BREACH/TRIGGERBlog

· BreachTrigger

What is SEC 8-K Item 1.05 cybersecurity disclosure

TL;DR: Item 1.05 requires SEC registrants that file Form 8-K to promptly disclose material cybersecurity incidents, focusing on what happened, timing, scope, impact, data exfiltration, remediation status, and updates. The key is a cross-functional materiality decision, timely filing after the date of determination, and careful but narrow redactions when disclosure would hamper response or an investigation.

What is SEC 8-K Item 105 cybersecurity disclosure?

Item 1.05 requires SEC registrants that file Form 8-K to promptly disclose material cybersecurity incidents, focusing on what happened, timing, scope, impact, data exfiltration, remediation status, and updates. The key is a cross-functional materiality decision, timely filing after the date of determination, and careful but narrow redactions when disclosure would hamper response or an investigation.

Why Item 1.05 exists and who it covers

The SEC requires prompt public notice when a registrant suffers a cybersecurity incident that is material to investors. The rule applies to companies required to file Form 8-K, and the goal is timely market transparency while protecting ongoing response and investigations.

Item 1.05 gives investors quick, comparable facts when cyber incidents could affect a public company's business, operations, or financial condition. It covers registrants that file Form 8-K, so U.S. reporting companies and others subject to those filing obligations must pay attention. The underlying policy is simple: investors deserve early notice of material risks, and markets work better when material cybersecurity events are disclosed on a standardized, prompt basis.

What Item 1.05 requires - core disclosure elements

Companies must describe the incident, its timing and scope, any impact, whether data was exfiltrated or systems remain compromised, and provide updates. Firms may omit or redact narrowly certain technical details when disclosure would increase risk or law enforcement requests a delay.

Item 1.05 focuses on the facts investors need to assess material impact. Typical core elements are:

  • A brief, factual description of the incident, including what happened and how it was discovered.
  • Timing, meaning when the incident occurred and when it was discovered, stated with useful precision.
  • Scope, describing which systems, business units, geographies, or types of data were affected.
  • Whether the company believes data or other information was exfiltrated, altered, or destroyed.
  • Whether systems remain compromised or whether remediation has restored normal operations.
  • Known or reasonably likely financial or operational impacts, including effects on customers, suppliers, or the company's ability to perform critical functions.
  • Information about notifications to law enforcement or regulators, when relevant.
  • Updates to earlier disclosures when new material information becomes available.

There are limits to granular technical exposition. Companies commonly redact or omit detailed forensic information, exploit or vulnerability specifics, and step-by-step remediation tactics when disclosure would meaningfully facilitate further intrusion or hamper remediation. Many firms coordinate with law enforcement or incident responders, and they should explain when information is omitted and why, rather than leaving a vacuum.

Determining materiality and the filing trigger

Materiality is a judgment that should involve legal, security, finance, investor relations, and the board. The filing trigger is the date the company determines the incident is material.

Materiality should be a cross-functional determination, not a solo call by the CISO or general counsel. Inputs typically include legal, cybersecurity, finance, investor relations, and, when appropriate, senior management or the board. The key operational concept is the date of determination, the specific day the company concludes the incident is material and therefore reportable under Item 1.05. Once that date is set, the Form 8-K timing clock begins.

Practical indicators that an incident likely meets the materiality threshold include operational outages affecting revenue or customer service, unauthorized access or theft of customer personal data or intellectual property, significant remediation costs that will affect results, major contractual breaches or customer notices, or regulatory obligations triggered by the incident. If multiple indicators are present, lean toward filing sooner rather than later. Document the reasons for materiality decisions thoroughly, because disclosure obligations and enforcement questions often turn on the contemporaneous record.

Comparison table: Item 1.05 incident reporting vs. periodic cybersecurity governance disclosures

Item 1.05 is for prompt incident reporting; periodic cybersecurity governance disclosures cover ongoing risk management and governance topics with different timing and content needs.

Feature Item 1.05 incident Form 8-K Periodic cybersecurity governance disclosures (e.g., 10-K, proxy)
Scope Specific material cyber incidents Ongoing risk, governance, policies, risk management program
Timing Prompt, triggered by determination of materiality Periodic, typically annual or proxy-cycle updates
Frequency Event-driven, can be multiple times a year Periodic, tied to filing calendar (annual, proxy)
Typical content Incident facts, timing, scope, impact, data exfiltration, remediation status, law enforcement notifications Board oversight, management responsibility, risk assessment processes, policies, metrics, and strategy
Examples when used Ransomware causing service outage; exfiltration of customer data that impacts financials Annual disclosure of cybersecurity risk management program or board cybersecurity expertise

These two disclosure streams should be coordinated. Item 1.05 gives investors immediate facts about a specific event, while periodic disclosures provide the broader context for how the company manages cyber risk.

