· BreachTrigger
SEC Item 1.05 vs Regulation S-K Item 106: The Two-Part Cybersecurity Rule
Short answer: The SEC's cybersecurity disclosure rule, adopted in 2023 under Release No. 33-11216, actually has two separate parts that get conflated constantly. Item 1.05 of Form 8-K (governed by 17 CFR 249.308) requires a company to disclose a specific material cybersecurity incident within four business days of determining it is material. Item 106 of Regulation S-K (17 CFR 229.106) is a completely different requirement: an annual, standing description of the company's cybersecurity risk management processes, strategy, and board oversight, disclosed in the Form 10-K. One is an event report, filed on demand; the other is a governance snapshot, filed once a year. BreachTrigger monitors the first.
What does 17 CFR 229.106 actually require?
Regulation S-K Item 106, "Cybersecurity," is the annual-disclosure half of the rule. Reading the regulation itself at law.cornell.edu/cfr/text/17/229.106 (mirroring the official Code of Federal Regulations text), the requirement breaks into four disclosure areas a registrant must address every year in its Form 10-K:
- Risk management processes. How the company assesses, identifies, and manages material risks from cybersecurity threats, including whether it engages third-party assessors and how it oversees risk from its service providers.
- Business impact. Whether cybersecurity threats or prior incidents have materially affected, or are reasonably likely to materially affect, the company's business strategy, results of operations, or financial condition.
- Board oversight. How the board of directors supervises cybersecurity risk, and which board committee (if any) is responsible.
- Management's role. Which management positions or committees are responsible for assessing and managing cybersecurity risk, their relevant expertise, and how they inform the board.
This is disclosure about a process, not an event. A company with zero incidents in a given year still has to describe its risk-management posture in Item 106.
What does Item 1.05 of Form 8-K require?
Item 1.05 lives inside Form 8-K itself, which is authorized under 17 CFR 249.308 as the current-report filing mechanism under the Securities Exchange Act of 1934. Added by the same 2023 rule, Item 1.05 requires disclosure of:
- The nature, scope, and timing of the incident.
- The material impact, or reasonably likely material impact, on the company's financial condition and results of operations.
The trigger is materiality, judged by the reasonable-investor standard, and the clock is four business days from the date the company determines the incident is material, not from the date the incident occurred. A limited delay is available only if the U.S. Attorney General determines immediate disclosure would pose a substantial national security or public safety risk.
Side-by-side comparison
| Item 1.05 (Form 8-K) | Item 106 (Regulation S-K) | |
|---|---|---|
| CFR citation | 17 CFR 249.308 (Form 8-K) | 17 CFR 229.106 |
| What it discloses | One specific material incident | Standing risk management process |
| Filing | Current report, as events occur | Annual, inside Form 10-K |
| Deadline | 4 business days from materiality determination | Once per fiscal year, with the 10-K |
| Is it forward-looking? | No, it describes what happened | Yes, it describes ongoing governance |
| Where BreachTrigger looks | Every 30 minutes, via EDGAR full-text search | Not monitored, read the 10-K directly |
Why the distinction matters for monitoring
If you are trying to catch news of an actual breach at a vendor, partner, or portfolio company, Item 1.05 is the filing that matters, it is event-driven and shows up the moment a company determines materiality. Item 106 disclosures are useful for diligence and vendor risk assessment (does this company describe a real incident-response process, or boilerplate?) but they will not tell you a new breach just happened. BreachTrigger polls SEC EDGAR full-text search every 30 minutes specifically for Item 1.05 filings, and separately flags voluntary Item 8.01 cyber disclosures, because those are the two places a fresh incident shows up between 10-K cycles.
Legal disclaimer
This post is informational only and is not legal, financial, or investment advice. Regulation citations are provided for reference; always read the current regulation text directly at law.cornell.edu or the official eCFR, and consult securities counsel for compliance decisions. The SEC's final rule (Release No. 33-11216) is the authoritative source; verify current requirements at sec.gov before relying on any summary, including this one.
Related reading
- SEC 8-K Item 1.05 Cybersecurity Disclosure: What It Is and What Companies Must Report
- SEC Cybersecurity Disclosure Rules: The 4-Business-Day Deadline Explained
- Cybersecurity Incident Materiality: How Companies Decide When a Breach Is 8-K Reportable
BreachTrigger polls SEC EDGAR every 30 minutes for new Item 1.05 filings and alerts you the same day, with sector and ticker filters. Not legal, security, or investment advice, verify every filing on sec.gov/edgar before acting.
Last updated: August 5, 2026.
Frequently asked questions
- Is Item 1.05 the same as Item 106?
- No. Item 1.05 is a Form 8-K item, codified under 17 CFR 249.308, that requires disclosure of a specific material cybersecurity incident within four business days. Item 106 is a Regulation S-K item, codified at 17 CFR 229.106, that requires an annual, forward-looking description of a company's cybersecurity risk management, strategy, and governance in its Form 10-K. One reports an event; the other describes a standing process.
- Where do I read the actual regulation text?
- 17 CFR 229.106 (Item 106, Cybersecurity) is published in the Code of Federal Regulations and mirrored at law.cornell.edu/cfr/text/17/229.106. The 2023 final rule that created both items is SEC Release No. 33-11216, available at sec.gov. Form 8-K itself, including the Item 1.05 requirement, is governed by 17 CFR 249.308.
- Does BreachTrigger track Item 106 annual disclosures too?
- No. BreachTrigger is scoped to Item 1.05 (and voluntary Item 8.01) 8-K filings, the event-driven disclosures that show up between 10-K filing dates. Item 106 disclosures live inside the annual 10-K itself and are not a same-day alerting product's natural fit; read them directly in each company's 10-K on EDGAR.