SEC cybersecurity enforcement in 2026 has narrowed to one thing: a material misstatement in an investor-facing disclosure. The flagship SolarWinds case was dismissed with prejudice in November 2025, the FY2025 enforcement results listed no new cyber-disclosure or controls actions, and the only public Item 1.05-era settlements remain the October 2024 four-company sweep (Unisys, Avaya, Check Point, Mimecast) for roughly $7 million combined. The risk now lives more in your trust-center page than in your 8-K.
Picture the call. 4:30 PM Thursday. Your CISO just told the GC an attacker exfiltrated files from the finance share. Forensics will not have clean scope for a week. The disclosure committee has 24 hours to decide between an Item 1.05 8-K, an Item 8.01, or nothing. The answer in mid-2026 looks different than it did in 2024.
The headline SEC case is gone. The Commission and SolarWinds Corp. filed a joint stipulation on November 20, 2025 dismissing the entire action with prejudice, including the claims against CISO Timothy Brown that survived Judge Engelmayer's July 2024 ruling. No verdict, no settlement, no liability finding.
The real shift is downstream. The cases that stuck (the four-company sweep in October 2024, settled for ~$7 million combined) hardened one drafting pattern: the SEC wins when external statements contradict internal records, and loses when the theory needs a creative reading of the statute.
The piece of SolarWinds that almost reached trial was the marketing page, not the 8-K. Most disclosure committees have never put a trust-center page through the review they give a 10-K. That is the exposure in-house teams are sleeping on.
TL;DR
- The SEC has filed a small number of public Item 1.05-era enforcement actions, not a flood. The October 2024 four-company sweep (Unisys, Avaya, Check Point, Mimecast) settled for a combined ~$7 million. The SolarWinds case was dismissed with prejudice in November 2025.
- The materiality framework is real and consistent: TSC Industries v. Northway, 426 U.S. 438 (1976), applied to cyber, with both quantitative and qualitative factors. Boards that wait for a clean dollar figure before assessing materiality are doing it wrong.
- Recent dispositions point one direction: be specific in your 8-K, treat your risk-factor language as a representation, and do not soft-pedal a breach you already know is bad.
- The four-business-day clock continues to be the operational problem. The fix is a pre-incident framework, not faster lawyering during the crisis.
When does the Item 1.05 four-business-day disclosure clock start?
Part of our securities, governance, and in-house counsel series.
The rule, briefly
The rule is SEC Release No. 33-11216, adopted July 26, 2023. It does two things.
Item 1.05 of Form 8-K, effective December 18, 2023 for most filers, requires a registrant to disclose a cybersecurity incident within four business days of determining the incident is material.
The disclosure must describe the material aspects of the nature, scope, and timing of the incident and the material or reasonably likely material impact, including on financial condition and results of operations.
Item 106 of Regulation S-K (17 CFR §229.106), in 10-K filings for fiscal years ending on or after December 15, 2023, requires registrants to describe their processes for assessing, identifying, and managing material cyber risks, plus management's role and the board's oversight.
Two practical points. The trigger is not the incident; it is the determination of materiality. The clock starts when the registrant concludes the incident is material, and the rule requires that determination "without unreasonable delay" after discovery.
The only delay available is a narrow national-security pathway requiring written notification by the Attorney General to the Commission. The threshold is high; most matters will not qualify.
SolarWinds: what happened, what it means
The SEC sued SolarWinds and Brown on October 30, 2023 in the Southern District of New York, SEC v. SolarWinds Corp. & Brown, No. 23-cv-9518, alleging fraud and internal accounting-controls violations tied to the Sunburst supply-chain compromise.
On July 18, 2024, Judge Paul A. Engelmayer issued a 107-page opinion granting most of the defendants' motion to dismiss. The court rejected the SEC's attempt to read the internal accounting controls provision of the Securities Exchange Act (Section 13(b)(2)(B)) as a backdoor cybersecurity-controls statute.
The provision covers controls over financial reporting, not the integrity of a company's network. The internal-controls theory was the Commission's most ambitious extension into territory Congress had not authorized, and Engelmayer shut it down.
The court also dismissed claims based on general risk-factor language and the post-Sunburst 8-K, finding the SEC was reading those disclosures with hindsight. What survived were narrower fraud claims tied to SolarWinds' public "Security Statement," alleged to be materially false in ways the company knew internally. On November 20, 2025, the parties filed a joint stipulation dismissing the remaining claims with prejudice.
Takeaways. The internal-controls theory is dead. General risk-factor language survives better than feared; the court did not let "a cyber incident could materially affect us" become a representation about specific system security.
Specific control statements (white papers, SOC 2 summaries, trust-center pages) are a different animal. Treat them as securities filings: same reviewers as your 10-K, refreshed on a cycle, evidence file at each refresh.
The rest of the enforcement record
The four-company sweep on October 22, 2024 is the other anchor case. The SEC charged Unisys, Avaya, Check Point Software Technologies, and Mimecast with materially misleading disclosures about Sunburst-related intrusions.
All four settled. Penalties were Unisys $4 million, Avaya $1 million, Check Point $995,000, Mimecast $990,000, roughly $7 million combined. The theory was not that these companies failed to disclose at all; it was that the disclosures they did file negligently minimized what each company already knew.
SEC cyber-disclosure enforcement actions: the full catalog
Here is every public SEC cybersecurity-disclosure enforcement action through June 2026, with the disposition and the specific drafting failure the Commission charged. Note what is not on this list: no new actions in fiscal year 2025, and the marquee case ended in dismissal.
| Action | Date filed | Disposition | Penalty | Core charge |
|---|---|---|---|---|
| SEC v. SolarWinds & Brown (S.D.N.Y. 23-cv-9518) | Oct 30, 2023 | Dismissed with prejudice, Nov 20, 2025 | None | Fraud tied to the public "Security Statement"; internal-controls and 8-K theories dismissed July 2024 |
| In re Unisys Corp. | Oct 22, 2024 | Settled | $4,000,000 | Framed cyber risk as hypothetical after knowing data was exfiltrated |
| In re Avaya Holdings | Oct 22, 2024 | Settled | $1,000,000 | Disclosed a "limited number" of emails; omitted at least 145 files accessed in cloud storage |
| In re Check Point Software | Oct 22, 2024 | Settled | $995,000 | Kept generic risk-factor language unchanged despite knowing of the intrusion |
| In re Mimecast Ltd. | Oct 22, 2024 | Settled | $990,000 | Did not disclose the number of affected customers or the volume of source code taken |
Sources: SEC Press Release 2024-174 (Oct 22, 2024); SEC v. SolarWinds joint stipulation of dismissal (Nov 20, 2025); Davis Polk and Perkins Coie client updates. Penalty figures are the agreed civil penalties in each settled order.
The SEC is not punishing companies for getting hacked. It is punishing companies that downplayed scope in filings while internal documents told a different story.
The drafting failure was hedge language ("the threat actor accessed a limited number of email accounts") that did not match the forensic reports inside the company.
A composite of that failure: a mid-cap software vendor's IR team writes a Slack update saying "attacker exfiltrated ~12 GB of source code and customer credentials from three repos." The 8-K two days later says "limited evidence of unauthorized access to certain systems."
Six weeks later, customer notifications cite 12 GB. The discovery production in the securities-fraud follow-on includes the Slack channel. October 2024 sweep theory, mid-cap version.
Three non-enforcement incidents that have shaped how counsel think about Item 1.05:
Clorox (August 2023). Clorox filed an 8-K on August 14, 2023. A month later it filed again, warning of a material effect on quarterly financials: net sales guidance revised down 23% to 28%, diluted EPS guidance of a $0.35 to $0.75 loss.
Incremental costs reached roughly $49 million. Textbook case for "materiality is iterative": the first 8-K did not predict the financial impact; the second did, once disruption was quantified.
MGM Resorts (September 2023). MGM filed on September 13, 2023, the day after identifying the issue. It disclosed approximately $100 million of negative impact to Adjusted Property EBITDAR for the quarter while taking the position that the incident was not expected to be material to full-year results.
The "material to the quarter, not to the year" framing is legitimate under TSC Industries but a representation to defend if the full-year forecast slips.
UnitedHealth / Change Healthcare (February 2024). UnitedHealth filed on February 22, 2024 reporting that a suspected nation-state actor had accessed Change Healthcare systems. The initial filing said the interruption appeared specific to Change Healthcare; that scope statement was the contested piece.
Amendments on March 8 and April 24, 2024 expanded the picture, and the company eventually disclosed business-disruption impacts of $0.60 to $0.70 per share. Initial scope is sticky; if a later filing expands the perimeter, plaintiffs' lawyers will ask why the first did not.
Tracking numbers: between the rule's effective date and early 2025, roughly 54 companies filed about 80 cyber-related 8-Ks (26 under Item 1.05, the rest under voluntary Item 8.01). Item 8.01 is the "something happened, materiality not yet concluded" surface.
The contrarian read: the trade press has spent two years worrying the SEC will treat heavy Item 8.01 use as evasion of Item 1.05. The enforcement record does not support that.