Common pitfalls, enforcement risk, and examples of disclosure mistakes to avoid

Frequent errors include late filing, vague or boilerplate language, inconsistent updates, and over-redaction. The SEC expects clear, timely, factual disclosures; sloppy Item 1.05 filings can attract scrutiny and confuse the market.

Common pitfalls to avoid:

  • Waiting too long to decide materiality and missing the filing window.
  • Offering vague, generic statements like we are "investigating" with no meaningful specifics for an extended period.
  • Changing the factual story without documenting why new facts alter earlier conclusions.
  • Over-redacting or withholding the existence of a material incident.

Enforcement risk centers on failure to timely disclose material information and on misstatements or omissions that materially mislead investors. Even without malice, poor documentation of the materiality analysis or inconsistent public statements can create regulatory and civil exposure.

Illustrative examples, synthetic and generic, to show the difference between poor and clearer Item 1.05 summaries:

  • Poorly drafted Item 1.05 sample: "We experienced a cybersecurity incident. We are investigating and will provide updates as appropriate." This is unhelpful. It leaves investors guessing about timing, scope, and impact.

  • Clearer Item 1.05 sample: "On [date discovered], we identified unauthorized access to our payroll system affecting employee records. We have isolated the affected servers, engaged external forensic specialists, notified law enforcement, and have no evidence to date that payroll data was exfiltrated. We estimate remediation costs will be immaterial to our current quarter, and we will update investors if new material information emerges." This one is concise, factual, and signals next steps.

Practical checklist for preparing and updating an Item 1.05 Form 8-K

A clear workflow helps avoid unnecessary risk. This checklist assigns roles, sets timing, and identifies what to document as facts emerge.

  1. Immediate triage and containment - Security leads, with incident response team
    • Isolate affected systems, preserve logs, preserve chain of custody for evidence.
    • Notify internal legal counsel and compliance immediately.
  2. Assemble cross-functional incident team - Legal, security, finance, IR, HR, business unit leads
    • Schedule frequent calls for fact collection and decision making.
  3. Early materiality assessment - Legal leads the determination process with input from others
    • Document the date and reasons for materiality or the decision to monitor further.
  4. Prepare initial Item 1.05 content when material - Legal drafts, security and IR provide facts, IR prepares external messaging
    • Keep the disclosure factual and narrowly focused on material items.
  5. Coordinate with law enforcement and external responders
    • Document any law enforcement requests to delay or redact and the scope of those requests.
  6. File within the required window after the date of determination
    • File the Form 8-K, and ensure internal and external stakeholders know the messaging.
  7. Continue monitoring and update as material new information arises
    • File amendments or additional Form 8-Ks for material updates; post clear public statements for investors.
  8. Preserve documentation for audit and investigations
    • Save incident logs, communication records, forensic reports, and contemporaneous notes on materiality decisions.

Timing tips:

  • Be conservative with the filing clock. If materiality is ambiguous but leaning toward material, escalate to legal and consider filing to avoid late disclosure risk.
  • Limit technical detail in the filed text, but do not omit material effects. If withholding details, explain why and commit to timely updates.

Closing FAQ

Q: Does Item 1.05 apply to all registrants? A: No. Item 1.05 applies to registrants required to file Form 8-K, meaning U.S. reporting companies and other entities subject to Form 8-K obligations. If your company files 8-Ks, Item 1.05 can apply.

Q: Can a company delay disclosure at law enforcement request? A: Yes, often. Companies frequently coordinate with law enforcement and may omit or delay specific technical details if a law enforcement request would protect an investigation or remediation. The omission or delay should be narrowly tailored, documented, and disclosed in form language explaining why information was omitted and when it may be provided.

Q: Are vendor or third-party incidents reportable? A: Yes, if a third-party or vendor incident has a material impact on your business, it triggers Item 1.05. The focus is on your company's exposure and effects, not who was initially breached.

Q: How should companies balance disclosure with privilege and confidentiality? A: Use narrow, documented redactions and legal counsel input. Preserve privilege where appropriate, but do not use privilege as a blanket block to avoid required disclosure. When in doubt, consult counsel and document the decision process.