It is a narrow route with a specific process, and it is not a general extension available because the investigation is incomplete.

The tension with the investigation

Disclosing details of an ongoing incident can compromise the response and can expose vulnerabilities the company has not yet closed — which is why the rules call for the nature, scope and timing and the material impact, rather than technical specifics. Companies are not required to publish a roadmap of their weaknesses.

There is a related and underappreciated conflict with trade secret protection: describing what was taken can itself reveal what the company treated as valuable and confidential. That is a drafting problem worth working through with counsel before the filing rather than after.

From our work

Dealing with sec cyber disclosure rules in a live matter?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.