BREACH/TRIGGERBlog

· BreachTrigger

SEC 8-K vs state data breach notification laws

TL;DR: SEC Item 105 is investor-focused disclosure of material cyber incidents for public companies, state breach-notification laws require notice to affected individuals and regulators and both can apply to the same incident.

SEC 8-K vs state data breach notification laws

SEC Item 105 is investor-focused disclosure of material cyber incidents for public companies, state breach-notification laws require notice to affected individuals and regulators and both can apply to the same incident.

TL;DR

SEC 8-K Item 105 (cybersecurity disclosure) and state data breach-notification laws are different obligations. The SEC rule requires public companies to disclose material cyber incidents to investors via SEC filings. State laws require notice to affected individuals and regulators under state-specific thresholds and content requirements. A single incident can trigger both because they target different audiences and use different triggers and procedures.

Direct answer: SEC 8-K Item 105 focuses on investor-facing disclosure of material cybersecurity incidents by public companies. State breach-notification laws require notice to affected individuals and state authorities under each state's rules. They are parallel obligations and one does not automatically satisfy the other.

What is SEC 8-K Item 105 cybersecurity disclosure?

Item 105 requires public companies to provide investor-facing disclosure about material cybersecurity incidents and about cybersecurity risk management and governance. The disclosure centers on facts a reasonable investor would consider material: the incident's nature and scope, any known material impact on operations or finances, remediation steps, and how the board and senior management are overseeing the issue. Item 105 is about market transparency, not individual privacy remediation or consumer credit protection.

State data breach notification laws: scope and common elements

Most U.S. states have statutes that trigger notice obligations when personal information is acquired or reasonably believed to be acquired by an unauthorized party. These laws define covered entities broadly and define personal information in state-specific ways. Common elements include a trigger based on unauthorized acquisition, required notice to affected individuals, potential notice to state attorneys general, and in some cases notice to consumer reporting agencies.

Required notice content is usually practical: a description of the incident, the types of information exposed, recommended steps for affected individuals, and contact information for the notifying entity. States differ on which data elements change the notice calculus, how encrypted data is treated, and whether there are exceptions for good-faith employee access or inadvertent exposure. Because state law is a patchwork, incidents affecting residents of many states require a multi-jurisdictional analysis.

Where they overlap and diverge (comparison table)

Topic SEC 8-K Item 105 State breach-notification laws
Purpose Investor-facing disclosure of material cybersecurity incidents and governance Protect individuals whose personal information was exposed and inform regulators where required
Legal trigger Materiality to investors, assessed by the public company Unauthorized acquisition or access of personal information as defined by each state
Audience Investors, market participants, SEC Affected individuals, state regulators, sometimes credit reporting agencies
Typical timing language Market-sensitive prompt disclosure when material (fact-specific) State-specific notice timing requirements and promptness standards; varies by statute
Required notice contents Description of material incident and its impact, remediation steps, governance and risk management details where material Practical details for individuals: what was exposed, recommended actions, contact information, and statutory language required by each state
Enforcement remedies SEC enforcement, potential investor lawsuits, market consequences State enforcement actions, statutory penalties or remedies in some states, private suits under state law in certain cases

Worked example: applying both regimes to a single incident (high-level, no invented numbers)

Scenario, short and human: the security team discovers unusual exfiltration of data. First, preserve logs and evidence and stand up an incident response team. Second, conduct an internal legal-materiality assessment for SEC disclosure: could this incident reasonably be material to investors given the company's operations, contracts, financial position, or reputation? Third, run a state-by-state privacy analysis to identify whose personal information was exposed and which state laws are triggered. Parallel workstreams often converge because the same factual record informs both analyses, but legal conclusions can differ. Communicate consistently: craft internal and external messages that meet state notice content requirements and also ensure investor disclosures are accurate and not misleading. Document decisions and board-level briefings so the company can demonstrate it treated both obligations seriously.

Practical compliance steps and recommended playbook

Checklist and roles

  • Immediately preserve forensic evidence and create an incident log, including a timeline of discovery, containment, and remediation steps.
  • Assemble a cross-functional incident response team: security, legal (securities and privacy), communications, compliance, and relevant business leaders.
  • Conduct a fact-based materiality analysis for SEC disclosure, involving securities counsel and senior management.
  • Conduct a state-by-state coverage analysis for breach-notification triggers, with privacy counsel mapping affected individuals by jurisdiction.
  • Prepare coordinated messaging templates: investor-facing language for SEC filings, consumer notice templates that meet state content requirements, and press/FAQ language.
  • Coordinate timing, ensuring investor disclosures remain accurate while meeting state notice obligations. Legal counsel should document the bases for timing decisions.
  • Notify and brief the board and audit or risk committee as part of governance obligations, with clear records of who approved disclosures and notices.
  • Keep meticulous records of communications, investigations, remediation measures, and regulatory contacts.

Avoid treating one regime as a substitute for the other. Use input from both securities and privacy counsel before finalizing public or consumer-facing communications.

Implications, enforcement and best practices

Both regimes carry enforcement risk, so prioritize documentation, governance, and careful coordination to reduce legal and reputational exposure.

The SEC may investigate whether a company made timely and accurate disclosures under Item 105 and related securities obligations. State attorneys general or regulators may pursue enforcement under breach-notification statutes, and affected individuals may assert private claims under state laws or other theories. Consistent documentation is invaluable: preserve investigation notes, legal analyses, board minutes, and decision logs. Best practices include pre-authorized playbooks that integrate securities and privacy analyses, tabletop exercises that cover parallel obligations, clear escalation paths to the board, and pre-approved template language that legal teams can adapt quickly.

FAQ

Q: Does filing an 8-K satisfy state breach-notification requirements?

A: No, they serve different legal audiences and requirements, so you must evaluate and comply with both separately.

Q: Are privately held companies subject to SEC Item 105?

A: No, Item 105 applies to public companies; private companies still must follow state breach-notification laws where applicable.

Q: Which obligation should be prioritized if timing conflicts arise?

A: Prioritize legal analysis and counsel to comply with both; coordinate communications to avoid undermining either obligation and document decision-making.

Q: Can responding quickly to customers create problems for SEC disclosure?

A: Rapid remediation and customer notices are prudent, but public companies should ensure investor disclosures remain accurate and update the market as material facts evolve; involve legal counsel.

Closing / next steps for readers

Do a quick gap review, call securities and privacy counsel, and update your incident response and disclosure playbooks so you're ready the next time the pager goes off.

Treat this as a prompt to run a tidy gap assessment, get counsel involved early, and make your next tabletop realistic enough that it wakes people up. If you need help translating these steps into checklists or playbook text, consult your securities and privacy counsel to tailor actions to your company's facts and jurisdictions.