BREACH/TRIGGERBlog

· BreachTrigger

SEC 8-K Item 1.05: The 4-Day Cybersecurity Disclosure Rule

Public companies face a new reality: major cybersecurity incidents are no longer optional disclosures to shareholders. Since December 18, 2023, the SEC has required material cybersecurity incidents to be reported on Form 8-K Item 1.05 within four business days of the materiality determination.

This guide breaks down Item 1.05 in plain English: what qualifies as a required disclosure, what companies must include, timing rules, permitted delays, and how to stay compliant.

TL;DR

SEC 8-K Item 1.05, titled "Material Cybersecurity Incidents," requires public companies to disclose material cybersecurity incidents within four business days of determining the incident is material, not four business days from discovery. "Material" means incidents that a reasonable investor would find important when making investment decisions, typically ransomware attacks, data exfiltration affecting customer data, system shutdowns, or breaches affecting confidentiality or integrity of personal data. Companies must describe the material aspects of the incident's nature, scope, and timing, and its material impact or reasonably likely material impact on the company, including financial condition and results of operations. A delay is available only if the U.S. Attorney General determines that disclosure would pose a substantial risk to national security or public safety and notifies the SEC in writing. Failure to disclose can trigger SEC enforcement actions, fines, officer sanctions, and reputational damage.


What Is SEC 8-K Item 1.05 Cybersecurity Disclosure?

Item 1.05, titled "Material Cybersecurity Incidents," is a new disclosure item added to Form 8-K (Current Report) by the SEC's final rule, Release No. 33-11216, adopted in July 2023 and effective September 5, 2023, with compliance required beginning December 18, 2023 for most filers (smaller reporting companies got until June 15, 2024). Form 8-K itself is a filing that public companies must submit under Exchange Act Rules 13a-11 and 15d-11 to report specified "material events," major corporate developments like mergers, leadership changes, bankruptcy, or, since the new rule, material cybersecurity incidents.

Item 1.05 requires a company to describe the material aspects of the nature, scope, and timing of a cybersecurity incident, and its material impact or reasonably likely material impact on the company, including its financial condition and results of operations, once the company determines the incident is material.

Note: Item 1.05 should not be confused with Item 2.05 of Form 8-K, which is a separate, unrelated disclosure item titled "Costs Associated with Exit or Disposal Activities" and covers restructuring charges, not cybersecurity incidents.

The rule applies to all companies subject to SEC reporting requirements, roughly 4,000-plus public companies in the U.S. It does not apply to private companies, though state-level breach notification laws and cyber-insurance requirements may impose similar obligations.


When Must Companies File an 8-K for Cybersecurity Incidents?

The triggering event is materiality. If a cybersecurity incident is "material," meaning a reasonable investor would consider it important, the company must file within four business days of that determination.

The SEC does not define a single bright-line threshold (e.g., "losses over $X million" or "more than Y records affected"). Instead, companies must apply a qualitative and quantitative test:

  • Quantitative: Financial impact (direct costs, recovery, remediation, regulatory fines, ransom).
  • Qualitative: Impact on business operations, customer trust, regulatory compliance, intellectual property, or competitive position.

Examples of incidents typically considered material:

  • Ransomware attacks preventing operations for 24+ hours or requiring significant ransom/recovery spending.
  • Data breaches affecting thousands of customer or employee records (personal data like SSN, financial info, health records).
  • Exfiltration of trade secrets or confidential business information.
  • System shutdowns affecting critical business functions (e.g., production, customer-facing services).
  • Regulatory consequences: Loss of license, state AG involvement, or HIPAA/PCI violations.

If a company is uncertain about materiality, the SEC expects it to err on the side of disclosure. Waiting to see if the breach "gets bigger" is not a defense for late filing.


What Specific Information Must Be Disclosed Under Item 1.05?

The final rule narrowed the proposed disclosure list to focus on impact rather than incident detail. Item 1.05 requires a registrant to describe:

  1. Nature, scope, and timing of the incident: What happened and when, described at a level that lets an investor understand the incident.
  2. Material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations. The SEC has said this is not limited to financial figures; qualitative factors like harm to reputation, customer or vendor relationships, or competitiveness, and the possibility of litigation or regulatory action, can also be part of a material impact.

If the required information is not yet determined or available when the filing is due, Item 1.05's Instruction 2 directs the company to say so in the 8-K and then file an amendment with the missing information within four business days after it is determined or becomes available.

The SEC explicitly declined to adopt a requirement to disclose the incident's remediation status, whether it is ongoing, or whether data were compromised, though a company's own materiality analysis may still lead it to discuss those points. Item 1.05's Instruction 4 also states that a registrant need not disclose specific or technical information about its planned incident response or its cybersecurity systems, related networks, and devices, or potential system vulnerabilities, in such detail that it would impede the registrant's response or remediation.

