SEC Cybersecurity Disclosure (Item 1.05 8-K): A GC Playbook for 2026

The first time most GCs read Item 1.05 of Form 8-K closely is the morning after their CISO walks in and says "we have a confirmed intrusion." That is the wrong morning to read it.

What your IR plan looks like by lunchtime was decided months earlier in a tabletop exercise nobody wanted to schedule.

The rule itself is short. The hard work is the seam between security operations and securities disclosure, where a network event becomes a Form 8-K filing decision. That seam is where almost every recent enforcement action has lived.

Short answer: The SEC cyber disclosure rule (Release No. 33-11216, adopted July 26, 2023) added Item 1.05 to Form 8-K. A public company must file an Item 1.05 8-K within four business days of determining that a cybersecurity incident is material. The clock runs from that materiality call, not from detection. The materiality call itself must be made "without unreasonable delay" after discovery. Annual cybersecurity governance disclosure lives in Item 106 of Regulation S-K (the 10-K). Incidents that are not material, or where materiality is still undetermined, belong under Item 8.01 (Other Events).

TL;DR

Part of our in-house counsel guide series.

  • Item 1.05 of Form 8-K requires public companies to disclose a material cybersecurity incident within four business days of determining materiality, under SEC Release No. 33-11216, with compliance for larger filers beginning December 18, 2023 and smaller reporting companies getting an extra 180 days.
  • The clock starts on the materiality determination, not the breach. The determination itself has to be made without unreasonable delay after discovery. That sentence is where most of the legal work actually happens.
  • Non-material incidents, and ones where you have not yet decided, belong under Item 8.01. Reserve Item 1.05 for the material call. The SEC's Division of Corporation Finance asked for exactly that on May 21, 2024, and filing practice followed.
  • The enforcement bar moved in 2025. The SEC dismissed its SolarWinds case with prejudice on November 20, 2025, and signaled it will pursue clear fraudulent misstatements rather than nuanced controls theories. The risk now lives in your trust-center and risk-factor language as much as your 8-K.
  • The deliverable that matters is the pre-incident package: an IR plan with disclosure decision points, a documented materiality framework, a tabletop record, and a board reporting cadence the audit committee can defend on examination.
Quick check

When does the four-business-day Item 1.05 8-K clock start?

The rule, briefly

Item 1.05 was added to Form 8-K by SEC Release No. 33-11216, "Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure," adopted July 26, 2023 (final rule, Federal Register). Compliance for incident disclosure began December 18, 2023 for larger filers, with an extra 180 days for smaller reporting companies.

The companion rule, codified at 17 CFR §229.106 (Item 106 of Regulation S-K), governs annual disclosures about cybersecurity risk management, strategy, and governance in the 10-K. Item 1.05 is the fast-clock trigger. Item 106 is the annual narrative.

Three operative pieces matter for the 8-K:

  1. The trigger is a "cybersecurity incident" the registrant has determined to be material.
  2. The deadline is four business days after the materiality determination.
  3. The required content is "the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations."

Two narrow deferrals exist. The U.S. Attorney General may permit a delay if immediate disclosure poses a substantial risk to national security or public safety, with written notice to the SEC. The second carve-out is for FCC-regulated communications providers under specific breach-notification rules.

Neither is a general "we are still investigating" extension, and treating them that way is how a deferred-disclosure case gets opened against you.

Item 1.05 is for material incidents only. Use Item 8.01 for the rest.

On May 21, 2024, Erik Gerding, then Director of the Division of Corporation Finance, said that companies disclosing an incident they have not determined to be material, or have not yet assessed, should use a Form 8-K item other than Item 1.05. Item 8.01 (Other Events) is the suggested home. The point was to keep Item 1.05 as a clean signal that the company concluded an incident was material.

Filing practice shifted within months. Voluntary, non-material disclosures now cluster under Item 8.01 while Item 1.05 stays reserved for the material call. A GC choosing the wrong item is not committing a violation, but is muddying the signal the SEC wanted protected.

