The SEC's cybersecurity rules did two things: they put incident disclosure on a short clock, and they made security governance an annual disclosure item. The first gets the attention. The second is what quietly changed how boards engage with security at US-listed companies - and at foreign private issuers, which have comparable obligations.
Incident disclosure and the materiality trigger
A registrant must report a material cybersecurity incident on a current report - Item 1.05 of Form 8-K - within four business days. The critical detail:
The four business days run from the determination that the incident is material, not from discovery of the incident. But that determination must be made "without unreasonable delay" - so you cannot extend the window by simply not deciding.
This creates the obligation that actually matters: you need a defined, documented process that reaches a materiality determination promptly, with named decision-makers and evidence of when they decided and on what basis. An organisation that discovers an incident and takes three weeks to convene a materiality discussion has a problem regardless of what it eventually files.
Disclosure must describe the nature, scope and timing of the incident and its material impact or reasonably likely material impact. It does not require technical detail that would impede response - and the SEC has been explicit that companies should not disclose specific vulnerabilities or remediation detail that would aid an attacker. Where information is unknown at filing, you file what you have and amend.
A limited delay is available where the US Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety. It is narrow and rarely applicable; do not build a plan around it.
Materiality is not severity
This is the most common misunderstanding among security teams. Materiality is a securities-law concept: would a reasonable investor consider the information important in making an investment decision? That is not the same as technical severity or record count.
Consequences to plan for:
- Qualitative factors count - reputational harm, customer relationships, litigation exposure, competitive impact - not only quantified loss.
- A technically modest incident can be material if it affects a flagship product or a major customer relationship.
- A large-sounding incident may not be if the practical impact is contained.
- Aggregation matters. Related incidents that are individually immaterial can be material collectively - which requires you to track them as a series rather than closing each ticket in isolation.
- Security does not decide. Materiality is a determination for disclosure counsel and the disclosure committee, informed by security. Get that boundary agreed before an incident, not during one.
Give the board something defensible to review
GRC Copilot maintains current control posture, risk and incident records with an audit trail - the evidence base a disclosure committee and board committee need to act quickly.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Annual governance disclosure
In the annual report, registrants describe their processes for assessing, identifying and managing material cybersecurity risks, whether those risks have materially affected or are reasonably likely to materially affect the business, and their governance arrangements - board oversight and the role and expertise of management.
This is a public, written description of your security programme, filed under securities liability. Two effects follow, and both are healthy:
- It must be accurate. Describing a risk assessment process you do not actually run is a misstatement in a filing, which is a materially worse category of problem than an audit finding.
- It is comparable. Analysts, customers and adversaries read these across peer companies. Thin governance disclosure now stands out.
Note that the SEC declined to require board cyber expertise disclosure in the final rule - but describing how the board exercises oversight, at what cadence, and through which committee is required. "The board receives an annual update" is a disclosure that invites questions.
Preparing before you need it
- Write the materiality process - triggers that convene the assessment, who participates, how the decision and its timing are recorded.
- Connect incident response to disclosure. The security team must know which incidents to escalate to counsel, and the threshold must be low enough to be useful.
- Run a disclosure tabletop with legal, finance, communications, investor relations and security together. Most organisations have exercised the technical response and never the filing decision.
- Establish the board cadence and minute it - the minutes are the evidence supporting your governance disclosure.
- Track related incidents so aggregation is possible.
- Extend to third parties. An incident at a service provider can be material to you, so contractual notification timelines must be short enough to leave you room to assess and file.
Frequently asked questions
Does this apply to non-US companies?
Foreign private issuers listed in the US have comparable incident and annual disclosure obligations through their own forms. Private companies are out of scope - though acquirers and investors increasingly ask the same questions.
What if we do not know the full impact within four days?
File based on what is known, state what remains under investigation, and amend as facts develop. Delay is not an option; incompleteness, disclosed as such, is expected.
Can we avoid the clock by not determining materiality?
No. The determination must be made without unreasonable delay, and an absent or slow process is itself exposure.
Who should own the materiality call?
Disclosure counsel and the disclosure committee, with security providing facts. Agree this in advance - an incident is a poor time to discover the decision rights are unclear.
Key takeaways
- Four business days run from the materiality determination, which must not be unreasonably delayed.
- Materiality is an investor-relevance test, not a technical severity rating - and security does not decide it.
- Annual governance disclosure is a public description of your programme filed under securities liability.
- Exercise the disclosure decision, not just the technical response.