Neither the October 2024 sweep nor the SolarWinds complaint turned on 1.05 vs 8.01 choice. They turned on misstatements within whichever item was filed. CETU, the 30-person Cyber and Emerging Technologies Unit led by Laura D'Allaird since February 2025, has framed its cyber-disclosure priorities as fraud, not clock-evasion.
If your disclosure committee is split on a borderline incident, 8.01 with a clean draft is usually the safer move.
The materiality framework that is actually emerging
The Adopting Release was explicit: materiality means what it means under TSC Industries, Inc. v. Northway, Inc., 426 U.S. 438 (1976), and Basic Inc. v. Levinson, 485 U.S. 224 (1988). An incident is material if a reasonable investor would consider it important, or if disclosure would significantly alter the total mix of information available.
Two axes in the materiality memo:
Quantitative. Direct costs (incident response, forensics, notification, ransom), revenue impact, cost of goods sold, capital structure, litigation and regulatory exposure. Clorox is the data point: a 23% to 28% downward revision to quarterly sales is unambiguously material.
Qualitative. Nature of the data affected (PII, PHI, IP, customer financial data), regulatory consequences beyond the SEC (HHS for HIPAA, state AGs, FTC), reputational impact, operational resilience signaling, and impact on key customer relationships.
A breach exposing protected health information can be material even where direct costs are limited, because of downstream regulatory and reputational consequences.
The common mistake is treating materiality as a quantitative threshold and waiting for a firm dollar figure. The Adopting Release rejects that. A company that knows on day two that customer PII was exfiltrated cannot delay the determination to day forty because the cost forecast is not done.
What the memo looks like in practice. One to two pages, dated, attributed to a named drafter (usually the deputy GC for securities), updated every 24 hours with a track-changes redline.
Four sections: incident summary as of the timestamp; quantitative factors with point estimates and ranges; qualitative factors with a yes/no/maybe on each; conclusion (material, not material, premature) with one-sentence justification and the next refresh time.
Teams get stuck when they treat the memo as a single artifact rather than a versioned series. The SEC, plaintiffs' counsel, and your audit committee will all want to see how the call evolved, not a tidy final draft.
What GCs and securities counsel get wrong
Four recurring failure modes:
Delaying the materiality assessment because facts are incomplete. The clock starts on the materiality determination, not on every operational detail. Preliminary memo within 24 to 48 hours of discovery, refreshed every 24 hours.
Conflating the IT incident with the material event. Every public company has cybersecurity incidents weekly. A reportable "incident" under Item 1.05 is the subset that crosses the materiality line. Item 106 is where you explain the triage. Item 1.05 is where you disclose what triage flagged.
Weak DOJ-defer process. The Item 1.05(c) delay requires written notification by the Attorney General to the SEC. If the FBI is "involved," a delay is not automatic.
The DOJ's threshold is narrow. Your IR plan needs the pathway pre-built and your CISO needs to flag national-security implications in the first hour.
Risk-factor disclosure that goes stale. A cybersecurity risk factor reading the same in your 2024 10-K as in your 2022 10-K, after twelve months of public industry incidents, is asking for a comment letter.
What a public-company GC should have ready by Q4 2026
Without all six of the following on the shelf, you are exposed to the worst version of an Item 1.05 disclosure under time pressure, and you will not draft your way out during the crisis.
-
An incident response plan that names the materiality call. Who convenes it, on what timeline, with what inputs, how it is documented. The GC or designated securities counsel chairs. CFO, CIO/CISO, and disclosure committee chair are required attendees.
-
A standing cyber materiality framework approved by the disclosure committee, with the company's own dollar thresholds and qualitative red flags.
-
A pre-drafted Item 1.05 8-K template with the four required elements (nature, scope, timing, material or reasonably likely material impact) plus standard cautionary language.
-
An annual tabletop with the IR firm, outside counsel, and the disclosure committee, including drafting a hypothetical Item 1.05 within the window.
-
Board cybersecurity reporting cadence. Quarterly updates to the audit committee, a deeper full-board briefing annually for a mid-cap. The actual oversight has to match the Item 106 disclosure. Document the meetings.
-
A marketing-page audit. A standing process where the disclosure committee reviews the trust-center page, security white papers, security FAQs, and any public statement about cybersecurity controls.
Companies that build this before an incident write a clean Item 1.05 within the window. Companies that build it during an incident write the kind of 8-K the SEC picks apart on the way to a settlement, like the four companies in the October 2024 sweep.
