The SEC published its final cybersecurity disclosure rules in July 2023, and they changed how public firms must run security. Cybersecurity risk can no longer sit with the IT team alone. It is no longer just a tech problem.
The SEC's message was clear: cybersecurity risk is investment risk. Your investors deserve to know how you handle it.
SEC Chair Gary Gensler put it plainly at the time. "Whether a company loses a factory in a fire—or millions of files in a cybersecurity incident—it may be material to investors."
That line sums up the shift. One breach can wipe out share value, halt your work, and break the trust you built with customers.
The rules give investors facts they can use, and they look the same from firm to firm. That lets investors weigh one against the next.
The rules landed in a brutal threat landscape. The average cost of a data breach hit $4.88 million worldwide in 2024. That was a 10% jump on the year before.
In the United States the figure soared to $10.22 million, an all-time high. Fines, legal bills, and the sheer grind of breach response drove it there.
Cybercrime is on track to cost the world economy $10.5 trillion a year by 2025. Set against that, the SEC judged that voluntary disclosure was no longer enough.
The impact reaches well past paperwork. The rules change how your security program runs and how you weigh and escalate a breach. They also change how your leaders talk about cybersecurity risk.
That shift brings work, but it also brings a chance to get ahead. A strong, disclosure-ready security program meets the rules and makes you safer.
This guide walks through what the SEC cybersecurity disclosure rules ask of you. It shows how enforcement has shaped what the SEC expects. Most of all, it shows how to build a security program that meets the rules and truly guards your business.
The framework runs on two tracks. You report a material incident on Form 8-K, and you report governance once a year on Form 10-K. Together they tie a single event to the wider story of how you run security.
The four-business-day rule is the hard part. Under new Item 1.05 of Form 8-K, you must report any cybersecurity incident you deem material. The clock gives you four business days from that materiality determination.
Your filing must cover the material aspects of the incident's nature, scope, and timing. It must also cover the material impact on your firm, or the impact that is reasonably likely. That takes in your financial condition and your results of operations.
The clock does not start on the day the incident happens, or on the day you find it. It starts on the day you determine the incident is material. But the SEC is blunt: you cannot unreasonably delay that determination to buy time.
This split matters. The SEC grants that you may not be able to judge materiality the day you find an incident. Many incidents take days or weeks to scope.
The rule allows for that, but it still expects you to press on with care. You may not have the full picture when you file. If so, say which facts you have not yet pinned down.
You must then file an amended Form 8-K within four business days of learning those facts. So the duty runs well past your first response.
Item 106 of Regulation S-K sets the yearly rules. You must lay out your cybersecurity posture in two areas: risk management and strategy, then governance.
On risk management and strategy, show how you weigh, spot, and manage material risks from cybersecurity threats. The SEC gives a non-exclusive list of points to cover, and what you say turns on your own facts. The list asks:
You must also say whether cybersecurity threats have materially hurt your firm, including threats from past incidents. And you must say whether they are reasonably likely to hurt you. That test covers your business strategy, your results of operations, and your financial condition.
The test looks ahead, so you must weigh future harm too. The governance half then covers your board and your leaders. Show how your board of directors oversees risks from cybersecurity threats, and name the committee or subcommittee that owns the job.
Say how the board or that committee gets briefed. Then set out management's role in judging and managing material risks from cybersecurity threats, and name the posts or committees that hold it. State the relevant expertise those people bring, and show how they learn about and track cybersecurity risk.
The rules took effect on September 5, 2023, and phased in from there. For Form 10-K and Form 20-F, all registrants had to comply for fiscal years ending on or after December 15, 2023. So most calendar year-end firms first met Item 106 in their 2023 annual reports, filed in early 2024.
Form 8-K incident disclosure came later. Larger registrants began on December 18, 2023. Smaller reporting companies got more time and began on June 15, 2024.
By mid-2024 every public firm was in scope. The rules also make you tag these disclosures in Inline XBRL, a machine-readable data format. Those structured data rules began in late 2024.
Machine-readable tags let investors line up filings side by side, which was the whole point.
Materiality sits at the core of the framework. You cannot comply until you know how to judge it. The SEC has said a lot about this one call.
