Skip to main content
Category: Regulatory & Legal Obligations

SEC Cybersecurity Disclosure

Also known as: SEC Cybersecurity Disclosure Rule, SEC Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rules, SEC Cyber Incident Reporting Rule
Simply put

SEC Cybersecurity Disclosure refers to rules the U.S. Securities and Exchange Commission adopted in July 2023 that require publicly traded companies to tell investors about serious cybersecurity incidents and about how they manage cybersecurity risk. Under these rules, companies generally must report a material cyber incident within four business days of deciding it is material, and must also provide annual information about their cybersecurity risk management and governance. The goal is to give investors more consistent and comparable information, not to guarantee that a company is secure or free from breaches.

Formal definition

The SEC Cybersecurity Disclosure rules, adopted July 26, 2023, mandate enhanced and standardized disclosures by registrants regarding cybersecurity incidents, risk management, strategy, and governance. Domestic registrants are generally required to disclose material cybersecurity incidents on Form 8-K (Item 1.05), describing the material aspects of the incident's nature, scope, timing, and material impact or reasonably likely material impact, typically within four business days of determining that an incident is material. Registrants must also provide annual disclosures on Form 10-K addressing processes for assessing, identifying, and managing material cybersecurity risks, as well as board oversight and management's role in that governance; comparable requirements apply to Foreign Private Issuers via Forms 20-F and 6-K. For a vCISO or fractional security leader, these rules shape governance advisory work such as helping define materiality assessment processes, incident escalation and disclosure workflows, and board reporting; however, legal and regulatory accountability for disclosure decisions remains with the registrant and its officers, and a security leadership engagement supports readiness and process design rather than assuming filing liability or guaranteeing compliance. Specific applicability, phase-in timing, and smaller reporting company accommodations may vary and should be confirmed against the final rule text.

Why it matters

The SEC Cybersecurity Disclosure rules, adopted July 26, 2023, changed how publicly traded companies communicate cybersecurity risk to investors. By requiring disclosure of material cybersecurity incidents on Form 8-K (Item 1.05) generally within four business days of determining an incident is material, and annual disclosures on Form 10-K covering risk management, strategy, and governance, the rules elevate cybersecurity from a purely technical concern to a board-level and investor-relations matter. This means that decisions about what constitutes a material incident, and how quickly it must be disclosed, now carry securities-law consequences that reach beyond the security team into the C-suite, legal, and the board.

For security leaders, the significance lies in the intersection of governance and accountability. The rules do not guarantee that a company is secure or free from breaches; they are designed to give investors more consistent and comparable information. A company can be fully compliant with the disclosure obligations and still experience a serious breach. What the rules demand is a defensible, documented process for assessing materiality, escalating incidents, and reporting to the board. Where those processes are weak or undefined, an organization risks late or inconsistent disclosures precisely when it is under the operational stress of an active incident.

Because legal and regulatory accountability for disclosure decisions rests with the registrant and its officers, security leadership engagements support readiness and process design rather than assuming filing liability. A vCISO or fractional security leader can help build the materiality assessment framework, escalation workflows, and board reporting cadence that make timely, accurate disclosure possible, but the responsibility for the filing itself remains with the company and its officers working alongside legal counsel.

