Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
For U.S. public companies, the SEC’s central incident-disclosure deadline is generally four business days after the company determines a cybersecurity incident is material—not four days after the incident is discovered. The company must make that materiality determination without unreasonable delay. For a CISO, the practical task is to get timely, credible technical and business-impact facts to the executives and advisers responsible for the decision.
The rules also require annual disclosures about cybersecurity risk management, strategy and governance. They do not make every breach reportable, establish a universal dollar threshold, or ask the CISO to decide securities-law materiality alone.
Who the SEC rules cover
The SEC’s cybersecurity disclosure rules principally apply to domestic companies that are registrants subject to Exchange Act reporting requirements, including business development companies. They are not a general breach-notification law for every U.S. business. Private companies, subsidiaries and suppliers may have separate obligations under state breach-notification laws, sector-specific rules, contracts or other regulatory requirements.
Foreign private issuers have different filing mechanics: annual cybersecurity disclosures generally appear in Form 20-F, while current-incident disclosure generally uses Form 6-K when the event has been disclosed or publicized in the circumstances specified by the rule. Confirm the requirements for the issuer’s status and filing circumstances with securities counsel.
#1 Best Overall
The SEC’s compliance guide summarizes the covered filers and the distinction between current-incident and annual disclosures.
The two parts of the disclosure regime
- Current incidents: A domestic registrant generally files Form 8-K, Item 1.05, within four business days after determining that a cybersecurity incident is material.
- Annual disclosure: Regulation S-K Item 106 requires domestic registrants to describe specified cybersecurity risk-management, strategy and governance matters in Form 10-K.
The SEC adopted the rules in 2023; the final rule sets out their requirements. A petition seeking changes to the current-incident requirements was filed in 2025, but a petition is not a repeal. As of September 23, 2026, this article describes the requirements in the rule; check the SEC’s current materials and counsel for any later change before relying on them.
What counts as a cybersecurity incident?
The rule uses a broad definition: an unauthorized occurrence, or series of related unauthorized occurrences, on or through information systems that jeopardizes the confidentiality, integrity or availability of information or systems. The relevant question is not limited to whether personal information was stolen.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Potentially relevant events include ransomware and extortion, destructive attacks, theft of sensitive information or intellectual property, material outages, compromise of production or transaction systems, and incidents at cloud, identity or managed-service providers. A vendor incident can matter to the registrant if it affects the company’s operations, data, customers or financial outlook. Several related incidents may also matter in aggregate.
Track operational disruption and integrity or availability failures as carefully as confirmed exfiltration. Lost production, recovery costs, customer or supplier effects, legal exposure, remediation burden and plausible future consequences can all inform the company’s assessment.
Materiality is an investor question, not a severity rating
The SEC did not set a cyber-specific dollar threshold. Traditional securities-law materiality asks whether there is a substantial likelihood that a reasonable investor would consider the information important, or whether it would significantly alter the total mix of information available. A technical severity label can inform the analysis, but it does not answer it.
Assess actual effects and reasonably likely future effects, including:
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall- Revenue interruption, lost production or effects on financial condition and results of operations.
- Disruption to customers, suppliers, markets or critical business services.
- Loss, exposure or corruption of sensitive data or strategically important intellectual property.
- Safety, business-continuity, regulatory, litigation, contractual or compliance consequences.
- Investigation, restoration, notification, legal, public-relations and remediation costs.
- Whether the incident changes the company’s risk profile, outlook or statements already made to investors.
- Whether related incidents, a campaign or a common root cause change the cumulative impact.
Do not treat unconfirmed data theft as proof an outage is immaterial, or the absence of an immediate outage as proof a data theft is immaterial. An outage may have substantial business effects without confirmed exfiltration; stolen data may create significant future legal, regulatory or strategic consequences before a direct revenue loss is known.