Where the regime is going
The SolarWinds dismissal does not mean cyber enforcement is over. CETU, the roughly 30-person Cyber and Emerging Technologies Unit that replaced the old Crypto Assets and Cyber Unit on February 20, 2025, lists public-issuer fraudulent disclosure about cybersecurity among its priorities. The Commission's focus under Chair Paul Atkins is fraud with genuine investor harm, not technical or judgment-call violations. Cases from here will look more like the October 2024 sweep than the original SolarWinds theory.
Two data points anchor the shift. FY2025 enforcement results, released in 2026, included no new cybersecurity disclosure or controls actions, a sharp break from FY2024. And the Division of Examinations kept cybersecurity on its 2026 exam-priorities list as a perennial focus: incident-response plans, access controls, data-loss prevention, third-party vendor oversight, and AI-related risk. Enforcement narrowed; examination did not.
The rule is here, the materiality framework matches TSC Industries, the four-business-day clock is enforceable, and the cases the SEC will win are the ones where a specific disclosure or marketing page contradicted internal records. Most public companies do not have a cyber-disclosure problem. They have a cyber-disclosure-process problem.
FAQ
Is the SEC still bringing cybersecurity enforcement actions in 2026? Yes, but the bar is higher. FY2025 produced no new cyber-disclosure or controls actions, and the SolarWinds case was dismissed with prejudice in November 2025. CETU, led by Laura D'Allaird, still lists cybersecurity disclosure fraud as a priority, so the live risk is an affirmative material misstatement in an investor-facing disclosure, not a judgment call on timing.
What happened to the SEC's SolarWinds case? Most claims were dismissed in July 2024 by Judge Engelmayer, including the internal-accounting-controls and 8-K theories. The fraud claims tied to SolarWinds' public "Security Statement" survived, then the SEC and SolarWinds filed a joint stipulation dismissing the entire action with prejudice on November 20, 2025. There was no verdict, settlement, or liability finding.
How much did the four SolarWinds-related companies pay the SEC? The October 22, 2024 settlements totaled roughly $7 million: Unisys $4 million, Avaya $1 million, Check Point $995,000, and Mimecast $990,000. The SEC charged each with negligently minimizing the impact of the Sunburst intrusion in public disclosures.
What is the SEC Item 1.05 four-business-day rule? Item 1.05 of Form 8-K requires a registrant to disclose a material cybersecurity incident within four business days. The clock starts when the company determines the incident is material, not at discovery, and that determination must be made without unreasonable delay.
When can a company delay an Item 1.05 disclosure? Only through a narrow national-security pathway that requires the U.S. Attorney General to notify the SEC in writing that disclosure poses a substantial risk to national security or public safety. FBI involvement alone does not trigger a delay, and the threshold is high enough that most incidents will not qualify.
Should a company file under Item 1.05 or Item 8.01? Item 1.05 is for incidents already determined material; Item 8.01 covers events where materiality has not yet been concluded. Neither the SolarWinds complaint nor the 2024 sweep turned on the 1.05-versus-8.01 choice, they turned on misstatements within whichever item was filed. For a borderline call, a clean Item 8.01 draft is usually the safer move.
Does the SEC cyber rule cover marketing and trust-center pages? Not directly, but the surviving SolarWinds claims targeted the company's public "Security Statement," a marketing-style page. Specific control statements (white papers, SOC 2 summaries, trust-center pages) can be treated as securities representations, so they should get the same review cycle as a 10-K.
For deeper operational detail, see the SEC cybersecurity disclosure Item 1.05 GC playbook, the vendor security questionnaire template, the data processing agreement negotiation playbook, and the AI governance policy template for in-house teams.
For a disclosure-timeline compliance workspace anchored to the actual statute and regulation text (Item 1.05, 17 CFR §229.106, and the Adopting Release), see /features/compliance-check.

The Item 1.05 clock starts when you determine materiality, not at discovery; the 8-K is due four business days later.
New legal AI guides, weekly.
Further Reading
SEC Cybersecurity Disclosure (Item 1.05 8-K): A GC Playbook for 2026
Read postAI Regulation for In-House Counsel in 2026: A State and Federal Update
Read postNon-Compete Law Updates 2026: New State Laws and the FTC's Exit
Read postWhat Lawyers Want From Legal AI in 2026: A 534-Lawyer Study
Read postLegal AI in Microsoft Word: Contract Review, Redlining, and Research in a Word Add-In
Read postLegal AI Word Add-Ins Compared: 14 Tools, Features, and Pricing (2026)
Read post
Co-Founder & CEO · Attorney
Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.