The disclosure should be specific enough for an investor to understand the risk, but not so detailed as to provide a roadmap for other threat actors.


What Qualifies as a "Material" Cybersecurity Incident?

Materiality is the core question. The SEC uses a reasonable investor standard: Would this information influence your decision to buy, hold, or sell the stock?

Factors the SEC considers material:

  • Confidentiality breach: Unauthorized access to or exfiltration of personal, financial, or proprietary data (10,000+ records often tips the scale).
  • Integrity compromise: Modification or deletion of critical systems, inventory, or records (even if data wasn't exfiltrated).
  • Availability loss: Ransomware or DoS attacks shutting down services for 24+ hours; critical business operations impaired.
  • Financial impact: Direct costs, recovery and remediation spending, and effect on results of operations. The SEC has not set a bright-line financial threshold; this is a facts-and-circumstances judgment, not a fixed percentage or dollar figure.
  • Brand/market impact: Public disclosure of breach, customer churn risk, loss of contracts.
  • Regulatory consequences: Triggering state AG investigations, HIPAA fines, PCI non-compliance, or industry-specific penalties.

Edge cases that may NOT be material:

  • Phishing attempts blocked by email filters (no breach occurred).
  • Isolated compromised employee credentials (if properly isolated and rotated).
  • Third-party vendor incidents not affecting your systems or data.
  • Low-volume data exposure (e.g., 50 customer records in a 500,000-customer base).

Best practice: If there's doubt, document the materiality analysis internally and consider disclosing. The SEC views non-disclosure of a material incident more harshly than premature or cautious disclosure.


What Are the Timing Requirements for 8-K Item 1.05 Filings?

Four business days is the hard deadline, but it is measured from the date the company determines the incident is material, not from the date the incident was discovered or occurred. Discovering an incident and determining it is material are two separate steps, and the SEC's final rule expects a company to make that materiality determination "without unreasonable delay" after discovery, so a company cannot indefinitely postpone the determination to push back the filing clock.

Timeline breakdown:

  • Discovery: Incident is detected; investigation begins.
  • Investigation: The company develops enough information to conduct a materiality analysis, without unreasonable delay.
  • Materiality determination: The company concludes the incident is (or is not) material. This starts the four-business-day clock.
  • Filing: Form 8-K Item 1.05 is due within four business days of the materiality determination.

Important nuances:

  • Weekends and holidays don't count: The four-day clock counts only business days, excluding federal holidays.
  • The clock runs from determination, not discovery: A company that unreasonably delays its materiality determination has not avoided the deadline; the SEC can still scrutinize whether the determination itself was made without unreasonable delay after discovery.
  • Preliminary information is acceptable: If required information is not yet determined or available, Item 1.05's Instruction 2 lets a company say so in the initial 8-K and then file an amendment with that information within four business days after it is determined or becomes available.

Can Companies Get a Delay Exception for 8-K Cybersecurity Disclosures?

Yes, but the decision is not the company's to make on its own. Under Item 1.05(c), a registrant may delay filing only if the U.S. Attorney General determines that disclosure would pose a substantial risk to national security or public safety, and notifies the SEC of that determination in writing.

How the delay works:

  1. The initial delay period is specified by the Attorney General, up to 30 days from when disclosure was otherwise due.
  2. That delay can be extended for an additional period of up to 30 days if the Attorney General again determines, in writing, that disclosure continues to pose a substantial risk.
  3. In extraordinary circumstances, a final additional delay of up to 60 days is available, again on written notification from the Attorney General, if the risk to national security continues.
  4. Beyond that, any further delay requires exemptive relief from the SEC itself.

The delay provision does not relieve a company of its other obligations, including Regulation FD and the antifraud provisions of the securities laws. A company cannot self-assert a delay based on an ongoing internal or external investigation, a pending law-enforcement inquiry it initiated, attorney-client privilege, or its own view that disclosure is inconvenient. The mechanism only works through the Attorney General's written determination to the SEC.

If a company incorrectly asserts a delay, or files late without a valid Attorney General determination in place, it faces enforcement risk for late filing.


What Happens if a Company Fails to Disclose Under Item 1.05?

Non-compliance carries significant penalties:

SEC Enforcement Actions:

  • Civil penalties: The SEC can seek civil monetary penalties for disclosure violations; specific per-violation caps are set by statute and adjusted for inflation periodically, check the SEC's current civil penalty schedule at sec.gov before citing a figure.
  • Officer sanctions: SEC can bar executives from serving as officers or directors.
  • Disgorgement: Recovery of ill-gotten gains if executives traded on non-public knowledge of the breach.
  • Cease-and-desist orders: Prohibition on violating disclosure rules in the future.