When the four-business-day clock starts
The Item 1.05 clock starts when the registrant determines that the incident is material. It does not automatically start at initial detection, when the response team declares a high severity, when a ransom note appears, or when counsel is retained. Nor does it wait for a completed forensic investigation, a final loss calculation or certainty about every affected system and person.
The company must make the materiality determination without unreasonable delay. That means an open-ended investigation cannot serve as a reason to postpone the decision indefinitely. It also does not mean that every technical alert automatically starts a filing deadline. The company needs an orderly, prompt process that brings decision-makers the available facts and updates them as those facts develop.
Rank #3
- Detect and classify: Preserve evidence, contain the event as appropriate and establish an initial chronology.
- Escalate promptly: Bring potential investor impact to legal, finance and executive decision-makers while the technical response continues.
- Assess materiality: Evaluate known facts, reasonable estimates, uncertainty and likely consequences; document the decision and its basis.
- Calculate the filing date: If the incident is determined to be material, count four business days from that determination and coordinate the Form 8-K with securities counsel.
- Continue reassessing: New facts may change the company’s understanding, disclosure or public statements.
The SEC’s small-entity compliance guide explains the trigger and deadline. The practical lesson is to run technical response and disclosure analysis in parallel, not to wait for one to finish before starting the other.
What an Item 1.05 filing must say
The filing describes the material aspects of the incident’s nature, scope and timing, along with its material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations. That is an investor-facing account of what happened and why it matters—not an incident-response manual.
A useful fact package should separate:
- Confirmed facts: What systems, information or business functions are known to be affected, and when the event began or was detected, if known.
- Preliminary findings: What current evidence indicates, with the basis and confidence level stated internally.
- Unknowns: What remains under investigation and why it is not yet possible to quantify or confirm.
- Business effects: Operational disruption, financial effects and material consequences that are reasonably likely, even if estimates remain preliminary.
- Response status: Material facts about containment and recovery as relevant to understanding the impact.
“The investigation is ongoing” may be accurate, but it is not a substitute for disclosing material aspects known at filing time. Avoid false precision: describe what is known, what is estimated and what remains unresolved. Sensitive details—such as credentials, exploitable indicators, precise network architecture, defensive gaps or unpatched vulnerabilities—should not be volunteered in a way that materially impedes response or remediation. The SEC says the rule does not require technical details at that level. See the final rule and compliance guide.
Special cases that commonly create confusion
Ransomware, payment and restoration
A ransom payment, restored systems, returned data or apparent end to an attack does not erase a material incident. The SEC’s Form 8-K guidance addresses ransomware: when a registrant determines the incident is material, later payment or restoration does not remove the obligation to make the determination or file as required. Include the payment, recovery costs, residual compromise and continuing extortion exposure in the impact assessment where relevant.
Third-party incidents
Do not assume the vendor owns the disclosure question. Assess effects on the registrant: its operations, data, customers, financial condition and reasonably likely future impact. Coordinate promptly with the provider, but do not make the company’s assessment depend on receiving a perfectly complete vendor report.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsVoluntary Item 8.01 disclosure
A company may make a voluntary Form 8-K Item 8.01 disclosure before completing its materiality determination. That filing does not replace the determination. If the company later determines the incident is material, it still must make the Item 1.05 filing. The SEC staff explains this in its May 2024 statement.
Law-enforcement coordination
Calling or cooperating with the FBI, CISA or another agency does not automatically pause the SEC deadline. The rule’s limited delay mechanism requires a U.S. Attorney General determination that immediate disclosure would pose a substantial risk to national security or public safety, with written notice to the SEC. The rule provides specified delay periods and conditions, including for extraordinary circumstances. Treat this as a formal process to coordinate through counsel, not as an extension the company can grant itself. See the final rule.
