DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Study Finds 60% Increase in Cybersecurity Disclosures to the SEC

Paul Hastings reported a 60% rise in disclosed cyber incidents in a sample of 75 filings from 48 public companies. The study also examined filing timing, impact detail and repeat disclosures.
From TheFinanceBase Team3 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Paul Hastings found a 60% increase in publicly disclosed cybersecurity incidents after the SEC’s new disclosure rules took effect. Its December 2024 analysis covered 75 disclosures from 48 public companies, for incidents disclosed between December 18, 2023, and October 31, 2024. The figure describes that defined sample; it is not a count through 2026, and it does not show that the rule alone caused the increase.

What Paul Hastings found

The law firm’s SEC Cybersecurity Incident Disclosure Report, published December 18, 2024, examined disclosures by public companies during the first period covered by the SEC’s new rules. Its findings describe what appeared in those filings, not every cyber incident affecting public companies.

Finding What the report observed
Disclosed incidents 60% increase since the rules became effective, as reported by Paul Hastings in 2024. The report analyzed 75 disclosures from 48 companies through October 31, 2024.
Time to disclosure 78% of disclosures were made within eight days of discovery, including 32% within four days of discovery, according to Paul Hastings’ 2024 sample.
Material impact detail Fewer than 10% of disclosures specified the incident’s material impact, according to Paul Hastings’ 2024 sample.
Repeat filings 42% of companies filed more than one disclosure for the same incident, typically by updating a Form 8-K, according to Paul Hastings’ 2024 sample.
Third-party incidents One in four disclosed incidents stemmed from a third-party incident, according to Paul Hastings’ 2024 sample.
Law enforcement and supplemental detail 75% of disclosed incidents referenced law-enforcement notification; 13% provided further details in an exhibit press release or a referenced blog, according to Paul Hastings’ 2024 sample.

The 60% figure is a comparison reported by the firm, not a causal estimate. The study does not establish how much of the increase, if any, resulted from the rule rather than other factors.

When does the SEC’s four-business-day deadline start?

For a covered domestic registrant, Form 8-K Item 1.05 is generally due within four business days after the company determines that a cybersecurity incident is material. The clock does not automatically start on the day the incident happened or was discovered. A company must assess materiality without unreasonable delay after discovery. The SEC’s small-entity compliance guide explains the trigger and filing framework.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report’s timing statistic and the rule’s deadline therefore measure different intervals: Paul Hastings counted time from discovery, while the SEC deadline runs from the materiality determination. The 78% filed within eight days finding is not a measure of compliance with the four-business-day deadline.

In May 2024, SEC staff clarified that companies may voluntarily disclose an incident not determined to be material, or whose materiality has not yet been determined, under another Form 8-K item such as Item 8.01. If the company later determines the incident is material, it should file an Item 1.05 Form 8-K within four business days of that determination. See the SEC Division of Corporation Finance guidance.

What must a material-incident filing say?

Item 1.05 calls for disclosure of material aspects of the incident’s nature, scope and timing, as well as its material or reasonably likely material impact on the registrant. The SEC rule does not require technical details about response plans or systems at a level that would impede remediation. The SEC describes the rule in its July 26, 2023 adoption announcement.

Paul Hastings’ finding that fewer than 10% of sampled disclosures specified material impact raises a question about the detail investors received, but it does not by itself prove that companies uniformly failed to comply. The rule requires investor-relevant impact disclosure while allowing companies to protect technical information that could hinder remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Materiality is an investor-focused judgment

Materiality can involve both quantitative and qualitative consequences. The report discusses immediate and longer-term operational effects, customer relationships, financial impact, reputation or brand perception, and potential litigation or regulatory action. A resolved incident or ransomware payment does not automatically remove the need to assess materiality; the payment amount alone does not determine the answer.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the findings matter to investors

The sample puts two parts of early incident reporting in contrast: many companies disclosed relatively soon after discovery, while few filings specified material impact. That distinction matters because investors need to understand potential effects on the business, not merely that an incident occurred. The report also found repeat filings for the same incident and a substantial share involving third parties, illustrating that disclosures can evolve and that a company’s systems are not the only source of exposure.

The results are a bounded snapshot of filings through October 31, 2024. They can show what Paul Hastings observed in that sample, but they should not be read as a complete measure of all incidents, a current 2026 trend, or proof that every incident must be reported under Item 1.05.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.