On July 26, 2023, the Securities and Exchange Commission adopted rules that change how public companies report on cybersecurity. There are two parts. A company that determines a cybersecurity incident is material must disclose it on Form 8-K within four business days of that determination. And annual reports on Form 10-K must describe how the company manages cybersecurity risk and how its board and management oversee it. Incident reporting starts December 18, 2023 for most companies, and the annual disclosure applies to fiscal years ending on or after December 15, 2023.

For security teams, the rules turn two internal questions into public ones. How quickly can you work out whether an incident matters to investors? And does your program actually work the way the 10-K will say it does?

What did the SEC adopt?

The final rules were published in the Federal Register on August 4, 2023, and take effect on September 5, 2023. They add a new Item 1.05 to Form 8-K for material cybersecurity incidents, and a new Item 106 to Regulation S-K for annual disclosure of cybersecurity risk management, strategy and governance. In the 10-K itself, that annual disclosure goes in a new Item 1C.

Foreign private issuers get parallel requirements on Forms 6-K and 20-F. Notably, the SEC dropped a proposed requirement to disclose whether any board members have cybersecurity expertise.

When do the SEC cybersecurity disclosure rules take effect?

Requirement Applies to Compliance begins
Form 10-K Item 1C (Regulation S-K Item 106) All domestic registrants, including smaller reporting companies Annual reports for fiscal years ending on or after December 15, 2023
Form 20-F Item 16K Foreign private issuers Annual reports for fiscal years ending on or after December 15, 2023
Form 8-K Item 1.05 and Form 6-K Registrants other than smaller reporting companies December 18, 2023
Form 8-K Item 1.05 Smaller reporting companies June 15, 2024
Inline XBRL tagging All registrants One year after initial compliance with the related requirement

A calendar-year company will include the new Item 1C section in the 10-K it files in early 2024, covering fiscal 2023. That means the description has to match how the program runs now, not how you plan to run it next year.

What does Form 8-K Item 1.05 require?

Item 1.05 is triggered when a company determines that a cybersecurity incident it has experienced is material. The 8-K is due within four business days of that determination. The rule also says the materiality determination must be made "without unreasonable delay" after the incident is discovered, so the analysis itself can't be stretched out to push back the clock.

The filing must describe:

  • the material aspects of the nature, scope and timing of the incident, and
  • the material impact, or reasonably likely material impact, on the company, including its financial condition and results of operations.

Companies do not have to disclose specific or technical information about their planned response, or about their systems, networks and potential vulnerabilities, in enough detail to impede the response or remediation. If some required information hasn't been determined or isn't available when the 8-K is due, the company says so. It then files an amended 8-K within four business days after that information is determined or becomes available.

What counts as a cybersecurity incident?

The rules define a cybersecurity incident as "an unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through a registrant's information systems that jeopardizes the confidentiality, integrity, or availability of a registrant's information systems or any information residing therein."

Two parts of that definition deserve attention from security teams:

  • "A series of related unauthorized occurrences." Several related events that each look minor can together amount to a material incident. You need a way to connect them.
  • "Information systems." The rules define these as information resources "owned or used by" the company. Incidents on a service provider's systems that you rely on can be in scope. The adopting release indicates companies generally aren't expected to make inquiries beyond their regular channels of communication with those providers.

Can disclosure be delayed?

Only in narrow circumstances. A company may delay the 8-K if the U.S. Attorney General determines that disclosure would pose a substantial risk to national security or public safety and notifies the SEC in writing. The steps look like this:

  1. An initial delay of up to 30 days.
  2. An additional delay of up to 30 days if the Attorney General makes a further determination.
  3. In extraordinary circumstances, a final additional delay of up to 60 days where national security is at stake.
  4. Anything beyond that requires an exemptive order from the SEC.

There is also a narrow accommodation for companies subject to the Federal Communications Commission's breach notification rule for customer proprietary network information. They may delay the 8-K for the period that rule allows, and in no event for more than seven business days. Beyond these two routes, the rule offers no general delay mechanism.

When is a cyber incident material?

The SEC did not create a new materiality test for cybersecurity. It relies on the long-standing securities law standard: information is material if there is a substantial likelihood that a reasonable shareholder would consider it important in making an investment decision, or if it would significantly alter the "total mix" of information available.

That analysis is quantitative and qualitative. Direct costs, lost revenue and recovery expenses matter, but so do harder-to-measure effects. The adopting release points to factors such as harm to reputation, customer or vendor relationships, or competitiveness, and the possibility of litigation or regulatory investigations. An incident with a modest price tag can still be material if it damages a key customer relationship or draws regulatory scrutiny.