The SEC uses the same test as the rest of the federal securities laws. A fact is material if a reasonable investor would likely deem it important to an investment decision. It is also material if it would significantly alter the total mix of information available to investors.
That test comes from Supreme Court case law. So judge a breach through an investor's eyes, not an engineer's.
Materiality turns on the facts of your case. A breach of customer data may be material for a health firm that runs on patient trust. The same breach may mean less for a manufacturer with little consumer data.
One flaw can be material for you and not for the firm next door. It turns on which systems it hits and what data it lays bare.
The SEC says you must weigh both quantitative and qualitative factors. The hard-number side covers direct costs: incident response, legal fees, SEC fines, and settlements. It also covers indirect costs, such as lost sales from downtime, higher insurance rates, and clean-up work.
The soft side counts just as much and is harder to pin down. The SEC's adopting release lists several to weigh:
SEC staff have stressed these qualitative factors again and again in public remarks on Item 1.05. Look only at hard cash numbers and you will miss breaches that clearly matter to investors. Damage to your work and your good name counts too.
These calls are complex, and four days is not long. So build your framework before an incident hits.
Start with a cross-team disclosure committee. Pull in:
A mixed group sees more angles, and its calls hold up better with regulators.
Set your triggers in advance. Write down what forces an escalation and a materiality review. Your criteria should weigh:
Every incident is unique, so a framework will not make the call for you. But it will speed up the work.
Many teams now use models like Factor Analysis of Information Risk (FAIR). These models add hard numbers to the call and turn a tech event into business impact terms. That is the language a disclosure decision needs.
Records matter just as much. You must be able to show you made the call without unreasonable delay. You must also show your work rested on the facts you had.
So keep notes on the steps you took, the facts you weighed, and why you landed where you did. Those notes protect you if the call is picked apart later.
Four business days is a tight squeeze, because you must dig deep yet judge fast. The SEC has owned up to that strain. It noted that these calls need "an informed and deliberative process."
You may warn peer firms and government agencies at any point in your response, and that does not start the clock. One condition applies: you must not use it to drag out your own review.
So you can share what you know with industry partners and law enforcement. Good-faith help costs you nothing.
The rules also carve out a narrow national security exception, and you may delay in one case only. The United States Attorney General must find that immediate disclosure would pose a substantial risk to national security or public safety.
You must ask through set channels at the Department of Justice. Build those steps into your incident response plan now.
The SEC has shown through its cases that it takes cybersecurity disclosure seriously. Those cases tell you what it expects, and they show where firms keep slipping.
The SEC brought a case against SolarWinds Corporation and its Chief Information Security Officer (CISO), Timothy Brown. It was the first litigated action the agency brought against a public company over cybersecurity disclosures. It was also the first charge against a person in such a case.
The complaint was filed in October 2023. It alleged that SolarWinds made materially misleading statements about its security practices. Those statements came both before and after the SUNBURST attack came to light.
That attack hit the firm's Orion software. It reached many customers, among them government agencies and Fortune 500 companies.
In July 2024 a federal judge threw out most of the SEC's claims. The judge deemed many of the statements "non-actionable corporate puffery." Even so, the case set key precedents.
The court let some claims go on. Those dealt with exact lines in the public SolarWinds Security Statement about access controls and password protection policies. Specific claims about how you guard systems can support liability if they are materially false.
The SEC dropped its remaining claims against SolarWinds in November 2025, after new leadership reset its priorities. Still, the case showed the SEC will go after specific, misleading claims about security posture. Broad, vague pledges draw a more skeptical look from judges.
The October 2024 cases may matter more to you. The SEC charged four firms that were themselves victims of the SolarWinds breach. They were Unisys Corporation, Avaya Holdings Corporation, Check Point Software Technologies Ltd., and Mimecast Limited.
The message was blunt: victim status does not excuse a misleading filing. The SEC said each firm learned in 2020 or 2021 that threat actors had reached its systems. Each then "negligently minimized" the incident in public filings.
The findings show just what the SEC hunts for. Unisys called its cybersecurity risks "hypothetical" in annual reports. Yet it knew the SolarWinds-related break-ins had led to the theft of gigabytes of data.
