Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
Home · Frameworks · SEC Item 1.05
Reference · LeakTrace Intelligence Team

SEC Item 1.05.

SEC Cybersecurity Disclosure Rules (Form 8-K Item 1.05 and Regulation S-K Item 106)
At a glance
Jurisdiction
US Federal
Breach reporting deadline
4 business days from materiality determination
Applies to
Public CompaniesFinancial
Authoritative source
https://www.sec.gov/rules/final/2023/33-11216.pdf
Last updated
August 5, 2026
## What it is The SEC adopted final cybersecurity disclosure rules on July 26, 2023, effective for larger reporting companies December 18, 2023 and for smaller reporting companies June 15, 2024. The rules amend Form 8-K (Item 1.05), Regulation S-K (Item 106), and Form 20-F for foreign private issuers. ## Who it applies to All public companies subject to the reporting requirements of the Securities Exchange Act of 1934, including foreign private issuers (via Form 20-F amendments) and smaller reporting companies (with delayed effective date). ## Form 8-K Item 1.05 — Incident disclosure Public companies must file a Form 8-K within four business days of determining that a cybersecurity incident is material. The disclosure must describe: - **Material aspects of the nature, scope, and timing** of the incident - **Material impact or reasonably likely material impact** on the registrant, including financial condition and results of operations Determination of materiality must be made without unreasonable delay. The four-business-day clock starts from the materiality determination, not the initial detection. A narrow national security or public safety delay is available with Attorney General notification. Amendments are required if the required information was not initially available (Form 8-K Item 1.05(b)) — filed within four business days of the additional information becoming available. ## Regulation S-K Item 106 — Annual disclosure Item 106 requires disclosure in annual reports (Form 10-K / 20-F) of: - **Item 106(b) — Risk management and strategy:** Processes for assessing, identifying, and managing material risks from cybersecurity threats; whether any cybersecurity threat, including any previous incident, has materially affected or is reasonably likely to materially affect the registrant - **Item 106(c) — Governance:** Board oversight of cybersecurity risks; management's role, expertise, and processes for reporting to the board Foreign private issuers face parallel requirements via Form 20-F amendments. ## What is a "material" cybersecurity incident? The SEC did not define materiality specifically for cybersecurity, deliberately relying on the existing materiality standard (TSC Industries v. Northway) — information is material if there is a substantial likelihood that a reasonable investor would consider it important. The SEC clarified that quantitative and qualitative factors matter: financial impact, reputational harm, operational disruption, litigation exposure, and long-term customer relationships all contribute. ## Enforcement and safe-harbour considerations The SEC has increased scrutiny of cybersecurity disclosures. Notable actions include SolarWinds and CISO Timothy Brown (charges filed October 2023) — [VERIFY current litigation status]. Cybersecurity-related disclosure statements may be subject to Section 10(b) securities fraud liability. Item 1.05 does not include a safe harbour, but Rule 175 provides some forward-looking statement protections. Companies are encouraged to distinguish between forward-looking statements and historical fact disclosures. ## Penalties SEC enforcement can include civil monetary penalties, disgorgement, officer/director bars, and cease-and-desist orders. Failure to timely disclose can also expose companies to shareholder securities class actions. ## How LeakTrace aligns LeakTrace supports public companies with continuous external-surface monitoring feeding into the Item 106(b) risk management processes. Incident evidence bundles are structured to support materiality determinations and Form 8-K narratives with defensible timelines, chain-of-custody documentation, and objective scope characterization.
Key provisions
Form 8-K Item 1.05(a) — Material incident disclosure
Disclose within four business days of determining an incident is material; describe nature, scope, timing, and material impact.
Form 8-K Item 1.05(b) — Amendment
File amendment within four business days of any required information becoming available if not disclosed initially.
Form 8-K Item 1.05(c) — National security delay
Attorney General may grant a delay if disclosure poses substantial risk to national security or public safety.
Regulation S-K Item 106(b) — Risk management and strategy
Describe processes for assessing, identifying, and managing material cybersecurity risks; describe whether prior incidents have materially affected the registrant.
Regulation S-K Item 106(c) — Governance
Describe board oversight and management's role in cybersecurity risk management.
Form 20-F Item 16K
Foreign private issuers must provide substantially similar cybersecurity disclosures.
Recent amendments & guidance
2023-07-26
SEC adopted final cybersecurity disclosure rules (Release No. 33-11216).
2023-12-18
Rules effective for larger reporting companies.
2024-06-15
Rules effective for smaller reporting companies.
Operating under this framework?
LeakTrace runs continuous external-surface intelligence aligned to your regulatory posture. Discovery call under mutual NDA; first-touch reply within one business day from an authenticated LeakTrace address.
View programs