Materiality is a legal and business judgment, usually made by senior management with counsel. But it rests on facts the security team gathers, and late or unclear facts make for a weaker determination.

What must go in the annual 10-K disclosure?

Item 106 has two main sections. Neither prescribes a framework or control set, but both require an accurate description of what the company actually does.

Risk management and strategy

Companies must describe their processes, if any, for assessing, identifying and managing material risks from cybersecurity threats, in enough detail for a reasonable investor to understand them. The disclosure should address, as applicable:

  • whether and how those processes are integrated into the company's overall risk management system
  • whether the company engages assessors, consultants, auditors or other third parties in connection with those processes
  • whether the company has processes to oversee and identify risks from cybersecurity threats associated with its use of third-party service providers

Companies must also say whether any risks from cybersecurity threats, including as a result of previous incidents, have materially affected or are reasonably likely to materially affect their business strategy, results of operations or financial condition.

Governance

On the board side, companies must describe the board's oversight of risks from cybersecurity threats, name any committee or subcommittee responsible, and describe how the board or committee is informed about those risks.

On the management side, they must describe which positions or committees assess and manage these risks, and the relevant expertise of the people in those roles. They must also explain how those people are informed about and monitor the prevention, detection, mitigation and remediation of incidents, and whether they report to the board.

How do the rules apply to foreign private issuers?

Foreign private issuers must furnish information on Form 6-K about material cybersecurity incidents they disclose, or are required to disclose, in their home jurisdiction, to a stock exchange or to security holders. Their Form 20-F annual reports must include comparable risk management, strategy and governance disclosure under new Item 16K.

What do the SEC rules mean for security teams?

Legal will own the filings, but security owns most of the inputs. Here's where we'd focus before December.

Define how incidents reach the disclosure committee

Most public companies have a disclosure committee that decides what goes into SEC filings. Fewer have a defined path from the security team to it. Write down which incidents get escalated beyond the security function, who does the escalating, and how fast. Useful triggers include impact on critical business systems, exposure of customer or employee data, extended outages, and incidents at key service providers.

Record timestamps as you go: when the incident was detected, when it was escalated, and when the materiality decision was made. Those dates will matter if anyone later questions whether the determination was made without unreasonable delay.

Build a documented materiality process

Decide in advance who takes part in the materiality call. That typically means security leadership, legal, finance and someone who understands the affected business lines. Agree on the quantitative and qualitative factors the group will weigh, and give them a standard incident brief to work from, so they aren't piecing facts together from chat threads.

Document the outcome and the reasoning, including decisions that an incident is not material, and revisit them as facts change.

Because a series of related occurrences can be an incident in its own right, someone needs to look across tickets for patterns, such as the same weakness exploited twice or repeated events at one provider. A periodic review of lower-severity incidents covers much of this.

Bring service providers into the process

Check that your contracts with key providers require timely notice of security incidents and name a contact on each side. The rules' focus on systems "used by" the company makes this more than good hygiene.

Pressure-test the Item 1C draft

Ask the security team to review the draft 10-K language line by line. If it says the board receives regular cybersecurity briefings, confirm that it does and that there's a record. If it says you assess vendor risk, make sure the process exists and is followed. Overstating the program in a public filing creates its own risk.

Rehearse under the real clock

Run a tabletop exercise that goes past containment and into the disclosure decision. Give the group an evolving scenario and a four-business-day deadline, and see where information stalls.

Frequently asked questions

Does the four-business-day clock start when an incident is discovered?

No. It starts when the company determines the incident is material. The determination itself must be made without unreasonable delay after discovery, so the gap between the two should be explainable.

Do we have to report incidents that happen at our vendors?

Potentially. The definition of information systems covers resources the company owns or uses, so an incident on a provider's systems can trigger Item 1.05 if it's material to you.

Are smaller reporting companies exempt?

No. They must include the Item 106 disclosure in annual reports for fiscal years ending on or after December 15, 2023, the same as everyone else. They get more time only for Form 8-K Item 1.05, which applies to them from June 15, 2024.

Key takeaways

  • Form 8-K Item 1.05 applies from December 18, 2023, or June 15, 2024 for smaller reporting companies. The filing is due four business days after a materiality determination.
  • The new 10-K Item 1C applies to fiscal years ending on or after December 15, 2023, so calendar-year companies need it in their next annual report.
  • Materiality is management's call, but it depends on fast, well-documented input from security.
  • Write down your escalation path, materiality process and provider notification terms, then test them together.

This post summarizes the rules as adopted and isn't legal advice. Confirm how they apply to your company with securities counsel.