Effective Date: December 18, 2023
Applies to: All public companies subject to the Securities Exchange Act of 1934
Administered by: U.S. Securities and Exchange Commission (SEC)
🧭 Purpose
To ensure investors receive timely, consistent, and material information about cybersecurity incidents that could affect a company’s financial condition or operations.
📄 What Must Be Disclosed?
Under Item 1.05 of Form 8‑K, companies must disclose:
- The nature, scope, and timing of the incident
- The material impact or reasonably likely impact on the company’s financial condition and operations
Importantly:
- Companies must disclose material cybersecurity incidents, not all incidents
- Disclosure must be based on facts available at the time — updates can follow later
📅 When Must It Be Filed?
- Within 4 business days after the company determines the incident is material
- Not necessarily 4 days after the incident occurs — the clock starts when materiality is determined
🔐 Exceptions
- Companies may delay disclosure if the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety
- This requires coordination with law enforcement and formal notification to the SEC
🧩 What Is “Material”?
Materiality is judged using standard securities law principles:
Would a reasonable investor consider the information important in making an investment decision?
Factors include:
- Operational disruption
- Financial loss
- Reputational damage
- Legal or regulatory exposure
- Impact on customers or partners
🛠️ Additional Requirements
- Companies must describe cybersecurity risk management and governance in their annual Form 10‑K
- Foreign private issuers must report material incidents on Form 6‑K
- Inline XBRL tagging is required for structured data reporting
