In December 2023, the Securities and Exchange Commission adopted rules requiring public companies to disclose material cybersecurity incidents within four business days and to report annually on their cybersecurity risk management, strategy, and governance. For the first time, a federal regulator has established a defined timeline for determining whether a security event is material to investors and for making that determination public.
The rules create a new accountability problem: leadership is now responsible for a rapid, defensible materiality judgment that requires technical understanding, legal sophistication, business context, and regulatory positioning—but no single executive typically owns all four dimensions. The four-day clock starts when materiality is determined, not when an incident is discovered, but that determination itself requires a governance process most organizations have not built.
What the Rules Require
The SEC rules impose two distinct obligations on public companies:
**Material Incident Disclosure.** Companies must file a Form 8-K within four business days of determining that a cybersecurity incident is material. The disclosure must describe the material aspects of the incident's nature, scope, and timing, along with its material impact or reasonably likely material impact on the company. The four-day period begins when materiality is determined, not when the incident is first detected.
**Annual Risk Management and Governance Disclosure.** Form 10-K filings must now include a description of the company's processes for assessing, identifying, and managing material cybersecurity risks, whether the company engages assessors or consultants, and how cybersecurity risks are integrated into overall risk management. Companies must also disclose the board's oversight of cybersecurity risk and management's role and expertise in assessing and managing that risk.
The annual disclosure is not a technical inventory. It is a governance statement. The SEC expects companies to explain who is accountable, how risk decisions are made, how information flows to the board, and whether management possesses relevant expertise.
Why Materiality Determination Is the Hard Part
The four-day disclosure clock does not start when an incident occurs or when it is detected. It starts when the company determines the incident is material. This creates a procedural burden: the organization must have a repeatable, documented process for making that determination quickly and defensibly.
Materiality is a judgment about investor impact, not technical severity. An incident may be operationally significant but not material if it does not affect financial condition, operations, or competitive position in a way a reasonable investor would consider important. Conversely, a narrow technical event may be material if it affects regulated data, triggers contractual obligations, or exposes the company to significant liability.
The determination requires collaboration between technical incident responders who understand scope and impact, legal counsel who understand disclosure obligations, finance leadership who understand business materiality, and executives who can make the call. Without a pre-defined process and clear ownership, the four-day window will pass while internal stakeholders negotiate in real time.
The Incident Readiness Gap
Most public companies have incident response plans that address containment, investigation, and recovery. Fewer have governance processes that address materiality determination, regulatory notification timing, disclosure drafting authority, and board escalation within a four-day window.
Incident readiness now means more than technical playbooks. It means having standing authority to convene decision-makers, pre-agreed criteria for evaluating investor impact, templated escalation procedures, and clarity about who drafts, reviews, and approves the 8-K language. It means knowing in advance whether outside counsel will be involved, whether cyber insurance carriers must be notified, and whether the disclosure will trigger obligations under other regulatory regimes.
This is not an IT function. It is a governance function that requires executive ownership.
What the Annual Disclosure Reveals About Organizational Maturity
The annual Form 10-K disclosure asks questions many boards and executive teams have not yet answered clearly:
- Who at the management level is accountable for cybersecurity risk decisions, and what is their relevant expertise?
- How does the board receive information about cybersecurity risks, and how often?
- What processes exist for identifying which cybersecurity risks are material to the business?
- If the company uses external assessors or consultants, what role do they play, and who oversees their work?
- How are cybersecurity risks integrated into the company's broader enterprise risk management framework?
These are not technical questions. They are questions about organizational structure, decision authority, and accountability. A company that cannot answer them clearly is effectively disclosing that cybersecurity risk management is not yet integrated into executive governance.
The disclosure is public. Investors, regulators, plaintiffs' counsel, and cyber insurers will read it. Vague or boilerplate language may satisfy the letter of the rule while signaling to sophisticated readers that risk ownership is unclear.
Who Owns This Inside the Organization
The SEC rules create an accountability problem because they fall across traditional organizational boundaries:
**IT and information security teams** understand technical incidents but typically do not make materiality judgments or draft public disclosures. They are responders, not decision-makers on investor impact.
**General counsel and legal teams** understand disclosure obligations and materiality standards but may not have the technical depth to assess incident scope or the operational context to evaluate business impact quickly.
**CFOs and finance leadership** understand business materiality but may not be equipped to translate technical incident details into investor-relevant impact assessments under time pressure.
