SEC Cyber Incident Disclosure Rules

Effective Date: December 18, 2023
Applies to: All public companies subject to the Securities Exchange Act of 1934
Administered by: U.S. Securities and Exchange Commission (SEC)

🧭 Purpose

To ensure investors receive timely, consistent, and material information about cybersecurity incidents that could affect a company’s financial condition or operations.

📄 What Must Be Disclosed?

Under Item 1.05 of Form 8‑K, companies must disclose:

  • The nature, scope, and timing of the incident
  • The material impact or reasonably likely impact on the company’s financial condition and operations

Importantly:

  • Companies must disclose material cybersecurity incidents, not all incidents
  • Disclosure must be based on facts available at the time — updates can follow later

📅 When Must It Be Filed?

  • Within 4 business days after the company determines the incident is material
  • Not necessarily 4 days after the incident occurs — the clock starts when materiality is determined

🔐 Exceptions

  • Companies may delay disclosure if the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety
  • This requires coordination with law enforcement and formal notification to the SEC

🧩 What Is “Material”?

Materiality is judged using standard securities law principles:
Would a reasonable investor consider the information important in making an investment decision?

Factors include:

  • Operational disruption
  • Financial loss
  • Reputational damage
  • Legal or regulatory exposure
  • Impact on customers or partners

🛠️ Additional Requirements

  • Companies must describe cybersecurity risk management and governance in their annual Form 10‑K
  • Foreign private issuers must report material incidents on Form 6‑K
  • Inline XBRL tagging is required for structured data reporting

See Also