The SEC also found its disclosure controls fell short. Its response process did not adequately require security staff to escalate what they knew to the people who write filings. Unisys paid a $4 million civil penalty, the largest of the four.
Avaya said threat actors had reached a "limited number" of company email messages. It did not say that hackers also reached at least 145 files in its cloud file sharing environment. Some of those files held confidential and proprietary data.
Avaya paid a $1 million penalty. Check Point wrote about the break-ins and risks in "generic terms" while it knew the specifics. Mimecast "minimized the attack by failing to disclose" what code was taken and how many encrypted credentials were stolen.
All four worked with the SEC, tightened their controls, and settled without admitting or denying the findings. The lesson is simple: say what you actually know about a breach. Vague words that mask the true scope will not save you.
These cases carry four clear lessons.
First, the SEC weighs what you knew inside against what you said outside. You cannot plead ignorance of a risk you have already sized up, or of an incident you have already lived through.
Second, disclosure controls matter as much as the disclosure itself. The Unisys charge shows you need a solid path that carries security facts to the people who draft SEC filings.
Third, generic risk factor wording buys you little. Boilerplate about broad cybersecurity risk may meet the bare minimum. It will not excuse silence about a specific incident or flaw you already know of.
Fourth, help and clean-up count in your favor, yet they do not stop a case. All four victim firms worked with the SEC and fixed what was broken. They still paid.
These rules take more than a tick-box drill. You need a security program built for disclosure from day one. That means you weave disclosure into incident response, risk management, and governance.
Old incident response plans focus on containment, eradication, and recovery. A disclosure-ready plan adds two more core steps: the materiality review and disclosure to the SEC.
Set clear triggers that link technical detection to disclosure review. Not every event needs a materiality review, so your criteria should say which ones always go to the disclosure committee. Triggers might include:
Your response team needs people who know the filing rules and can join the materiality talk. Wait for a materiality call before you loop in legal and compliance, and you lose days. You also risk a poor decision.
Run disclosure drills in your tabletop exercises. Most teams rehearse the tech response, but far fewer rehearse the four-day drill. Practice the whole chain:
The drill exposes gaps and builds muscle memory. Write it all down as it happens. Note what you chose to disclose, what you did not yet know, and why the call took as long as it did.
Those notes may prove vital years later if the SEC asks how you got there.
The Form 10-K governance disclosures make you spell out board oversight and management duty. But good governance does more than fill an annual report. It builds the accountability that lets you respond well and report risk with care.
Most boards hand cybersecurity risk to one committee, and that is often the audit committee. Look at S&P 100 filings and the audit committee is named most often for cybersecurity oversight. It should get regular briefings on your posture, on major events, and on new risks.
Match the depth and pace of those briefings to your risk profile. High-risk firms may need them each quarter, or even each month. Others may do fine with one deep review a year plus exception reports in between.
Whatever pace you set, write it down and stick to it. It will show up in your Form 10-K.
The CISO or an equal role usually holds the management duty, though some firms split it across a few leaders. The rules make you disclose management's relevant expertise. That may cover past work in cybersecurity, degrees, certifications, or other background.
Make sure the people you name truly have it, along with the clout to act.
Reporting lines matter too. Say your CISO reports to the chief information officer. That officer reports to the chief financial officer, who briefs the audit committee now and then.
That looks weaker than a rival whose CISO can reach the board directly. No set shape is required. But naming the line lets investors judge how well you are run.
The rules ask you point blank whether you have tied cybersecurity processes into your company-wide risk management system. Look at Form 10-K filings and 90% of S&P 100 firms say they have. It is now the baseline.
Tying them in means you weigh, report, and manage cyber risk with the same tools you use for every other risk. In practice that can mean:
Think about how you describe the cybersecurity frameworks you follow. Filings show 51% of companies name a framework, attestation, or rule as the base of their program. The NIST Cybersecurity Framework is cited most often.
Naming a known framework shows maturity and gives investors a yardstick.
The rules ask you to show how you oversee risk from third-party service providers. Supply chain attacks like the SolarWinds breach are a large and growing threat. That is why the SEC called them out.