Related events and changing facts
Evaluate a campaign, recurring compromise or series of related events in context rather than treating each alert as isolated. If a preliminary assessment was that an incident was not material, establish reassessment triggers. Examples include evidence of exfiltration, a longer outage, higher recovery costs, broader customer or supplier impact, a regulatory inquiry, litigation, strategic data exposure or discovery of related activity. Reassess as facts change and coordinate any additional filing or public communication with counsel.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the CISO should provide—and who decides
The CISO should own the quality and speed of the security fact record, not independently make the company’s securities-law materiality decision. A practical division of responsibility looks like this:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
| Role | Primary contribution |
|---|---|
| CISO and security team | Detection, technical scope and chronology, evidence preservation, confidence levels, unknowns, containment and recovery status, attack-path assessment, business-service effects and remediation risks. |
| General counsel and securities counsel | Legal analysis, materiality process, filing requirements and wording, coordination of legal advice and any formal delay process. |
| CFO, finance and controllership | Cost estimates, financial-statement implications, effects on financial condition or results of operations, and reasonable future-impact estimates. |
| Disclosure committee, corporate secretary and executives | Cross-functional review, decision record, filing approval, public-company disclosure coordination and investor-relations alignment. |
| Board or designated committee | Oversight and appropriate escalation—not management of the forensic investigation or drafting of technical incident language. |
The CISO’s report should translate technical findings into operational and investor-relevant terms. Instead of supplying only “severity one” or a list of affected hosts, state which business service was interrupted, for how long, which customers or processes may be affected, what evidence supports the estimate and what remains uncertain.
Best Value
Annual Form 10-K disclosure: make governance match practice
Regulation S-K Item 106 requires domestic registrants to disclose their processes for assessing, identifying and managing material cybersecurity risks; whether risks from cybersecurity threats have materially affected or are reasonably likely to materially affect business strategy, results of operations or financial condition; and the board’s oversight and management’s role in cybersecurity risk.
That can make operational evidence important at reporting time: management responsibilities and reporting lines, how risk reaches executives and directors, board or committee oversight, relevant expertise, escalation practices and reliance on outside providers. The rule does not require naming a particular executive by title, and it does not require disclosure of sensitive information where doing so would materially harm security. Annual statements should be grounded in actual practices and consistent with other company disclosures, not treated as generic boilerplate.
The cybersecurity disclosures must be provided using Inline XBRL. Foreign private issuers generally address comparable annual disclosure in Form 20-F. See the SEC’s final rule.
Build the process before an incident
A written disclosure protocol reduces the chance that technical response, legal review and business-impact analysis begin on different timelines. At minimum, establish:
- Escalation criteria: Identify events that require immediate legal and executive notification, critical business services, sensitive data and high-impact third parties.
- A decision group: Name the CISO, general counsel or securities counsel, CFO or controller, corporate secretary, investor relations, CEO or COO, communications and privacy contacts, and relevant board liaison.
- A shared impact dashboard: Track affected systems, duration and geographic scope; revenue processes, customers and suppliers affected; data categories; restoration status; direct and indirect costs; legal exposure; future effects; and evidence confidence.
- A timestamped chronology: Record first detection, escalation, scope and business-impact updates, materiality discussions, decision-makers, decisions, deadline calculations and law-enforcement communications.
- A disclosure-ready fact template: Capture what happened, when, what was affected, what remains unknown, which functions were disrupted, the actual or likely financial effect, response status and unresolved future risks.
- Rehearsed workflows: Test how technical facts reach counsel and finance, who convenes a materiality discussion, how the filing date is calculated, and how board and investor-relations communications are coordinated.
After filing, continue monitoring whether new facts materially change the original disclosure. Keep subsequent Form 10-K, earnings, risk-factor, MD&A and other public statements consistent. Preserve the decision record and review detection-to-escalation time, the quality of business-impact estimates and the effectiveness of the governance process.
Tools for incident response, GRC, evidence management and board reporting can help preserve timestamps, route approvals and assemble facts. They cannot decide legal materiality or guarantee compliance; that remains a company-level responsibility.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