Two years in, the filing record backs the split. As of the Debevoise Form 8-K tracker's two-year update, May 21, 2026, 29 issuers had filed under Item 1.05 for material incidents while 50 filed under Item 8.01 for events that were undetermined or non-material. Only 5 issuers filed under both, and each followed the same sequence: an initial Item 8.01, then an Item 1.05 once the materiality call landed. Most Item 8.01 disclosures never converted to a 1.05. The optional route is now the default, and the mandatory one is the exception the SEC intended it to be.

Here is how the three provisions actually divide the work:

ProvisionWhat it isTriggerClockWhat a filing signals
Item 1.05 (8-K)Material-incident reportYou determine an incident is material4 business days from the materiality determinationThe company concluded this incident was material
Item 8.01 (8-K)Voluntary "Other Events" disclosureAny incident you choose to surface (non-material or undetermined)NoneTransparency without conceding materiality
Item 106 (10-K, Reg S-K)Annual governance narrativeEvery fiscal yearThe 10-K cycleHow the company manages and oversees cyber risk

A month later, on June 24, 2024, the Division added five Compliance and Disclosure Interpretations (C&DIs 104B.05 to .09) on ransomware. The headline: paying a ransom, and the incident appearing to stop, does not relieve you of assessing materiality and disclosing under Item 1.05 if the call comes out material. The size of the payment can itself be a materiality input.

One more timing nuance the rule text carries: the materiality determination has to be made "without unreasonable delay" after discovery. You control when the clock starts by deciding materiality, but you cannot park an obviously material incident in permanent assessment. The SEC reads "without unreasonable delay" as days, not weeks.

"Material" is the GC's call, and it is not new law

Item 1.05 inherits the materiality standard from TSC Industries, Inc. v. Northway, Inc., 426 U.S. 438 (1976): information is material if there is a substantial likelihood that a reasonable shareholder would consider it important to a voting or investment decision (extended in Basic Inc. v. Levinson, 485 U.S. 224 (1988)). The application to cyber is what is new.

What changes is the input. Traditional materiality analysis has a legible fact pattern: an earnings miss, a product recall, a pending acquisition. The numbers are knowable.

In a cyber incident at hour twelve, the input is a CISO saying "we see evidence of lateral movement, the blast radius is uncertain, we believe the attacker is no longer in the environment but cannot confirm." The test has not changed; the evidence has gotten murkier.

The adopting release is explicit that materiality sweeps in qualitative factors, not just quantitative impact. Reputational harm, customer relationships, regulatory exposure, the nature of the data exfiltrated, and second-order operational impacts are all in scope.

A ransomware incident that costs less than 1% of revenue can still be material if it took the customer-facing platform offline for a week or if regulated data left the environment.

The determination needs to be a documented, dated, multi-disciplinary call, not an after-the-fact rationalization. If the IR plan does not specify who convenes, who participates, what the criteria are, and how the determination is memorialized, the GC is improvising.

Improvisation does not hold up in an SEC examination.

The SEC Item 1.05 four-business-day disclosure clock

The Item 1.05 clock starts when you determine materiality, not at discovery.

The four-business-day clock, with the bear traps

The clock starts on the date of materiality determination, not on the date of detection. The SEC was deliberate about this.

Pinning the clock to detection would chill investigation or generate premature disclosure. Pinning it to determination preserves judgment, which is the right design and also the part the SEC will scrutinize hardest.

That choice creates three predictable failure modes:

Failure mode one: structuring the investigation to never trigger the determination. If the IR process is engineered so that materiality is "still being assessed" three weeks in while the company negotiates with the threat actor, the clock has not been avoided.

In retrospect, the fact pattern will read as deliberate deferral. The October 2024 settlements with Unisys, Avaya, Check Point, and Mimecast turned on the same point: the disclosure has to track what the company actually knows.

Failure mode two: the "still investigating" 8-K. Several early Item 1.05 filings have been thin: "We experienced a cybersecurity incident. We are investigating. We do not yet know the impact." Sometimes that is the right filing.

It also sometimes needs amendment within a week, and an amended 8-K invites questions about what the company knew when. Be honest about incompleteness without hiding behind it, and be ready to file a 1.05/A.

Failure mode three: confusing customer notification with shareholder disclosure. State breach-notification statutes (CCPA, the New York SHIELD Act, the GLBA Safeguards Rule) and contractual clauses run on their own clocks and thresholds. None of them satisfies Item 1.05, and Item 1.05 does not satisfy them.

The GC runs parallel streams with different audiences, standards, and sign-off chains. The mistake is letting one timeline drive another.

The internal coordination problem

The hard part of Item 1.05 is not the legal analysis. It is the org chart.

A material cyber incident pulls together a set that does not normally meet on a four-day clock: legal (GC and securities counsel), security (CISO, infrastructure leads, third-party IR firm), investor relations, the audit committee chair, the CFO, the CEO, outside counsel, and a forensic vendor.

The CISO is describing TTPs, the CFO is asking about cost accruals, IR is drafting the holding statement, and securities counsel is writing a draft 8-K against a fact pattern that changes every six hours.

The IR plan has to name the room. There needs to be a standing disclosure committee for cyber incidents with a named convener (almost always the GC), named alternates, a defined quorum, and a documented decision protocol that specifies what the call looks like when half the facts are in motion, what dissent looks like, and how the determination is memorialized.

Item 106 requires annual disclosure of how the board oversees cybersecurity risk, which means a regular reporting cadence to the audit committee or a designated cyber subcommittee. That cadence is what makes the committee's involvement on incident day plausible rather than improvised.

If the committee has not seen a cyber report in eighteen months, its sudden engagement on day two is a risk indicator, not a strength.

Decision tree: from detection to disclosure

The IR plan should produce, on demand, a one-page decision tree the committee runs in the room:

Loading diagram...

Detection starts the investigation clock. Only the materiality call starts the four-business-day Item 1.05 clock.

  1. Incident detected. Security operations confirms the event meets the internal definition of "incident" (not every alert qualifies). Internal investigation clock starts; materiality clock does not.
  2. Triage. Within 24 to 48 hours, the IR lead delivers a scoping memo: systems affected, data categories at risk, attacker access status, containment posture, business impact so far.
  3. Initial materiality screen. The disclosure committee convenes and asks two questions: is there a reasonable basis to determine materiality now, and if not, what specific facts are missing. If yes, the four-business-day clock starts on this date.
  4. If material: draft and file. Securities counsel drafts within the window, IR coordinates the holding statement, CEO and CFO sign, file.
  5. If not yet determined: document and re-screen. The committee records the facts driving deferral, names what would change the analysis, and calendars a re-screen. Deferral is a step, not a verdict.
  6. If DOJ deferral sought: the GC, with outside counsel, makes the referral and tracks the written determination back to the SEC.
  7. Amend as facts develop. File a 1.05/A when the picture changes materially. Amendment is a feature of the regime, not a failure.

Every step is dated, named, and documented. That is what survives an enforcement inquiry years later.

What the enforcement record actually says

Five reference points define how the SEC is reading this rule. The enforcement posture shifted in 2025, so read the SolarWinds entry with its ending, not its filing.

SolarWinds, and how it ended. SEC v. SolarWinds Corp. and Timothy G. Brown, filed October 30, 2023 in S.D.N.Y., named both the company and its CISO. The complaint alleged public risk disclosures were misleading given the internal record of known vulnerabilities.

On July 18, 2024, Judge Paul Engelmayer dismissed most of the case, leaving only statements in the company's website Security Statement. The SEC then dismissed the remaining claims with prejudice on November 20, 2025. The takeaway is not that controls do not matter. It is that the agency under the current administration is pursuing clear false statements in investor-facing disclosures, not nuanced disclosure-controls theories.

The four-company sweep. The one set of Item 1.05-era settlements that stuck came on October 22, 2024, when the SEC charged Unisys, Avaya, Check Point, and Mimecast for materially minimizing SolarWinds-related intrusions in their public disclosures (SEC press release 2024-174). Penalties ran from $990,000 to $4 million, about $7 million combined. Each company described real, known intrusions as hypothetical or limited. That gap, known fact versus softened disclosure, is the live enforcement risk.

Clorox. Clorox disclosed a cyberattack in August 2023 that took manufacturing offline and produced multi-quarter financial impact the company quantified in subsequent filings. The disclosure drew scrutiny over scoping and timing.

The 2026 lesson: how do you frame an ongoing operational disruption when the financial picture sharpens over multiple reporting periods.

MGM Resorts. The September 2023 social-engineering attack against MGM became the textbook example of an incident whose operational impact (closed gaming floors, manual check-ins, days of service degradation) was visible to the public long before any internal materiality determination could be completed.

When the public can see the impact, the company's timing has to be defensible against the obvious counterfactual.

UnitedHealth and Change Healthcare. The February 2024 attack on Change Healthcare, a UnitedHealth subsidiary, raised the scoping question every conglomerate needs to plan for: when an incident hits a subsidiary, who decides materiality at the parent level, and on what timeline.

The disclosure cadence and cost accruals that emerged over later quarters illustrate the multi-period nature of "material impact" for cyber events.

Across all five, the SEC is not running a stopwatch on detection. It is reading the candor of the disclosure against the internal record. The companies that get into trouble are not the ones that take a beat to determine materiality. They are the ones whose filings said less than what they already knew.

For the full enforcement picture, including the FY2025 results and where the risk sits now, see SEC cybersecurity disclosure 2026 enforcement update.

The SEC is not running a stopwatch on detection. It is reading the candor of the disclosure against the internal record.

Pre-incident readiness: the actual deliverable

If a GC reads only one section of this post, it should be this one. The 8-K is the easy artifact. The hard artifact is the readiness package that should sit on a shared drive with controlled access before any incident.

IR plan with disclosure decision points baked in. Most IR plans are written by security teams for security teams. They contain the detection, containment, eradication, and recovery phases the NIST Cybersecurity Framework expects. They often do not contain the disclosure decision tree above.

The fix is editorial: add named decision points for materiality screening, with the GC or designee as convener, and integrate the disclosure-committee protocol as an annex.

Documented materiality framework. The framework should enumerate the quantitative screening signals the company uses (revenue impact, restoration cost, customer count affected, regulated-data volume) and the qualitative factors (reputational exposure, regulatory exposure, contractual notification triggers, nature of data).

State explicitly that no quantitative threshold is dispositive. Materiality is a judgment, not a calculation, and the committee's job is to document the reasoning.

Tabletop exercises with the actual room. A tabletop the legal team runs alone is a comfort exercise. A tabletop where the CISO, CFO, head of IR, audit committee chair, and outside securities counsel work through a fact pattern together is the readiness exercise.

The output is the list of seams that broke under pressure: who could not be reached, which authority was unclear, which template did not exist. Two tabletops a year is the cadence; one is the floor.

Board reporting cadence. Item 106 describes board oversight. Its credibility depends on the underlying record. A quarterly written report to the audit committee, with at least one in-person executive session a year, is a defensible baseline.

The report should cover the threat picture, control posture, material incidents (including ones that did not reach disclosure), and known gaps. Minutes should reflect substantive discussion, not a single acknowledgment line.

Pre-cleared 8-K skeleton. Securities counsel should have a draft Item 1.05 form with headers populated and placeholder language. The same goes for an IR holding statement, customer notification templates by jurisdiction, and a board notification email. Together these save three to five hours on the day.

FAQ

What is Item 1.05 of Form 8-K? Item 1.05 is the SEC rule that requires a public company to disclose a material cybersecurity incident on Form 8-K. It was added by Release No. 33-11216, adopted July 26, 2023. The filing describes the material aspects of the incident's nature, scope, and timing, and its material or reasonably likely material impact on the company.

When does the four-business-day clock start under Item 1.05? It starts when the company determines the incident is material, not when the incident is detected. The materiality determination itself must be made without unreasonable delay after discovery, which the SEC reads as days rather than weeks. So you do not control whether to decide, only the reasonable window for deciding.

What makes a cybersecurity incident material for SEC disclosure? The standard is the TSC Industries test: would a reasonable investor consider the information important to a voting or investment decision. It sweeps in qualitative factors, not just dollars: reputational harm, the nature of data exfiltrated, regulatory exposure, and operational disruption. An incident under 1% of revenue can still be material if it took a customer-facing system offline or exposed regulated data.

What is the difference between Item 1.05 and Item 8.01 for cyber incidents? Item 1.05 is for incidents you have determined are material. Item 8.01 (Other Events) is the home for voluntary disclosure of incidents that are not material, or where you have not yet decided. On May 21, 2024, the SEC's Division of Corporation Finance asked companies to keep Item 1.05 reserved for material incidents and use Item 8.01 for the rest.

What is Item 106 of Regulation S-K? Item 106 is the annual companion to Item 1.05. It requires 10-K disclosure of how the company manages cybersecurity risk, its strategy, and how the board and management oversee that risk. Item 1.05 is the fast-clock incident trigger; Item 106 is the yearly governance narrative.

Can a company delay an Item 1.05 disclosure? Only in narrow cases. The U.S. Attorney General can permit a delay if immediate disclosure poses a substantial risk to national security or public safety, with written notice to the SEC. A separate carve-out covers certain FCC-regulated communications providers. Neither is a general "still investigating" extension.

Does paying a ransom remove the duty to disclose under Item 1.05? No. In June 2024 C&DIs, the SEC said paying a ransom, and the incident appearing to stop, does not relieve a company of assessing materiality and disclosing under Item 1.05 if the incident is material. The size of the ransom can itself be a materiality input.

How many companies have filed an Item 1.05 8-K? Few, by design. Two years into the rule, the Debevoise Form 8-K tracker (May 21, 2026) counted 29 issuers filing under Item 1.05 for material incidents against 50 filing under Item 8.01 for undetermined or non-material events. Only 5 filed under both, always starting with an 8.01 and adding a 1.05 once materiality was determined. The low Item 1.05 count reflects the SEC's intent that it flag genuinely material incidents, not every intrusion.

Is the SEC cybersecurity disclosure rule still in effect after the SolarWinds dismissal? Yes. The SEC dismissed its SolarWinds case with prejudice on November 20, 2025, but the Item 1.05 and Item 106 rules remain in force. The enforcement focus narrowed toward clear false or misleading statements in investor-facing disclosures rather than broad disclosure-controls theories.

The position worth defending

Item 1.05 is sometimes pitched as a heavy new burden. That framing is wrong. The substantive law (the TSC standard, the duty to disclose what the company knows, the prohibition on materially misleading statements) was already there.

Item 1.05 added a specific trigger, form, and clock in a domain where prior practice was wildly inconsistent. Companies with mature disclosure controls extended them. Companies without are discovering the gap was always a risk; the rule just made it visible.

The GC's job in 2026 is not to memorize the rule. It is to build the room. Name the convener, write the framework, run the tabletop, set the board cadence, put the templates in place.

The 8-K, when it comes, will write itself in the four-business-day window because the work was done in the year before.

For related operational playbooks, see AI Governance Policy for In-House Legal, Legal Department KPIs in 2026, the AI compliance check for CCPA, GDPR, and SOX, and the vendor security questionnaire guide.

Vaquill AI helps GC teams keep the current Item 1.05 and Item 106 text inside the workflow and draft the disclosure package against it, so the readiness work is done before the incident. See compliance check.

Legal AI that reads your documents and knows the law.
Ask a legal question, review a contract, or search thousands of your files. Every answer shows where it came from. 7-day free trial, no card.
Updated July 3, 202621 min read

New legal AI guides, weekly.

Arshita Anand

Arshita Anand

Co-Founder & CEO · Attorney

Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.