Cybersecurity Incident Disclosure
Cybersecurity incident disclosure refers to the practice of publicly reporting significant cyber events that affect a company. Under rules adopted by the U.S. Securities and Exchange Commission (SEC) in 2023, publicly traded companies in the United States are generally required to disclose cybersecurity incidents they determine to be material. This disclosure is typically made through a designated regulatory filing within a set number of business days after the materiality determination.
Cybersecurity incident disclosure, as operationalized under the SEC's 2023 amendments, requires registrants to file current disclosure about a cybersecurity incident once it is determined to be material. Under the final rule, the underlying definition of a cybersecurity incident is described as not self-executing but rather operationalized through Item 1.05; the disclosure is generally required via Form 8-K within four business days of determining that the incident is material, rather than within four days of the incident's occurrence. The rule does not prescribe a fixed timeframe for making the materiality determination itself, and the obligation applies to U.S. public companies subject to SEC reporting; scope, applicability, and related requirements vary and this entry does not address disclosure regimes in other jurisdictions or the substantive analysis of what constitutes materiality. This entry is educational and not legal, audit, or compliance advice.
Why it matters
Cybersecurity incident disclosure sits at the intersection of compliance, risk, and investor protection. For U.S. public companies subject to SEC reporting, the SEC's 2023 amendments elevate certain cyber events from an operational security concern to a securities-law disclosure obligation. Once an incident is determined to be material, the company generally must file current disclosure via Form 8-K within four business days of that determination. This reframes cyber incidents as potentially price-sensitive information that the market is entitled to receive on a defined timeline.
The rule's structure places significant weight on the materiality determination, which triggers the disclosure clock. The four-business-day window runs from the materiality determination rather than from the incident's occurrence or discovery, and the rule does not prescribe a fixed timeframe within which that determination must be made. This makes the determination process itself a focal point for governance and controls: companies need a defensible, documented process for assessing materiality promptly, because delay in reaching a determination is an area of regulatory and reputational sensitivity.
Because the underlying definition of a cybersecurity incident is described in the final rule as not self-executing but rather operationalized through Item 1.05, companies cannot rely on the definition alone to know what and when to disclose; they must apply the operative disclosure requirement to their specific facts. The scope of the rule is limited to U.S. public companies subject to SEC reporting, and it does not address disclosure regimes in other jurisdictions. Organizations operating across borders may face additional or overlapping obligations that this entry does not cover.
Who it's relevant to
Inside Cybersecurity Incident Disclosure
Common questions
Answers to the questions practitioners most commonly ask about Cybersecurity Incident Disclosure.