Who it's relevant to

Public company boards and audit committees
The annual Form 10-K disclosures require companies to describe board oversight of cybersecurity risk and management's role in that governance. Boards and their committees need to understand what they are attesting to and how oversight is exercised and documented. A security leader can help translate technical risk into board-appropriate reporting, but accountability for the disclosures remains with the registrant and its officers.
CISOs, vCISOs, and fractional security leaders
These rules shape governance advisory work such as defining materiality assessment processes, incident escalation and disclosure workflows, and board reporting cadence. It is important to be clear that a security leadership engagement supports readiness and process design rather than assuming filing liability or guaranteeing compliance. The four-business-day window is triggered by the materiality determination, so the practical value lies in having those processes defined before an incident occurs.
General counsel and securities/disclosure teams
Because the four-business-day incident reporting requirement is a securities-law obligation, legal counsel and disclosure teams hold primary accountability for the Form 8-K Item 1.05 filing and the annual Form 10-K disclosures. Security leaders coordinate closely with these teams, providing the technical facts and impact assessments that inform materiality determinations, but the disclosure decision itself is a legal and officer-level responsibility.
Foreign Private Issuers
Comparable disclosure requirements apply to Foreign Private Issuers through Forms 20-F and 6-K. Organizations that file under these forms should confirm how the incident and governance disclosure obligations apply to their specific circumstances, as applicability, phase-in timing, and accommodations may vary and should be verified against the final rule text.
Smaller reporting companies preparing for compliance
The rules include accommodations that may affect timing for smaller reporting companies. These organizations often have less mature governance structures and may benefit most from establishing defined materiality assessment and escalation processes, since the value of readiness depends heavily on organizational maturity, stakeholder access, and clearly defined scope. Specific accommodations should be confirmed against the final rule text and with counsel.

Inside SEC Cybersecurity Disclosure

Form 8-K Item 1.05 Incident Disclosure
A current report requirement for domestic registrants to disclose a cybersecurity incident once it has been determined to be material, describing the material aspects of the incident's nature, scope, and timing and its material or reasonably likely material impact on the registrant.
Four-Business-Day Reporting Window
The general timing standard requiring the Item 1.05 disclosure within four business days after the registrant determines an incident is material. The window runs from the materiality determination, not necessarily from the date of discovery.
National Security and Public Safety Delay
A limited provision allowing a delay in disclosure when the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety, subject to specified conditions.
Annual Form 10-K Risk Management and Strategy Disclosure
A periodic requirement to describe the registrant's processes for assessing, identifying, and managing material cybersecurity risks and how any such risks have materially affected or are reasonably likely to affect the business.
Governance and Board Oversight Disclosure
Annual disclosure describing the board's oversight of cybersecurity risk and management's role and expertise in assessing and managing that risk, emphasizing security as a governance and business-risk matter rather than a purely technical one.
Foreign Private Issuer Reporting
Comparable obligations for Foreign Private Issuers, which report material incident information on Form 6-K and periodic risk and governance information on Form 20-F.
Materiality Standard
The threshold governing whether an incident or risk must be disclosed, based on established federal securities law principles concerning what a reasonable investor would consider important, rather than a fixed technical severity score.

Common questions

Answers to the questions practitioners most commonly ask about SEC Cybersecurity Disclosure.

