Skip to content
BREACH/TRIGGER

SEC CYBER 8-K DISCLOSURE GUIDES

SEC cyber 8-K disclosures, by sector

Every material cybersecurity incident at a US public company is disclosed on Form 8-K, usually under Item 1.05, filed to SEC EDGAR within 4 business days of determining a cybersecurity incident is material. What that means in practice differs by sector, because each carries its own overlapping notification rules. These guides break it down.

Informational only, not legal, security, or investment advice. These are high-level summaries of a fast-moving regulatory area. Verify every rule and filing against primary sources (sec.gov/edgar and the named regulators) before acting.

SEC cyber disclosure FAQ

What is an SEC Item 1.05 cybersecurity 8-K?
The SEC adopted its cybersecurity disclosure rules in 2023. Item 1.05 of Form 8-K requires a public company to disclose a material cybersecurity incident within 4 business days of determining a cybersecurity incident is material. Companies sometimes file non-material or precautionary cyber disclosures under Item 8.01 instead of Item 1.05.
What is the difference between Item 1.05 and Item 8.01?
Item 1.05 is the mandatory disclosure for a cybersecurity incident the company has determined is material. Item 8.01 is a catch-all companies sometimes use to voluntarily disclose an incident that is precautionary or not yet determined material.
Where are cyber 8-K filings published?
Every Form 8-K is filed to SEC EDGAR and is public. You can search EDGAR full-text yourself, or subscribe to same-day alerts filtered by sector and ticker.
SEC Cyber 8-K Disclosures by Sector