Cybersecurity has become one of the most significant enterprise risks facing US corporations, and the board of directors bears ultimate oversight responsibility for how that risk is managed. The ransomware attacks that have crippled healthcare systems, the supply chain compromises that have penetrated government agencies, and the data breaches that have exposed hundreds of millions of consumers’ personal information are not merely operational or IT problems — they are governance failures. When a cyberattack results in massive financial losses, regulatory penalties, prolonged business disruption, or the theft of trade secrets, shareholders, regulators, and courts increasingly look to the board to ask whether its oversight of cybersecurity risk was adequate. The SEC’s 2023 cybersecurity disclosure rules formalized this accountability by imposing specific legal obligations on public companies and their boards to disclose cybersecurity risks, incident responses, and governance arrangements.
The SEC adopted its cybersecurity disclosure rules on July 26, 2023, effective for annual reports filed for fiscal years ending on or after December 15, 2023. The rules create two distinct categories of disclosure obligation: a requirement to disclose material cybersecurity incidents within four business days of the company determining that the incident is material, through a new Item 1.05 on Form 8-K; and a requirement to disclose annually the company’s cybersecurity risk management program, governance arrangements, and board oversight in the company’s annual report on Form 10-K. Together, these rules represent the most significant federal regulatory action on corporate cybersecurity governance in the history of US securities law.
The Four-Day Material Incident Disclosure Requirement
The most operationally demanding provision of the SEC’s cybersecurity rules is the requirement to file a Form 8-K within four business days of determining that a cybersecurity incident is material. The materiality determination — not the date of discovery of the incident — triggers the four-day clock. This means that companies can take the time necessary to investigate an incident and determine whether it meets the materiality threshold before filing, but once that threshold is crossed, disclosure must follow promptly. The SEC made clear in the adopting release that companies may not delay the materiality determination unreasonably, and that prompt and thorough investigation is expected.
The standard for materiality in the cybersecurity context is the general securities law standard: information is material if there is a substantial likelihood that a reasonable investor would consider it important in making an investment decision, or if it would have significantly altered the total mix of information available. For cybersecurity incidents, the SEC identified several factors relevant to materiality: the nature, scope, and timing of the incident; the impact or reasonably likely impact on the company’s financial condition, results of operations, liquidity, customer relationships, reputation, competitive position, and legal and regulatory standing; and whether the incident has triggered any notification obligations under applicable data privacy laws. An incident that encrypts the company’s entire manufacturing system, exfiltrates its customer database, or compromises its financial reporting infrastructure is almost certainly material; an incident that affects a peripheral system and is contained quickly without significant business impact likely is not.
The 8-K disclosure must describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the company. Companies need not disclose information that would impede ongoing remediation efforts or law enforcement investigations, and the SEC has indicated that the four-day clock may be tolled by a written notification from the Attorney General that disclosure would pose a substantial risk to national security or public safety — but this exception is expected to be rarely invoked. The disclosure obligation does not require disclosure of specific technical details about the vulnerability exploited, the attacker’s identity, or proprietary security information that could enable further attacks.
Annual Cybersecurity Disclosures in Form 10-K
In addition to the incident-specific 8-K disclosure, the SEC’s rules require public companies to provide comprehensive annual disclosures about their cybersecurity risk management and governance in their Form 10-K, under new Item 106 of Regulation S-K. These disclosures must address two subjects: the company’s processes for assessing, identifying, and managing material risks from cybersecurity threats; and the board of directors’ oversight of risks from cybersecurity threats.
The risk management process disclosure requires companies to describe whether and how they have implemented processes to assess, identify, and manage material cybersecurity risks; whether their processes include engaging third-party assessors, consultants, or auditors; and whether and how cybersecurity risks from their use of third-party service providers are managed. This last point is particularly significant: many of the most consequential cyber incidents in recent years have originated in compromised third-party vendors and service providers rather than in the company’s own systems. The SEC’s rules reflect a regulatory expectation that companies will actively manage cyber risk in their supply chains and third-party relationships, not just within their own four walls.
The governance disclosure requires companies to describe the board of directors’ oversight of risks from cybersecurity threats, including whether any board committee or subcommittee is responsible for that oversight and how the board or committee is informed about and monitors prevention, detection, mitigation, and remediation of cybersecurity incidents. Companies must also describe management’s role in assessing and managing material cybersecurity risks, including whether any management positions or committees are responsible for cybersecurity risk management, the relevant expertise of those persons or committees, and how they report cybersecurity risks to the board.
