Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Paul Hastings found a 60% increase in publicly disclosed cybersecurity incidents after the SEC’s new disclosure rules took effect. Its December 2024 analysis covered 75 disclosures from 48 public companies, for incidents disclosed between December 18, 2023, and October 31, 2024. The figure describes that defined sample; it is not a count through 2026, and it does not show that the rule alone caused the increase.
What Paul Hastings found
The law firm’s SEC Cybersecurity Incident Disclosure Report, published December 18, 2024, examined disclosures by public companies during the first period covered by the SEC’s new rules. Its findings describe what appeared in those filings, not every cyber incident affecting public companies.
| Finding | What the report observed |
|---|---|
| Disclosed incidents | 60% increase since the rules became effective, as reported by Paul Hastings in 2024. The report analyzed 75 disclosures from 48 companies through October 31, 2024. |
| Time to disclosure | 78% of disclosures were made within eight days of discovery, including 32% within four days of discovery, according to Paul Hastings’ 2024 sample. |
| Material impact detail | Fewer than 10% of disclosures specified the incident’s material impact, according to Paul Hastings’ 2024 sample. |
| Repeat filings | 42% of companies filed more than one disclosure for the same incident, typically by updating a Form 8-K, according to Paul Hastings’ 2024 sample. |
| Third-party incidents | One in four disclosed incidents stemmed from a third-party incident, according to Paul Hastings’ 2024 sample. |
| Law enforcement and supplemental detail | 75% of disclosed incidents referenced law-enforcement notification; 13% provided further details in an exhibit press release or a referenced blog, according to Paul Hastings’ 2024 sample. |
The 60% figure is a comparison reported by the firm, not a causal estimate. The study does not establish how much of the increase, if any, resulted from the rule rather than other factors.
When does the SEC’s four-business-day deadline start?
For a covered domestic registrant, Form 8-K Item 1.05 is generally due within four business days after the company determines that a cybersecurity incident is material. The clock does not automatically start on the day the incident happened or was discovered. A company must assess materiality without unreasonable delay after discovery. The SEC’s small-entity compliance guide explains the trigger and filing framework.
#1 Best Overall
The report’s timing statistic and the rule’s deadline therefore measure different intervals: Paul Hastings counted time from discovery, while the SEC deadline runs from the materiality determination. The 78% filed within eight days finding is not a measure of compliance with the four-business-day deadline.
In May 2024, SEC staff clarified that companies may voluntarily disclose an incident not determined to be material, or whose materiality has not yet been determined, under another Form 8-K item such as Item 8.01. If the company later determines the incident is material, it should file an Item 1.05 Form 8-K within four business days of that determination. See the SEC Division of Corporation Finance guidance.
What must a material-incident filing say?
Item 1.05 calls for disclosure of material aspects of the incident’s nature, scope and timing, as well as its material or reasonably likely material impact on the registrant. The SEC rule does not require technical details about response plans or systems at a level that would impede remediation. The SEC describes the rule in its July 26, 2023 adoption announcement.
Paul Hastings’ finding that fewer than 10% of sampled disclosures specified material impact raises a question about the detail investors received, but it does not by itself prove that companies uniformly failed to comply. The rule requires investor-relevant impact disclosure while allowing companies to protect technical information that could hinder remediation.
Rank #3
Materiality is an investor-focused judgment
Materiality can involve both quantitative and qualitative consequences. The report discusses immediate and longer-term operational effects, customer relationships, financial impact, reputation or brand perception, and potential litigation or regulatory action. A resolved incident or ransomware payment does not automatically remove the need to assess materiality; the payment amount alone does not determine the answer.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the findings matter to investors
The sample puts two parts of early incident reporting in contrast: many companies disclosed relatively soon after discovery, while few filings specified material impact. That distinction matters because investors need to understand potential effects on the business, not merely that an incident occurred. The report also found repeat filings for the same incident and a substantial share involving third parties, illustrating that disclosures can evolve and that a company’s systems are not the only source of exposure.
Rank #4
The results are a bounded snapshot of filings through October 31, 2024. They can show what Paul Hastings observed in that sample, but they should not be read as a complete measure of all incidents, a current 2026 trend, or proof that every incident must be reported under Item 1.05.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools




