The SEC cybersecurity disclosure rules changed what a public company's board is accountable for, and the change is subtler than the headlines suggested. The rules do not require any particular security control. They require you to disclose material incidents promptly, and to describe how you manage cyber risk.
Both obligations turn out to require the underlying program to actually exist, which is the practical effect.
The Two Requirements
Item 1.05 of Form 8-K: material incident disclosure. On determining that a cybersecurity incident is material, a registrant must file within four business days, describing the material aspects of the incident's nature, scope and timing, and its material impact or reasonably likely material impact on the company, including financial condition and results of operations.
The rule does not require technical detail, and specifically does not require disclosure that would impede response or remediation.
Item 106 of Regulation S-K: annual disclosure. In the annual report, a registrant must describe its processes for assessing, identifying and managing material risks from cybersecurity threats, whether any risks have materially affected or are reasonably likely to materially affect the company, management's role in assessing and managing those risks, and the board's oversight of them.
The Clock Starts on Judgment
The four business days run from the determination of materiality, not from discovery, and the determination must be made without unreasonable delay.
This is the most consequential detail in the rules, and the one most likely to cause difficulty in practice.
An incident is discovered on a Friday evening. Its scope is unclear for several days. The organization does not know whether customer data was taken until forensics progresses. At what point was materiality determinable, and can the company defend that timeline afterward?
The answer is not found in the technical response; it is found in whether a defined process exists for making the determination, who participates, what information triggers it, and whether the deliberation is documented. Companies that have designed that process in advance can show a reasoned timeline. Companies that have not are reconstructing one after the fact, under scrutiny.
What Materiality Means Here
The rules deliberately use the established securities law standard rather than defining a cyber-specific one: whether a reasonable investor would consider the information important.
That is broader than financial impact, and the adopting release is explicit about it. Qualitative factors matter: harm to reputation, harm to customer or vendor relationships, the possibility of litigation or regulatory action, the nature and sensitivity of data compromised, and the effect on operations.
An incident with modest direct cost can be material because of what it says about the company's controls or because of what was taken. Conversely, an incident with a significant remediation cost may not be material if it had no meaningful effect on the business.
The practical implication for a board is that the materiality assessment is a business judgment informed by security facts, and it should be made by people equipped to make business judgments, with security providing the facts.
What the Annual Disclosure Actually Demands
Item 106 asks you to describe your processes. It does not prescribe them, which sounds permissive and is not.
A description is a public statement. Describing a robust risk management process that does not operate as described creates exposure that has nothing to do with cybersecurity and everything to do with disclosure accuracy. This is the mechanism by which a disclosure rule became a de facto governance requirement.
Companies should therefore ensure the description is accurate and that evidence supports it. If you describe periodic independent assessment of your controls, you should be conducting it. If you describe board oversight at defined intervals, the minutes should reflect it.
This is where technical assessment connects to the disclosure obligation directly: a program that includes regular independent testing produces evidence supporting the description, and it produces information the board needs to oversee anything meaningfully.
What Boards Should Actually Do
Four things, in rough order of value.
Design the materiality determination process now. Who convenes, on what trigger, with what information, and how the deliberation is recorded. Rehearse it in a tabletop exercise, because the first time should not be during a real incident.
Establish a reporting cadence that produces informed oversight. Describing board oversight requires oversight to exist. Reports should cover material risks, what has been tested, what was found and what is being done, not a dashboard of green indicators.
Make sure the annual description is accurate. Read it against what actually happens. Where the two diverge, fix the practice or change the description.
Understand third-party incident obligations. An incident at a service provider can be material to you. Materiality assessment processes should account for incidents you learn about rather than detect, and vendor contracts should require prompt notification.
Alongside Everything Else
The SEC rules sit on top of obligations that already exist: state breach notification laws in every state, sector regulation such as HIPAA or NYDFS Part 500, and contractual notification commitments to customers.
An incident can trigger several simultaneously with different thresholds and timelines. Mapping those in advance, so the response team knows on day one who must be told and by when, is straightforward preparation that is very difficult to do under pressure.
To discuss testing that supports your disclosure position, or an executive tabletop exercise, get in touch.
Frequently asked questions
What do the SEC cybersecurity rules require?
Two things. Item 1.05 of Form 8-K requires disclosure of a material cybersecurity incident within four business days of determining it is material, describing its nature, scope, timing and material impact. Item 106 of Regulation S-K requires annual disclosure in Form 10-K of processes for assessing, identifying and managing cybersecurity risk, and of board and management oversight.
When does the four-day clock start?
On the determination of materiality, not on discovery of the incident. The determination must be made without unreasonable delay, which means an organization cannot extend the deadline by deferring the judgment. In practice this makes the materiality assessment process itself the thing that needs to be designed in advance.
What makes an incident material?
The standard is the traditional securities law one: whether a reasonable investor would consider it important in making an investment decision. It is not confined to financial impact. Reputational harm, operational disruption, loss of customer confidence and the nature of data compromised all bear on it, and qualitative factors can make an incident material even where the dollar figure is modest.
Did the rules require a cybersecurity expert on the board?
No. That was proposed and not adopted in the final rules. The board expertise disclosure requirement was dropped, though the requirement to describe board oversight of cybersecurity risk remains. Companies must explain how the board oversees this risk, which in practice pushes toward some form of informed oversight.
Can disclosure be delayed?
Only in a narrow circumstance: where the United States Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety, and notifies the Commission in writing. This is a limited exception requiring active government involvement, and it is not a general hardship provision.
