The short answer
Public companies must now disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality, and describe their cybersecurity risk management, governance and board oversight annually on Form 10-K. The rules assign clear accountability but create an execution problem: leadership is responsible for outcomes in a domain where they often lack technical fluency, internal ownership is fragmented, and the materiality determination requires judgment that technical staff cannot make alone.
On July 26, 2023, the Securities and Exchange Commission adopted rules requiring all public companies to disclose material cybersecurity incidents and to describe their cybersecurity risk management, strategy and governance. The rules create two distinct obligations: incident disclosure on Form 8-K within a fixed deadline, and annual disclosure of cybersecurity programs on Form 10-K. Both place accountability squarely on executive leadership and boards in a domain where authority is often diffuse and technical ownership unclear.
1What the Rules Require
The SEC's rules establish two main components. First, companies must disclose material cybersecurity incidents on a new Item 1.05 of Form 8-K within four business days of determining that an incident is material. Second, companies must describe their cybersecurity risk management, strategy and governance annually in their Form 10-K under new Regulation S-K Item 106. The Form 10-K disclosures became effective for fiscal years ending on or after December 15, 2023. The Form 8-K disclosures became effective 90 days after publication in the Federal Register or December 18, 2023, whichever was later, with smaller reporting companies receiving an additional 180 days.
2Form 8-K Incident Disclosure Under Item 1.05
Item 1.05 requires disclosure of the material aspects of the incident's nature, scope and timing, as well as its material impact or reasonably likely material impact on the registrant, including on financial condition and results of operations. The four-business-day deadline is measured not from discovery of the incident but from the determination that the incident is material. Companies must make the materiality determination without unreasonable delay.
Materiality is judged from the perspective of a reasonable investor. Information is material if there is a substantial likelihood that a reasonable shareholder would consider it important in making an investment decision, or if it would significantly alter the total mix of information available. The assessment must consider both quantitative and qualitative factors, including harm to reputation, customer or vendor relationships, competitiveness, the possibility of litigation or regulatory investigations, and actions by state, federal or non-U.S. authorities.
Item 1.05 does not require disclosure of specific or technical information about planned response, cybersecurity systems, related networks and devices, or potential system vulnerabilities in detail that would impede response or remediation. The rule permits limited delay if the United States Attorney General determines in writing that immediate disclosure would pose a substantial risk to national security or public safety and notifies the SEC of that determination.
The Division of Corporation Finance has clarified that Item 1.05 is reserved for incidents the company has determined to be material. If a company chooses to disclose an incident for which it has not yet made a materiality determination, or an incident determined not to be material, the Division encourages disclosure under a different item of Form 8-K, such as Item 8.01, to avoid investor confusion.
3Form 10-K Annual Disclosure Under Item 106
Item 106 of Regulation S-K requires registrants to describe, in their annual reports on Form 10-K, their processes for assessing, identifying and managing material risks from cybersecurity threats, as well as whether any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the company. The rule includes a non-exclusive list of disclosure items that registrants should address based on their facts and circumstances.
Item 106 also requires description of the board of directors' oversight of risks from cybersecurity threats and management's role and expertise in assessing and managing material risks from cybersecurity threats. Foreign private issuers must provide comparable disclosure on Form 20-F under new Item 16K, and must furnish material cybersecurity incidents on Form 6-K promptly after the incident is disclosed or otherwise publicized in a foreign jurisdiction, to any stock exchange, or to security holders.
4Who Is Accountable
The rules apply to all domestic registrants and foreign private issuers subject to reporting requirements under the Securities Exchange Act of 1934, including business development companies. The disclosure obligations rest with the registrant itself, which means executive leadership and the board are directly accountable. The rules explicitly require disclosure of the board's oversight role and management's role and expertise, making governance structure a reportable fact.
This creates a structural problem in many organizations. The people who can assess whether an incident is material are typically not the people who discover it or manage the technical response. The people accountable for the disclosure are typically not the people who understand the incident's technical scope. The determination must be made without unreasonable delay, which means the organization needs a functioning process in place before an incident occurs.
5The Materiality Determination
Determining materiality is a judgment that requires both business and technical context. It is not a task that can be delegated entirely to technical staff, and it is not a task that executives can perform without technical input. The determination must be made through the lens of a reasonable investor and must account for the total mix of information, considering both quantitative factors such as financial impact and qualitative factors such as reputational harm, regulatory exposure and competitive position.