Look at 10-K filings and you see a clear pattern. In those filings, 90% of S&P 100 firms report a way to vet, watch, or run due diligence on vendor security. Write down your own vendor risk process and be ready to describe it in your annual filing.
A strong third-party program covers:
You do not have to do this alone. Experienced cybersecurity advisory services can help you build a vendor risk program that meets both your security needs and your disclosure duties.
The rules focus on filings and governance, but strong tech controls still hold the whole thing up. You cannot honestly claim strong practices you do not have. The SolarWinds cases show that the gap between claim and reality creates real legal exposure.
Good vulnerability management is how you learn your true risk and spot trouble early. A sound program includes:
Together these give you honest facts about your security posture.
Vulnerability management data often proves vital during incident response. It answers questions such as:
The answers shape both containment and your disclosure.
Annual penetration testing proves your controls work as meant. It also finds flaws that scanners miss. Hands-on work against network defenses, application security, and social engineering shows that the practices you disclose match reality.
Application penetration testing matters most if you run large web apps or customer-facing systems. Web applications account for 36% of all penetration tests conducted. That attack surface earns a hard look.
Feed test results back into your board reporting. Briefings should cover penetration testing findings, fix status, and trends. That builds a written record of steady gains and backs up what you say about active risk management.
A four-day window makes fast detection vital. You need monitoring that flags trouble early enough to dig in, judge materiality, and draft a filing in time.
That means investing in security information and event management (SIEM) systems. You also need endpoint detection and response (EDR) tools. It may also mean managed cybersecurity services for round-the-clock watch.
The mean time to identify a breach averaged 194 days worldwide in 2024. That is far too long under these rules.
Finding a breach yourself beats hearing of it from an attacker or a third party. Research shows the average breach costs $4.18 million when your own team finds it first. It costs $5.08 million when the attacker discloses the breach.
Find it yourself and you also gain time and control over what you file.
Many firms lack a large in-house security team. A virtual Chief Information Security Officer (vCISO) can bring the skill to build and run a disclosure-ready security program. A vCISO can set up governance, write response procedures, prep board briefings, and line up tech controls with your compliance goals.
The rules make you disclose management's relevant cybersecurity expertise. So you need credentialed, seasoned security leadership. Hire it full time or bring it in as an advisor.
The SEC cybersecurity disclosure regime keeps moving. Firms are learning the rules, and regulators are watching how they comply. Knowing the trends helps you get ready for what comes next.
Form 10-K filings are getting better. Early ones leaned on generic lines that told investors little. Newer ones give more detail on board oversight, on response processes, and on supply chain exposure.
More detail brings both upside and risk. Detailed, honest disclosures build investor trust and show a mature security program. But they also create liability if you do not follow the practices you describe.
So make sure your filing matches what you really do.
In May 2024 the SEC clarified that Item 1.05 is for incidents actually determined to be material. Since then, firms have leaned on Item 8.01 for voluntary disclosure. They use it when materiality is undetermined, or when they determined the incident immaterial.
The split helps investors tell true material events from a heads-up. Set an internal policy on when to use Item 1.05 and when to use Item 8.01. Make sure a voluntary disclosure does not hint at materiality by mistake.
Have legal counsel review each choice.
SEC rules are only one layer. Many firms must also meet:
A joined-up approach pays off. One well-built incident response plan can cover SEC disclosure, state notice, and contract duties at once.
The SEC's stance has shifted since the rules came in. It dropped the SolarWinds case in late 2025. Yet it still goes after firms that mislead about incidents they know of.
Expect a hard look at the gap between what you know and what you say. That goes double after a big incident.
Leadership and priorities at the SEC may keep changing. The rules themselves stay in force. And the market now expects open cybersecurity disclosure, whatever the mood at the agency.
Use this five-phase roadmap to build or upgrade your disclosure-ready security program.
Start by weighing what you have against what the SEC asks. Work through this list:
This pass should surface gaps that could block compliance. It should also show any daylight between what you disclose and what you do.
Set up or firm up the structures you will disclose in Form 10-K:
Fold disclosure into daily work:
Make sure your tech stack backs up your compliance goals:
Disclosure readiness is an ongoing program, not a one-time win. Keep it alive:
The SEC cybersecurity disclosure rules changed how you must treat security. Cybersecurity is no longer just a tech function. It is now part of how you are governed and how you talk to investors.
