CISO Tribune

Analysis

The SEC cyber disclosure rules, explained for security leaders

What the SEC's cybersecurity disclosure rules require — the four-business-day 8-K, the 10-K risk-management disclosures, and how materiality decisions actually work.

By CISO Tribune Editorial · Published April 14, 2026 · 2 min read

TL;DR: The SEC's rules did two things: put material incidents on a four-business-day disclosure clock (Form 8-K Item 1.05), and made cyber risk governance an annual, comparable, public disclosure (Reg S-K Item 106 in the 10-K). For CISOs the operational consequence is that materiality determination is now a formal corporate process — and the CISO's judgment sits at the top of it.

What are the two obligations?

Incident disclosure. A public company that experiences a cybersecurity incident must determine whether it is material and, if so, file a Form 8-K Item 1.05 within four business days of that determination, describing the incident's nature, scope, timing, and material impact or reasonably likely material impact. A narrow national-security/public-safety delay exists, granted through the Attorney General — rare by design.

Annual disclosure. In the 10-K, companies must describe their processes for assessing, identifying, and managing material cyber risks; whether risks from cybersecurity threats have materially affected the company; the board's oversight of cyber risk; and management's role and expertise in managing it.

How does the materiality clock actually work?

The four days start at the materiality determination, not at discovery — but the rule requires that determination be made "without unreasonable delay." That phrase does the work: a company can investigate, but it cannot park the question. In practice this has pushed public companies to build a standing materiality process: defined escalation from the security team, a small committee (legal, finance, CISO, often the CFO), pre-agreed criteria drawing on both quantitative thresholds and qualitative factors, and minutes. For the CISO, the job is feeding that committee accurate severity information fast — and documenting that they did.

What does Item 106 mean for the CISO?

The annual disclosure quietly restructured the CISO's governance position. Companies must describe management's role in cyber risk and the expertise of those responsible — which makes the security leadership function itself a disclosed fact. It also makes board engagement disclosable: a board that never hears from security is now describable as exactly that, in a filing plaintiffs' lawyers read. The practical effect: more CISOs presenting to boards on a regular cadence, and more attention to how the program is described — because the SolarWinds case established that public statements about security can carry fraud exposure when internal reality diverges.

What should security leaders do about it?

Four moves. Build the materiality committee before the incident, with criteria and a call tree. Keep an incident log with timestamps — discovery, escalation, determination — because "without unreasonable delay" is judged in hindsight. Reconcile the 10-K language with internal assessments annually; the CISO should read the cyber disclosures before they file, not after. And rehearse the four-day scenario in tabletop exercises: the drill isn't containment, it's whether the company can investigate, decide, and draft accurate disclosure under a clock.

Frequently asked questions

What do the SEC cybersecurity rules require?
Two things: public companies must disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining it is material, and must describe their cyber risk management, strategy, and governance annually in the 10-K under Regulation S-K Item 106.
Does the four-day clock start at discovery of the incident?
No — it starts when the company determines the incident is material, and that determination must be made without unreasonable delay. The distinction matters: companies get time to investigate, but cannot slow-walk the materiality call itself.
Do the SEC rules require naming the CISO?
The 10-K disclosures require describing management's role in assessing and managing cyber risk, including the relevant expertise of the people responsible — which in practice puts the security leadership function, and often the CISO role, into the filing.

Sources

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.