SEC cybersecurity disclosure — the Form 8-K Item 1.05 and Item 106 playbook
Short definition
A CISO playbook for the SEC's 2023 cybersecurity rules: the Form 8-K Item 1.05 filing due four business days after a materiality determination, and the annual Item 106 disclosure.
Why this matters now
The four business days start when the company determines that an incident is material, and that determination must itself be made without unreasonable delay after discovery. What the security team can establish in the first days about scope, access and impact therefore shapes both the timing and the content of the filing. The annual Item 106 disclosure describes the same processes, so it has to match what the company can show it actually does.
Key points
- ▸Item 1.05: file within four business days after determining that a cybersecurity incident is material, not after discovering it.
- ▸The materiality determination must be made without unreasonable delay after discovery; missing details can follow in an amendment.
- ▸Disclose the material aspects of nature, scope and timing and the material or reasonably likely impact, not a technical roadmap.
- ▸Delay only if the US Attorney General finds that disclosure poses a substantial risk to national security or public safety.
- ▸Item 106 in the 10-K: risk management processes, third-party assessors, board oversight, and management's role and expertise.
- ▸Staff guidance: use Item 8.01 for incidents not found material; related intrusions can be material together.
Who the rules cover, and their status in 2026
The rules, adopted in Release 33-11216 on 26 July 2023, apply to companies that report under the Securities Exchange Act of 1934. Domestic registrants disclose material incidents under Form 8-K Item 1.05 and describe cybersecurity risk management, strategy and governance in the annual report under Regulation S-K Item 106 (Item 1C of Form 10-K). Foreign private issuers use Item 16K of Form 20-F for the annual disclosure and Form 6-K for incidents.
The dates, from Section II.I of the release:
- 5 September 2023: the amendments took effect.
- Fiscal years ending on or after 15 December 2023: Item 106 and Item 16K disclosures begin.
- 18 December 2023: Item 1.05 and Form 6-K incident disclosure begin, except for smaller reporting companies.
- 15 June 2024: smaller reporting companies begin Item 1.05 disclosure.
- One year after each initial date: the disclosures must be tagged in Inline XBRL.
As of September 2026 the rules are unchanged in substance. The Item 1.05 text in the Form 8-K published on sec.gov is identical to the 2023 adopted text, 17 CFR 229.106 shows no amendment since it took effect, and the only later rulemaking that touched them was a February 2025 technical correction removing a paragraph label from Item 1C of Form 10-K. Nothing has stayed or rescinded them.
The four-business-day clock
General Instruction B.1 to Form 8-K sets the deadline: a report under Item 1.05 is due within four business days after the registrant determines that it has experienced a material cybersecurity incident. The trigger is the determination, not the discovery, but the two are linked: Instruction 1 to Item 1.05 requires the materiality determination to be made without unreasonable delay after discovery of the incident.
Three points from the staff's Form 8-K interpretations (C&DIs 104B.01 to 104B.09) shape the clock in practice:
- Consulting the Department of Justice about a possible delay does not by itself mean the incident is material, and asking for a delay does not move the deadline if the Attorney General declines or does not respond in time.
- Ransomware: the incident ending, or a ransom being paid, does not remove the obligation to determine materiality or to report an incident already found material. Insurance reimbursement and the size of the payment are only some of the facts to weigh.
- Related intrusions: a cybersecurity incident includes a series of related unauthorised occurrences (Item 106(a)), and Item 1.05 can be triggered when related intrusions are material together even if each alone is not.
Record the date and time of the determination, who made it and the facts it relied on. The deadline runs from that decision.
What the filing must say, and what it need not
Item 1.05(a) requires the material aspects of the incident's nature, scope and timing, and its material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations. The information is tagged in Inline XBRL (Item 1.05(b)).
Two instructions keep the filing workable:
- Facts not yet known (Instruction 2): if required information is not determined or is unavailable when the report is due, the registrant says so in the filing and files an amendment within four business days after the information is determined or becomes available.
- No technical roadmap (Instruction 4): the registrant need not disclose specific or technical information about its planned response, its systems, networks and devices, or potential vulnerabilities in such detail as would impede its response or remediation.
The permitted delays are narrow. If the US Attorney General determines that disclosure poses a substantial risk to national security or public safety and notifies the SEC in writing, the filing may be delayed for up to 30 days, then up to 30 more, and in extraordinary circumstances involving national security for a final period of up to 60 days; beyond that, the SEC may grant relief by exemptive order (Item 1.05(c)). A registrant subject to the FCC rule at 47 CFR 64.2011 may delay for the period that rule requires, and no more than seven business days after the notification it requires, if it notifies the SEC (Item 1.05(d)).
Running the materiality determination
Materiality is a judgement for management and counsel, not for the security team, but it depends on facts that only the security team can establish quickly. A workable process:
- Pre-agreed escalation. Severity criteria that route candidate incidents to a disclosure committee within hours, with named members and deputies.
- A fact base refreshed daily. Systems and data affected; whether the attacker still has access; what else is reachable and exploitable from the systems already compromised; operational, customer and financial impact so far.
