Vai al contenuto
BREACH/TRIGGER

GUIDE ALLE COMUNICAZIONI CYBER SEC 8-K

Comunicazioni cyber SEC 8-K per settore

Ogni incidente di cybersicurezza rilevante di una società quotata USA viene comunicato nel Form 8-K, di norma sotto Item 1.05, depositato su SEC EDGAR entro 4 giorni lavorativi dalla determinazione che un incidente di cybersicurezza è rilevante. L'impatto pratico cambia da settore a settore, perché ciascuno ha ulteriori obblighi di notifica. Queste guide li spiegano.

Contenuto puramente informativo, non consulenza legale, di sicurezza o finanziaria. Sono sintesi generali di un ambito normativo in rapida evoluzione. Prima di agire, verifica ogni regola e deposito nelle fonti primarie (sec.gov/edgar e gli enti citati).

Domande frequenti sulle comunicazioni cyber SEC

Che cos'è un 8-K di cybersicurezza SEC Item 1.05?
The SEC adopted its cybersecurity disclosure rules in 2023. Item 1.05 of Form 8-K requires a public company to disclose a material cybersecurity incident within 4 business days of determining a cybersecurity incident is material. Companies sometimes file non-material or precautionary cyber disclosures under Item 8.01 instead of Item 1.05.
What is the difference between Item 1.05 and Item 8.01?
Item 1.05 is the mandatory disclosure for a cybersecurity incident the company has determined is material. Item 8.01 is a catch-all companies sometimes use to voluntarily disclose an incident that is precautionary or not yet determined material.
Where are cyber 8-K filings published?
Every Form 8-K is filed to SEC EDGAR and is public. You can search EDGAR full-text yourself, or subscribe to same-day alerts filtered by sector and ticker.
Comunicazioni cyber SEC 8-K per settore