Does the SEC's cybersecurity disclosure rule make our virtual CISO legally accountable for what we file?
No. The SEC's cybersecurity disclosure requirements place accountability on the registrant and its officers, typically including the CEO, CFO, and the board, who certify and are responsible for the company's filings. A virtual CISO advises on the substance of cybersecurity risk management, materiality assessment, and governance disclosures, and may help draft or review technical content, but the legal and regulatory accountability for the accuracy of Form 8-K Item 1.05 incident disclosures and Form 10-K risk and governance disclosures generally remains with the company and its named officers. This division of accountability from responsibility should be clarified in the engagement scope; a vCISO does not assume liability for a filing unless a contract explicitly specifies otherwise, which is uncommon.
Does engaging a virtual CISO guarantee our SEC cybersecurity disclosures will be compliant?
No. A virtual CISO can support readiness by helping establish materiality assessment processes, incident response documentation, governance structures, and disclosure controls that map to the rule's expectations. However, no engagement guarantees compliance or that a given disclosure will satisfy regulators. Compliance outcomes depend on legal counsel, the accuracy of facts at the time of filing, the judgment of company officers, and the quality of the company's underlying processes. A vCISO is one input into a cross-functional effort that typically also involves legal, finance, disclosure committees, and the board. It is a mistake to treat a vCISO engagement as a substitute for securities counsel or as a certification of compliance.
How can a virtual CISO help us determine whether a cybersecurity incident is material enough to disclose?
The rule requires disclosure of material cybersecurity incidents on Form 8-K Item 1.05, generally within four business days of determining that an incident is material. A virtual CISO often helps by establishing a repeatable materiality assessment process, providing technical context on incident scope and impact, and coordinating with legal, finance, and disclosure decision-makers who make the final determination. In many engagements the vCISO advises rather than decides, because materiality is ultimately a legal and business judgment that considers both quantitative and qualitative factors. The value of this support depends heavily on the company having defined escalation paths and giving the vCISO timely access to incident details.
What role does a virtual CISO play in preparing the annual cybersecurity disclosures in Form 10-K?
The annual filing typically calls for disclosures about the company's processes for assessing, identifying, and managing material cybersecurity risks, as well as its governance, including board oversight and management's role. A virtual CISO can help articulate and document these processes, describe the risk management program in language appropriate for the filing, and support descriptions of governance and reporting relationships. The vCISO usually works alongside legal counsel and the disclosure team, who own the final wording. This support is most effective when the company's underlying program is documented and mature; where processes are informal, the vCISO's contribution may focus first on building those processes before they can be accurately disclosed.
How should we structure a virtual CISO engagement to support the four-business-day incident reporting window?
Because the incident reporting timeframe is generally four business days from the materiality determination, engagements often define how quickly the vCISO can be reached and involved during an incident. Scope should clarify whether the vCISO participates in incident triage and materiality input on an on-call basis, since a standard part-time or fractional arrangement may not include operational incident response execution or continuous availability. Companies typically pair the vCISO's advisory role with defined internal escalation procedures, a disclosure committee, and legal counsel so materiality decisions and filings are not dependent on any single external advisor. Availability commitments, response expectations, and any out-of-scope operational tasks should be stated explicitly in the contract.
Does a virtual CISO handle the actual SEC filing and governance reporting to the board?
Generally no for the filing itself. Preparing and submitting SEC filings is a function of the company's legal, finance, and executive teams, not the vCISO. A virtual CISO more commonly supports board and committee reporting by providing risk briefings, program updates, and governance documentation that inform oversight, which the rule expects the company to describe. It is a common mistake to assume a vCISO replaces internal officers or securities counsel in the disclosure process. The engagement's effectiveness depends on the vCISO having direct access to the board or its committees and on clearly defined boundaries between advisory input and the accountable parties who approve and submit disclosures.

Common misconceptions

The rules require reporting every cybersecurity incident within four business days of discovery.
The Item 1.05 obligation is generally triggered when the registrant determines an incident is material, and the four-business-day window typically runs from that materiality determination. Not all incidents are material, and the standard is a securities-law materiality judgment rather than a mandate to report all events on discovery.
Engaging a virtual CISO transfers SEC disclosure accountability to the vCISO or their firm.
A vCISO can help design governance, risk assessment, and materiality escalation processes and support readiness, but legal accountability for the accuracy, completeness, and timeliness of SEC filings ordinarily remains with the registrant, its officers, and its board, typically working with legal counsel. Accountability shifts only if a contract explicitly provides otherwise.
The SEC rules dictate specific security controls or certifications a company must implement.
These are disclosure requirements about incidents, risk management processes, and governance. They do not prescribe particular technical controls or certifications, so supporting compliance with the disclosure rules is distinct from achieving any given security certification.

Best practices

Establish a documented materiality determination process, involving security leadership, legal counsel, and disclosure controls owners, so that the four-business-day clock and its trigger are understood before an incident occurs.
Integrate incident response escalation with the disclosure workflow so that material incidents are surfaced promptly to those responsible for the 8-K Item 1.05 filing rather than remaining contained within technical teams.
Prepare annual Form 10-K cybersecurity risk management, strategy, and governance disclosures in advance, keeping records of the processes and board oversight practices actually in place so filings are accurate and supportable.
Clarify in any vCISO engagement scope who advises on materiality and readiness versus who retains accountability for the filings themselves, and confirm that legal counsel is engaged in disclosure decisions.
For organizations with Foreign Private Issuer status, confirm the applicable forms and reporting mechanisms, since incident and periodic disclosures follow Form 6-K and Form 20-F rather than the domestic 8-K and 10-K.
Periodically test the end-to-end disclosure process through tabletop exercises to validate that materiality determinations, timing, and stakeholder coordination function under realistic incident conditions.