**Chief Risk Officers**, where they exist, may own enterprise risk frameworks but often lack incident-level visibility and the authority to convene cross-functional teams on short notice.
What is missing is a role with standing executive authority, cybersecurity expertise, regulatory fluency, and the business context to make rapid materiality determinations and coordinate disclosure. This is the function a [virtual Chief Information Security Officer (vCISO)](/vciso/) is designed to fill: strategy-first leadership that translates security events into business decisions and regulatory positions.
Building the Governance Process Before the Incident
Compliance with the SEC rules depends on decisions made before an incident occurs. Specifically, organizations need:
- A documented process for materiality determination that identifies who participates, who decides, and what factors are considered.
- Pre-defined escalation criteria and notification timelines so that decision-makers are engaged immediately when a qualifying incident is detected.
- Template communication frameworks that allow rapid drafting and review of 8-K disclosures without starting from blank pages under time pressure.
- Clear authority for convening the incident governance team, which may include IT, legal, finance, communications, and executive leadership.
- A repeatable method for documenting the materiality determination itself, so the company can demonstrate that the four-day clock was appropriately triggered.
- Integration points with cyber insurance, outside counsel, forensic investigators, and other third parties whose involvement may be contractually required or strategically advisable.
None of this is speculative. These are operational requirements created by a rule that is now in effect. Companies that wait until an incident occurs to build the process will miss the four-day window or produce disclosures that were drafted in haste without adequate review.
The Board's Role and Disclosure Obligations
The annual disclosure requirement makes board oversight of cybersecurity risk a public statement. Boards must now be prepared to explain how they are informed about cybersecurity threats, how often they receive updates, which committee has oversight responsibility, and whether directors have relevant expertise.
This shifts the nature of board engagement. Periodic presentations from IT leadership may no longer be sufficient if they do not address risk management processes, materiality thresholds, or enterprise integration. Boards need visibility into whether management has the expertise and organizational structure to comply with the disclosure rules, not just whether technical defenses are in place.
Directors should ask whether the company has tested its incident governance process, whether management can demonstrate compliance with the four-day timeline in a tabletop exercise, and whether the annual disclosure accurately reflects how cybersecurity risk is actually managed. A disconnect between the disclosure and operational reality is itself a risk.
Practical Next Steps for Leadership
Organizations subject to the SEC rules should take the following steps if they have not already done so:
- **Designate clear executive ownership** for cybersecurity risk governance and SEC disclosure compliance. Identify who has authority to convene the materiality determination process and who makes the final call.
- **Document the materiality determination process** in writing, including decision criteria, required participants, escalation timelines, and approval authority. Make sure legal, finance, and IT leadership have reviewed and agreed to the process.
- **Conduct a tabletop exercise** that simulates a material incident and tests whether the organization can complete the materiality determination and draft a disclosure within four business days. Identify gaps and revise the process accordingly.
- **Review the annual Form 10-K disclosure language** with the board and management to ensure it accurately reflects governance structure, decision authority, and expertise. Avoid boilerplate language that does not describe the actual process.
- **Integrate SEC disclosure obligations into the incident response plan** so that regulatory notification is a defined step in the playbook, not an afterthought. Ensure that incident responders know when and how to escalate for materiality review.
- **Evaluate whether current leadership has the expertise and bandwidth** to fulfill the governance role the SEC rules assume. If not, consider whether external advisory support or [virtual CISO leadership](/vciso/) would provide the necessary executive ownership and regulatory positioning.
The SEC rules are in effect. The four-day clock will start the next time a potentially material incident occurs. Organizations that have not built the governance process in advance will be making irreversible decisions under time pressure without a clear framework.
Where Heights Can Help
Heights Consulting Group provides virtual CISO leadership for organizations that need executive ownership of cybersecurity strategy, governance, and regulatory compliance. Our work includes building incident governance processes, preparing organizations for regulatory disclosure obligations, and providing the standing executive presence that allows boards and management to answer the questions the SEC rules now require.
We work with CFOs, general counsel, and boards to translate regulatory requirements into operational governance, to document decision processes that will withstand scrutiny, and to provide the expert judgment that materiality determinations demand. This is strategy-first advisory work, not technical implementation.
If your organization is subject to the SEC disclosure rules and has not yet established clear ownership of materiality determination and incident governance, a confidential consultation can clarify what adequate compliance looks like and whether external advisory support would address the gap. There is no charge for an initial conversation, and no obligation beyond it.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Incident Readiness and Response Planning
A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.