- Quantitative and qualitative factors. The May 2024 statement by the Director of the Division of Corporation Finance lists harm to reputation, customer or vendor relationships and competitiveness, and the possibility of litigation or regulatory investigations, alongside financial effects.
- A written decision. Date and time, the facts relied on, the conclusion, and the next review point if the answer is not yet.
- The right Form 8-K item. The same statement says Item 1.05 is for incidents determined to be material. A company that wants to disclose an incident it has not yet found material, or has found immaterial, can use another item such as Item 8.01, and must file under Item 1.05 within four business days if it later determines that the incident is material.
The weak point is usually step 2. Scope that rests on assumptions, such as “the attacker never left that segment”, produces either a late determination or a filing that needs large amendments.
Item 106: describe processes you can evidence
Item 106 asks for a description, not a certification, but every sentence in it is a statement to investors. It covers:
- Risk management and strategy (106(b)): the processes for assessing, identifying and managing material risks from cybersecurity threats, in enough detail for a reasonable investor to understand them, including whether they are integrated into overall risk management, whether the company engages assessors, consultants, auditors or other third parties, and how it oversees risks from third-party service providers; and whether cybersecurity risks, including from previous incidents, have materially affected or are reasonably likely to materially affect the business.
- Governance (106(c)): the board's oversight, any committee responsible and how the board is informed; management's role, the positions responsible and their expertise, how they are informed about and monitor the prevention, detection, mitigation and remediation of incidents, and whether they report to the board.
A practical test before the annual report is filed: for each process the draft describes, can the company produce the artefact that shows it running? If the disclosure says the company conducts regular penetration testing and red team exercises and remediates findings by risk, the file should hold dated test reports, the remediation record and the board or committee reporting that cites them. If it names a framework, keep the mapping.
Evidence to have ready before the next incident
- Severity and escalation criteria that name the point at which the disclosure committee is convened.
- The disclosure committee charter, members and deputies, and a decision log with timestamps.
- An asset inventory and data map precise enough to say which systems hold which data.
- A current exposure record: what is internet-facing, what has been shown to be exploitable, and which paths lead to critical systems. This is what turns scope from an estimate into a finding.
- Retainers and contact routes for outside counsel, forensic support and law enforcement, including the internal procedure for a possible request to the Department of Justice.
- A Form 8-K Item 1.05 skeleton that separates the material aspects from technical detail, as Instruction 4 allows.
- The Item 106 evidence file for the fiscal year: policies, test reports, remediation records, third-party oversight and board reporting.
Common failure modes
1. Treating discovery-to-determination as outside the rule. The determination must come without unreasonable delay, and the four business days run from it.
2. Waiting for certainty. The rule expects a filing with what is known and an amendment for what is not.
3. Deciding on cost alone. The staff's guidance lists qualitative factors, and says the size of a ransom, insurance cover or the end of an attack do not settle materiality.
4. Assessing related incidents one by one. A series of related intrusions can be material together.
5. Over-disclosing technical detail. Instruction 4 exists so that the filing does not become a guide for the next attacker.
6. An Item 106 that describes the program the company intends to have. Describe what runs today, and keep the evidence.
How an on-premise autonomous AI red team helps
The SEC rules do not require penetration testing, and no tool makes a materiality determination. An on-premise autonomous AI red team supports the facts that both disclosures depend on.
- A current exposure record before the incident. Continuous black-box and gray-box campaigns establish what is exposed and what is exploitable, so scoping during an incident starts from evidence. See CTEM.
- Controlled checks during the incident. Coordinated with incident response and behind operator approval gates, gray-box tests with the privileges of a compromised account show what that account can actually reach. See human in the loop.
- Records that can be shown to be unaltered. Every attack attempt is an Ed25519-signed entry in a SHA-256 hash chain per campaign, so any alteration of the record of what was tested and found can be detected.
- Evidence for Item 106. Test history, proven-exploitable findings and remediation re-tests are the artefacts behind a description of processes for assessing, identifying and managing cybersecurity risk. See autonomous AI red team.
- Confidentiality before disclosure. Details of an incident still under assessment are sensitive and may be material nonpublic information. Zero Hunt runs its own models on the appliance with no external AI service, so the analysis does not add an outside AI provider to the people who hold that information. See private AI in cybersecurity.
Sources
- Release 33-11216, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (SEC)
- Final rule text, Release 33-11216 (SEC, PDF)
- Form 8-K and General Instructions, current version (SEC, PDF)
- 17 CFR 229.106, Regulation S-K Item 106 (eCFR)
- Exchange Act Form 8-K Compliance and Disclosure Interpretations, Section 104B (SEC)
- Disclosure of Cybersecurity Incidents Determined To Be Material and Other Cybersecurity Incidents, statement of 21 May 2024 (SEC)
- SEC rulemaking activity
Goes deeper
Want this against your environment?
Book a 30-minute scoping call — we will map this directly to your current compliance scope and threat profile.