Embrace that and the rules become a chance, not just a chore. A genuinely strong security program lets you stand out through open, detailed disclosure. Investors now see cybersecurity as a value driver.
Speak well about your posture and you may win more trust. You may even lower your cost of capital.
Treat the rules as a box to tick and you carry real risk. The cases against SolarWinds victims show the SEC will go after disclosures that do not match what you knew. That damage stacks on top of the heavy cost of the breach itself.
A disclosure-ready security program takes real investment in governance, process, and tech. Many firms gain from partnering with advisors who know both the security side and the compliance side.
Threats will keep changing, and the rules will likely grow. Build strong ground now and you are set for today's rules and tomorrow's. Cyber risk is business risk, and disclosure-ready security is simply good business.
The clock starts on the day you determine that a cybersecurity incident is material. It does not start when the incident occurs or when you find it. Materiality uses the same test as the rest of federal securities law.
A fact is material if a reasonable investor would likely deem it important to an investment decision. You must make the call "without unreasonable delay." The SEC does grant that you often need to dig first.
Weigh both quantitative and qualitative factors. Hard numbers cover direct costs such as incident response, legal fees, and fines. They also cover indirect costs such as lost sales and higher insurance rates.
Soft factors cover harm to your good name and damage to customer and vendor ties. They also cover a hit to how well you compete, plus exposure to lawsuits or probes. The SEC stresses those soft factors again and again.
Look only at the cash hit and you may miss a clearly material incident.
Yes, but only through a set process. The U.S. Attorney General must find that immediate disclosure would pose a substantial risk to national security or public safety. The Attorney General must then tell the SEC of that finding in writing.
You cannot decide on your own to delay. The provision allows an initial 30-day postponement. Extensions can run to a total of 60 days, or 120 days in extraordinary circumstances.
Item 106 makes you describe management's role and expertise in judging and managing material cybersecurity risks. The SEC's instructions say that expertise may include past work in cybersecurity. It may also include relevant degrees or certifications, or any other knowledge, skills, or background in the field.
Give investors enough detail to judge whether your leaders are qualified. You need not publish full biographies.
The rules set no fixed pace. But you must disclose how the board or its named committee learns about cybersecurity risk. Look at 10-K filings and 33% of S&P 100 firms disclose a set briefing cadence.
That may be quarterly or annually. Pick a pace that fits your risk profile. Then write it down for disclosure.
No. The rules state that companies need not disclose "specific or technical information about planned response to the incident or cybersecurity systems, related networks and devices, or potential system vulnerabilities in such detail as would impede the registrant's response or remediation."
You must still disclose the material aspects of the incident's nature, scope, and timing. You must also disclose its material impact. Describe what happened so investors grasp it, without handing attackers a map.
Sometimes the required facts were not available or not yet settled when you first filed. In that case, you must file an amended Form 8-K. You have four business days from the day those facts land.
You must also amend if you later find the first filing was inaccurate or materially misleading. So the duty runs right through response and recovery.
They run on separate tracks. An incident may trigger SEC disclosure but no state notice, if it is material to investors but involves no personal data. It may trigger state notice but no SEC disclosure, if it involves personal data but is not material to investors.
It may trigger both. So keep processes that cover every rule that applies to you.
Yes, though they got a slightly longer runway. Smaller reporting companies had to begin complying with Form 8-K Item 1.05 on June 15, 2024, six months after larger firms. The annual Form 10-K rules applied to all companies on the same timeline.
Since mid-2024, every registrant has been fully subject to both incident disclosure and annual governance reporting.
In its October 2024 cases, the SEC imposed civil penalties from $990,000 to $4 million. Those cases hit firms that downplayed their exposure to the SolarWinds breach. The size of each penalty tracked how bad the disclosure gaps were.
It also tracked whether disclosure controls fell short, and how far the firm cooperated. Each firm also agreed to a cease and desist order barring future violations.
This article is provided for informational purposes only and does not constitute legal advice. Organizations should consult with qualified legal counsel regarding their specific SEC disclosure obligations.