Secondary Consequences:

  • Shareholder litigation: Investors can file securities class actions arguing they were deprived of material information.
  • Stock price impact: Once a breach becomes public, whether through the company's own filing, third-party reporting, or regulatory action, the market reaction varies by company and incident; the SEC's own economic analysis of the rule cites academic research finding that delayed cybersecurity disclosure can lead to mispricing of securities.
  • Credit rating downgrade: Rating agencies treat undisclosed breaches as governance failures.
  • Cyber-insurance denial: Insurers may deny claims if the insured failed to disclose a prior breach to the SEC.
  • Customer and vendor trust: Clients, partners, and employees lose confidence in the company's governance and security posture.

For actual enforcement actions the SEC has brought under Item 1.05, review the SEC's own enforcement actions and litigation releases rather than relying on a secondhand summary.


How Can Companies Stay Compliant with Item 1.05?

1. Establish a Cyber Incident Response Plan

  • Define materiality triggers (quantitative and qualitative thresholds).
  • Assign roles: IR team, legal counsel, CFO (for cost estimation), investor relations.
  • Create a notification workflow so leadership is informed within hours of discovery.

2. Monitor and Detect Incidents Quickly

  • Deploy SIEM, EDR, and intrusion detection tools to catch breaches fast.
  • Conduct regular penetration testing and tabletop exercises.
  • Train employees to report suspicious activity immediately.

3. Assess Materiality Promptly (Typically Within 24 to 48 Hours)

  • Gather preliminary facts: What systems were hit? What data? How many records?
  • Estimate financial impact (direct recovery costs, potential regulatory fines, ransom).
  • Consult legal counsel: Is this material? Does a delay exception apply?

4. Draft the 8-K Item 1.05 Filing

  • Use plain language; avoid jargon.
  • Include the incident date, type, scope, and impact.
  • Describe immediate mitigation (patches, network isolation, credential rotation).
  • Estimate financial costs; note if insurance may cover some costs.
  • Flag if the investigation is ongoing and an amended 8-K will follow.

For guidance on what past companies disclosed, see our post on 8-K Cybersecurity Incident Disclosure Examples 2026.

5. File Within Four Business Days

  • Coordinate with Investor Relations to file via EDGAR.
  • Maintain a log of disclosure dates for compliance audits.

6. Update Shareholders if Facts Change

  • If forensic findings reveal a larger breach than originally disclosed, file an amended 8-K (Form 8-K/A).
  • If costs are higher than estimated, disclose the update.
  • The SEC expects companies to correct material misstatements promptly.

7. Communicate Externally (Separate from SEC Filing)

  • SEC filing is for investors; customer notification is required by state law (not SEC rule).
  • Time your customer breach notification letter to coincide with or follow the 8-K filing.
  • For employee data breaches, also check your state's employment law requirements.

For details on the SEC's four-business-day rule in context, see SEC Cybersecurity Disclosure Rules: Four Business Days Explained.


Coordination with Other Compliance Requirements

Item 1.05 disclosure does not replace other reporting obligations:

  • State breach notification laws: Most states require notification of affected customers within 30 to 60 days (varies by state).
  • HIPAA breach notification: Healthcare covered entities must notify affected individuals within 60 days.
  • PCI DSS incidents: Payment processors must report to acquiring banks and card networks.
  • Cyber-insurance claims: Insureds must notify insurers as required by policy (typically within 30 days).

The SEC filing often happens first (4 days), followed by customer and regulatory notifications.

For multi-state or industry-specific compliance, consider using tools or services that monitor both SEC requirements and state-level rules. If your company operates in HR/employment sectors, cross-reference HR Compliance Watch for state-specific employee data breach rules.


Legal Disclaimer

This post is informational only and does not constitute legal, financial, or investment advice. Materiality determinations are fact-specific and require consultation with qualified legal counsel and your disclosure counsel. Always verify disclosure requirements against current SEC guidance, the most recent Form 8-K instructions, and applicable state laws. The SEC's final rule on Item 1.05 and subsequent interpretations are available at sec.gov. If your company has experienced a cybersecurity incident, consult a securities attorney immediately.


Ready to Stay on Top of 8-K Filings?

Manual monitoring of SEC filings is slow and error-prone. BreachTrigger alerts your IR, cyber, and MSSP teams to material 8-K cybersecurity disclosures filed by competitors and peers in real time, so you can benchmark disclosure practices, stay informed of industry threats, and catch regulatory or market-moving incidents before they hit the news.

Learn how IR professionals and cyber insurance underwriters use BreachTrigger to monitor 8-K Item 1.05 filings: Explore BreachTrigger.


Last updated: August 5, 2026. SEC guidance referenced against SEC Release No. 33-11216, the 2023 final rule on Form 8-K Item 1.05 cybersecurity disclosure (effective September 5, 2023; compliance required beginning December 18, 2023 for most filers).

SEC 8-K Item 1.05: The 4-Day Cybersecurity Disclosure Rule