Four Business Days to Disclose. Zero Days to Figure Out What Material Means.
Public companies have been living with the SEC's cybersecurity disclosure rules since December 2023. The core requirement is not complicated: if you experience a material cybersecurity incident, you must file a Form 8-K within four business days of determining it is material.
What is proving complicated is the word "determining." The clock starts when you make the materiality determination, not when the incident begins. This gives the rule a deceptively accommodating character, because the determination is under your control. Several companies have learned through SEC comment letters and enforcement actions that the Commission reads "determining" to mean "when a reasonable company in your position would have concluded" - not "when your legal team finished deliberating" and not "after you had time to properly scope the remediation."
If you do not have a process for making that determination, the clock does not stop while you build one.
What the Rule Actually Requires
The rule created two disclosure obligations. The first is the incident report on Form 8-K, Item 1.05, covering the nature, scope, timing, and material impact of any cybersecurity incident determined to be material. Companies also have to state whether the incident is ongoing and describe any known material impact on operations or financial condition.
The second obligation runs through the annual 10-K and requires disclosure of cybersecurity risk management strategy, governance structure, and board oversight of cybersecurity risk. This annual disclosure is not about responding to incidents. It is about demonstrating that the company has thought about cybersecurity risk before something happens.
Both obligations interact in a way companies are still adjusting to. If your 10-K says the board receives regular cybersecurity briefings and your incident timeline shows no board involvement until three weeks into a breach, the SEC will notice the gap.
The Materiality Standard Is Not a Security Standard
"Material" in the SEC's rule means the same thing it has always meant in securities law: information that a reasonable investor would consider important in making an investment decision. This is a securities law definition applied to cybersecurity incidents, not a cybersecurity definition.
The practical implication is that "how bad is this incident from a security standpoint" and "would disclosure change a reasonable investor's decision" do not always produce the same answer. A significant data exfiltration from a company with no regulatory exposure might not be material. A moderate credential theft at a regulated company with customer notification obligations could be.
The factors that matter: financial impact (confirmed and estimated), operational disruption, reputational harm, regulatory exposure created by the incident, and customer or business partner effects that create secondary consequences. None of these have bright-line thresholds. The SEC wanted flexibility and did not want to create safe harbors that could be engineered around.
The Clock Nobody Built Into Their IR Playbook
The four-business-day window is tight by design.
Most incident response programs are built around operational recovery: contain the threat, restore systems, figure out what happened, then think about notifications. That sequence takes days or weeks in a significant incident. The SEC disclosure obligation runs parallel to that operational track and does not wait for it to finish.
What this requires is a decision-making process running concurrently with the technical response from essentially day one. Legal counsel, the CISO, and senior leadership need a shared escalation protocol for raising the materiality question early - not after the technical investigation concludes. Waiting for the forensic report before starting the materiality analysis is a plan for missing the four-day window.
The practical structure: within 24 to 48 hours of detecting an incident that might be significant, someone with authority to make the materiality call needs to be briefed. That briefing does not need to be complete. It needs to be sufficient to make a preliminary determination or to start the documented reasoning process that will support the final determination.
The Board Is Now Part of the IR Process
The 10-K governance disclosure has a consequential side effect: it creates documentation of what the board is supposed to know about cybersecurity, which gets tested against what the board actually knew during any material incident.
If your governance disclosure says the audit committee receives quarterly cybersecurity briefings, the committee is on the hook for awareness of material risks on roughly that cadence. A material incident that the board learns about for the first time from the press creates a question about whether the governance program described in the 10-K reflects reality.
The CISO or general counsel who decides not to loop in the board until the situation is "more certain" may be creating a governance disclosure problem alongside the operational one.
What Good Preparation Looks Like
The right preparation is mostly organizational. Define your materiality assessment process in writing before you need it. Assign the decision-making authority clearly, with a named person or role rather than a vague "legal and leadership." Run a tabletop that includes the 8-K question explicitly: at what point in this scenario would we file, who makes that call, and what documentation do we need to support the determination.
Keep the documentation as you go. SEC enforcement actions and comment letters have focused on companies that could not reconstruct their disclosure timelines or demonstrate a coherent materiality determination process. The question is not only whether you disclosed correctly but whether you can show your work.
The four-business-day clock does not care that you are in the middle of a crisis. Figure out the process while you still have time to think.