What the Rules Mean for Boards
The SEC’s rules impose specific legal obligations on public companies, but they reflect broader governance expectations that apply to any company facing significant cybersecurity risk. For boards of public companies, the rules require at minimum a clear answer to the question ‘which committee or board body is responsible for cybersecurity oversight?’ and a functioning process by which that committee receives regular, substantive information about the company’s cybersecurity posture. For boards of private companies, while the specific SEC disclosure rules do not apply, the governance expectations reflected in those rules provide a useful benchmark for best practices.
Effective board-level cybersecurity oversight requires directors who have sufficient understanding of cyber risk to ask the right questions, even if they are not technical experts. This does not mean that every board member needs to be a cybersecurity professional. It does mean that every board or relevant committee should include at least one director with meaningful cybersecurity experience or expertise, and that the full board should receive regular education on the cyber threat landscape relevant to the company’s industry. The SEC’s rules do not require companies to designate a ‘cybersecurity expert’ on the board in the manner that Sarbanes-Oxley requires an ‘audit committee financial expert,’ but having a director with genuine cybersecurity credentials significantly strengthens the board’s oversight posture.
The committee responsible for cybersecurity oversight — which in many companies is the audit committee, the risk committee, or in some cases a dedicated technology or cybersecurity committee — should receive regular management briefings from the chief information security officer (CISO) or equivalent executive, structured to provide the committee with a genuine understanding of the company’s threat environment, the adequacy of its defenses, the status of known vulnerabilities, the results of third-party assessments and penetration tests, and any incidents or near-misses. These briefings should occur at least quarterly and should be supplemented by prompt escalation of significant incidents. The committee should also periodically meet with the CISO without management present, similar to the audit committee’s executive sessions with the external auditor.
Incident Response and the Board’s Role
When a cybersecurity incident occurs, the board’s oversight role shifts from proactive governance to crisis oversight. The board or its designated committee should be notified promptly when a significant incident is detected — in most companies, this means notification within hours or days of an incident achieving a certain severity threshold, not weeks. The board should ensure that the company’s incident response plan addresses the escalation process for board notification and that this process is tested through regular tabletop exercises.
During an active incident, the board’s role is not to manage the response — that is management’s function — but to provide oversight, resources, and strategic direction. Key governance questions during a material incident include: Has outside legal counsel with cybersecurity expertise been retained to protect attorney-client privilege over the investigation? Has the company engaged forensic cybersecurity experts to identify the scope and nature of the breach? What are the company’s notification obligations under applicable data breach notification laws? When and how should the company communicate with shareholders, customers, regulators, and the media? Has the company notified its D&O and cyber insurers? What are the legal and regulatory exposure implications of the incident?
The SEC’s four-day disclosure rule adds significant urgency to the materiality assessment process. Boards must ensure that the company has a rapid, well-structured process for making the materiality determination and, once made, for preparing accurate and adequate Form 8-K disclosure within the four-day window. This process requires close coordination between management, the CISO, legal counsel, and the audit committee (or the relevant board-level oversight body). Companies that have rehearsed this process through tabletop exercises are in a far better position to execute it under the stress of an actual incident than those that encounter it for the first time when a breach has just been discovered.
Caremark Liability and Cybersecurity
As discussed in the Caremark Standard article, derivative plaintiffs have begun testing oversight liability theories in the cybersecurity context, arguing that boards that fail to implement adequate cybersecurity oversight systems, that ignore known vulnerabilities, or that receive red flags about the company’s cyber defenses and take no action have breached their oversight duties. While no Delaware court has yet entered a judgment against a director specifically for a cybersecurity oversight failure under a Caremark theory, the legal framework clearly supports such a claim where the facts are sufficiently egregious: a board that operates in an industry with known and severe cyber risks and that has no board-level oversight process for cybersecurity would face a colorable Caremark claim if a catastrophic breach occurred.
The SEC’s disclosure rules create an additional layer of legal exposure: false or misleading disclosures about the company’s cybersecurity risk management program, the board’s oversight, or the nature and impact of a material incident can constitute securities fraud, creating potential liability for the company, its directors, and its officers. SEC enforcement of the cybersecurity disclosure rules is an emerging area, and enforcement actions will provide important guidance on the specific disclosure standards the SEC considers adequate. In the meantime, boards should err on the side of comprehensive, accurate disclosure — overstating cyber defenses or understating known vulnerabilities is far more dangerous than acknowledging the inherent uncertainty of the cyber threat environment.
See Also
- Corporate Governance
- Laws Overview
- The Caremark Standard: Board Oversight Duties and the Risk of Liability for Compliance Failures
- Audit Committee Responsibilities: What Every Director Needs to Know
- AI Governance at the Board Level: Oversight Obligations for Directors in the Age of Agentic AI
- SEC Climate Disclosure Rules: What US Public Companies Are Required to Report