The SEC has noted that there may be cases in which a cybersecurity incident is so significant that a company determines it to be material even though the company has not yet determined its impact or reasonably likely impact. In those cases, the company should disclose the incident in an Item 1.05 Form 8-K, include a statement noting that it has not yet determined the impact, and amend the Form 8-K to disclose the impact once that information is available. The initial filing must still provide investors with information necessary to understand the material aspects of the nature, scope and timing of the incident.
6Selective Disclosure and Regulation FD
The Division of Corporation Finance has clarified that nothing in Item 1.05 prohibits a company from privately discussing a material cybersecurity incident with other parties or from providing information beyond what was included in an Item 1.05 Form 8-K. Those parties may include commercial counterparties such as vendors and customers, as well as other companies that may be impacted by the same incident or threat actor.
Regulation FD requires public disclosure of any material nonpublic information that has been selectively disclosed to securities market professionals or shareholders as specified in the regulation. However, companies can privately share information about an incident without triggering Regulation FD if the information is immaterial, if the recipients are not covered by Regulation FD, or if an exclusion applies. For example, information shared with a person who owes a duty of trust or confidence to the issuer, such as an attorney, investment banker or accountant, or a person who expressly agrees to maintain the information in confidence under a confidentiality agreement, does not trigger Regulation FD's public disclosure requirement.
7The Connection to Incident Readiness and Response Planning
The SEC's rules do not prescribe specific incident response processes or cybersecurity controls. They require disclosure of the processes a company has in place and the governance surrounding those processes. This means that compliance depends on having a functioning incident readiness and response program before an incident occurs. The four-business-day deadline leaves no time to build the process during the event.
An effective program for <a href="/services/incident-readiness/">incident readiness and response planning</a> establishes who has authority to make materiality determinations, what information those decision-makers need, how technical findings are translated into business impact, and how disclosure obligations are coordinated with response activities. It defines escalation paths, communication protocols and decision-making authority in advance. Without this structure, the organization cannot meet the regulatory deadline reliably.
8What Leadership Should Do Next
Leadership should begin by verifying that the organization has clear executive ownership of cybersecurity risk, incident materiality determinations and regulatory disclosure obligations. This ownership must rest at a level that can coordinate across technical operations, legal, finance, investor relations and the board. The role requires someone who understands both the business implications of technical events and the regulatory obligations that govern public disclosure.
Next, leadership should verify that the organization has documented processes for assessing, identifying and managing material cybersecurity risks, because Item 106 requires disclosure of those processes. The processes must be real and operative, not aspirational or generic. Leadership should verify that the board's oversight role is defined and documented, and that management's role and relevant expertise are clear, because both are required disclosures.
Finally, leadership should verify that <a href="/services/incident-readiness/">incident response planning</a> includes the decision framework, information flow and timeline needed to support a materiality determination within the regulatory deadline. This means identifying who makes the determination, what information they need, who provides it, and how conflicting assessments are resolved. It means rehearsing the process before an incident occurs. The rules do not permit learning during the event.
9How vCISO Leadership Addresses This Gap
The SEC's rules create an accountability gap in organizations that lack executive-level cybersecurity leadership. Technical staff can describe what happened but typically cannot assess materiality from an investor's perspective. General counsel can assess disclosure obligations but typically cannot evaluate technical scope or impact. The CFO can quantify financial impact but typically cannot assess reputational harm, competitive position or the adequacy of response. The determination requires someone who can synthesize technical facts, business context and regulatory obligations at an executive level.
<a href="/vciso/">vCISO leadership</a> provides this executive ownership. A vCISO establishes the governance structure, decision-making authority and incident readiness processes that enable the organization to meet its disclosure obligations reliably. The vCISO owns the strategy, maintains the board reporting relationship, makes risk decisions in business terms, translates technical findings into executive context, and coordinates the materiality determination with legal and finance. This is the role the SEC's rules assume exists but many organizations do not have.
For public companies or organizations preparing for public markets, this is not optional. The rules assign clear accountability. The organization needs someone at the executive level who can discharge it.
10Taking the Next Step
If your organization lacks clear executive ownership of cybersecurity risk and regulatory disclosure, or if incident response planning does not include the decision framework needed to meet the SEC's timeline, Heights can help. We provide the executive leadership, governance structure and incident readiness planning that close this gap. <a href="/contact/">A confidential consultation</a> will clarify where accountability rests today, what the rules require, and how vCISO leadership addresses the structural problem. Schedule that conversation when the decision makes sense for your organization.
Related service: Incident Readiness and Response Planning
A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.