DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Why CISOs and Companies Struggle With SEC Cybersecurity Disclosure Rules

The SEC generally gives public companies four business days after a materiality determination to report a material cyber incident. The hard part is making that decision promptly and explaining business impact while facts are still developing.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Public companies generally must file a Form 8-K Item 1.05 within four business days after determining that a cybersecurity incident is material—not automatically four days after discovering it. The materiality decision itself must be made without unreasonable delay. That leaves companies with a difficult task: quickly turn an incomplete technical investigation into a documented assessment of business impact and a useful public disclosure.

What the SEC cybersecurity rules require

The SEC adopted its cybersecurity disclosure rules on July 26, 2023. Most registrants began complying with the incident-reporting requirement on December 18, 2023. The rules have two main parts:

  • Form 8-K Item 1.05: A current report about a cybersecurity incident the registrant determines is material.
  • Regulation S-K Item 106: Periodic disclosures about the company’s cybersecurity risk-management processes, strategy and governance.

These obligations serve different purposes. Item 1.05 addresses a particular material incident; Item 106 describes the company’s broader approach to cybersecurity risks and oversight.

When the four-business-day clock starts

The filing deadline is generally four business days after the company determines that an incident is material. Discovery starts the internal assessment, but it does not by itself start that four-business-day filing period. The company must make its materiality determination without unreasonable delay after discovering the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Stage What the rule requires
Incident discovered Begin assessing the incident and its potential effects. Discovery alone does not start the four-business-day filing period.
Materiality determination Make the decision without unreasonable delay; record when and how it was reached.
Materiality confirmed Generally file Item 1.05 within four business days of the determination.
New material facts emerge Information unavailable for the initial filing may require an amended Form 8-K when it becomes known.

The SEC provides a limited delay if the Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety. It is not a general extension for a company that needs more time to investigate or coordinate internally.

Who decides whether an incident is material?

The registrant is responsible for the determination; the rule does not make the CISO the sole decision-maker. The CISO and technical teams may have the earliest access to incident facts, but assessing their significance to the company calls for input from people who understand operations, finances, legal obligations and disclosure practices.

SEC Corporation Finance Director Erik Gerding recommended conversations among CISOs, other cybersecurity experts and technologists, the disclosure committee, and securities-law advisers. In practice, a company’s process may also involve finance, investor relations and board-level stakeholders, according to its governance structure.

That coordination matters because technical severity and securities-law materiality are not interchangeable. A serious-looking intrusion does not automatically answer what the event means for the company; conversely, a sequence of less conspicuous events can have a material combined effect.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How related incidents can change the assessment

Companies must consider whether multiple unauthorized occurrences are related and whether their combined effect is material. A string of individually immaterial events may require disclosure when assessed together. Relevant connections can include timing, form, a common actor or an exploited vulnerability.

For that reason, an incident record should capture more than the latest alert. Teams need a way to identify earlier or parallel occurrences and assess their collective operational and financial consequences. The SEC also indicates that a company may alert similarly situated companies or government actors before completing its materiality determination, provided those communications do not unreasonably delay the internal process.

What an Item 1.05 filing should say—and what it can omit

A filing should describe the material aspects of the incident’s nature, scope and timing, as well as its material impact or reasonably likely material impact on the company. That includes effects on financial condition and results of operations. The practical challenge is to explain consequences clearly even when investigators are still confirming the full scope.

The SEC does not require companies to publish specific technical information about planned response measures, systems, networks, devices or vulnerabilities at a level of detail that would impede response or remediation. That protection is not a reason to make the disclosure empty: companies still need to communicate the material facts and impacts that the rule calls for while avoiding details that could undermine the response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why disclosures can remain vague

The incident-reporting timetable puts pressure on a process in which facts arrive unevenly. Security teams may know what systems are affected before the company can quantify financial consequences. Legal and disclosure teams need to assess the significance of evolving facts, while the company must avoid revealing technical details that could make remediation harder. If those groups do not share information through a defined process, a filing can describe the event without giving investors much sense of its business impact or response.

A 2024 BreachRx analysis, as reported by Axios, found that 16.9% of public Form 8-K cyber-incident filings in its analysis provided specific details about material impact on the business. The same report said 48% provided any specifics about how an organization was responding to an ongoing incident. These figures describe the level of detail in the filings examined; they do not establish that every filing lacking specifics violated the SEC rule.

A practical workflow for filing accurately and on time

  1. Detect and preserve facts. Record the discovery time, known systems and services affected, key uncertainties, and steps taken to preserve evidence.
  2. Open a cross-functional incident record. Give security, legal, finance and disclosure stakeholders a shared place to track facts, decisions and open questions.
  3. Connect related occurrences. Check whether earlier or concurrent events may be linked by timing, form, actor or vulnerability, and assess their combined effects.
  4. Assess business impact. Evaluate operational disruption and actual or reasonably likely effects on financial condition and results of operations. Identify what is known, what remains uncertain and what could change the assessment.
  5. Document the materiality decision. Record the basis for the decision, participants and timing. This helps establish when the filing clock starts and whether the assessment proceeded without unreasonable delay.
  6. Draft and review Item 1.05. Describe the incident’s material nature, scope, timing and impact. Have appropriate legal and disclosure reviewers check the filing, while keeping technical response details within the limits described above.
  7. File within the applicable period. Once the company determines that the incident is material, work to meet the four-business-day deadline, subject only to the rule’s limited national-security or public-safety delay.
  8. Update when warranted and tag the filing. Reassess as facts develop and amend the Form 8-K if material information unavailable at the initial filing becomes known. Inline XBRL tagging for material cybersecurity incident disclosures in Form 8-K and Form 6-K was required by December 18, 2024.

What stronger readiness looks like

Companies cannot eliminate uncertainty from a fast-moving incident, but they can reduce avoidable delay and improve the usefulness of disclosures. A readiness process should make it possible to:

  • escalate an incident to the people responsible for materiality and disclosure decisions;
  • assess business impact alongside technical scope, rather than waiting for a complete forensic account;
  • recognize when related events should be assessed together;
  • explain material consequences without disclosing technical details that could impede remediation; and
  • prepare the filing and Inline XBRL tagging as part of the incident-response process.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.