Reference · LeakTrace Intelligence Team
SEC Item 1.05.
SEC Cybersecurity Disclosure Rules (Form 8-K Item 1.05 and Regulation S-K Item 106)
At a glance
- Jurisdiction
- US Federal
- Breach reporting deadline
- 4 business days from materiality determination
- Applies to
- Public CompaniesFinancial
- Authoritative source
- https://www.sec.gov/rules/final/2023/33-11216.pdf
- Last updated
- August 5, 2026
## What it is
The SEC adopted final cybersecurity disclosure rules on July 26, 2023, effective for larger reporting companies December 18, 2023 and for smaller reporting companies June 15, 2024. The rules amend Form 8-K (Item 1.05), Regulation S-K (Item 106), and Form 20-F for foreign private issuers.
## Who it applies to
All public companies subject to the reporting requirements of the Securities Exchange Act of 1934, including foreign private issuers (via Form 20-F amendments) and smaller reporting companies (with delayed effective date).
## Form 8-K Item 1.05 — Incident disclosure
Public companies must file a Form 8-K within four business days of determining that a cybersecurity incident is material. The disclosure must describe:
- **Material aspects of the nature, scope, and timing** of the incident
- **Material impact or reasonably likely material impact** on the registrant, including financial condition and results of operations
Determination of materiality must be made without unreasonable delay. The four-business-day clock starts from the materiality determination, not the initial detection. A narrow national security or public safety delay is available with Attorney General notification.
Amendments are required if the required information was not initially available (Form 8-K Item 1.05(b)) — filed within four business days of the additional information becoming available.
## Regulation S-K Item 106 — Annual disclosure
Item 106 requires disclosure in annual reports (Form 10-K / 20-F) of:
- **Item 106(b) — Risk management and strategy:** Processes for assessing, identifying, and managing material risks from cybersecurity threats; whether any cybersecurity threat, including any previous incident, has materially affected or is reasonably likely to materially affect the registrant
- **Item 106(c) — Governance:** Board oversight of cybersecurity risks; management's role, expertise, and processes for reporting to the board
Foreign private issuers face parallel requirements via Form 20-F amendments.
## What is a "material" cybersecurity incident?
The SEC did not define materiality specifically for cybersecurity, deliberately relying on the existing materiality standard (TSC Industries v. Northway) — information is material if there is a substantial likelihood that a reasonable investor would consider it important. The SEC clarified that quantitative and qualitative factors matter: financial impact, reputational harm, operational disruption, litigation exposure, and long-term customer relationships all contribute.
## Enforcement and safe-harbour considerations
The SEC has increased scrutiny of cybersecurity disclosures. Notable actions include SolarWinds and CISO Timothy Brown (charges filed October 2023) — [VERIFY current litigation status]. Cybersecurity-related disclosure statements may be subject to Section 10(b) securities fraud liability.
Item 1.05 does not include a safe harbour, but Rule 175 provides some forward-looking statement protections. Companies are encouraged to distinguish between forward-looking statements and historical fact disclosures.
## Penalties
SEC enforcement can include civil monetary penalties, disgorgement, officer/director bars, and cease-and-desist orders. Failure to timely disclose can also expose companies to shareholder securities class actions.
## How LeakTrace aligns
LeakTrace supports public companies with continuous external-surface monitoring feeding into the Item 106(b) risk management processes. Incident evidence bundles are structured to support materiality determinations and Form 8-K narratives with defensible timelines, chain-of-custody documentation, and objective scope characterization.
Key provisions
- Form 8-K Item 1.05(a) — Material incident disclosure
- Disclose within four business days of determining an incident is material; describe nature, scope, timing, and material impact.
- Form 8-K Item 1.05(b) — Amendment
- File amendment within four business days of any required information becoming available if not disclosed initially.
- Form 8-K Item 1.05(c) — National security delay
- Attorney General may grant a delay if disclosure poses substantial risk to national security or public safety.
- Regulation S-K Item 106(b) — Risk management and strategy
- Describe processes for assessing, identifying, and managing material cybersecurity risks; describe whether prior incidents have materially affected the registrant.
- Regulation S-K Item 106(c) — Governance
- Describe board oversight and management's role in cybersecurity risk management.
- Form 20-F Item 16K
- Foreign private issuers must provide substantially similar cybersecurity disclosures.
Recent amendments & guidance
2023-07-26
SEC adopted final cybersecurity disclosure rules (Release No. 33-11216).
2023-12-18
Rules effective for larger reporting companies.
2024-06-15
Rules effective for smaller reporting companies.
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs