The Securities and Exchange Commission adopted its cybersecurity disclosure rules yesterday, on a three-to-two vote, after eighteen months of consultation and two dissents that will be quoted in the litigation. Registrants must report material cybersecurity incidents on Form 8-K within four business days, and must describe their cybersecurity risk management, strategy and governance in the annual report. The annual disclosure requirement applies for fiscal years ending on or after 15 December this year. The incident reporting requirement follows shortly after, with smaller reporting companies granted an additional six months. For most calendar-year filers, this is a five-month runway.
The four-day clock does not start when you are breached. It starts when you decide, which means the decision is now the regulated act
Read the trigger carefully, because almost every summary published today will get this wrong. The four business days run from the determination that an incident is material, not from discovery, not from containment, and not from the point at which the facts are comfortable. That sounds generous. It is not. The rule also requires that the materiality determination be made without unreasonable delay after discovery, which closes the obvious loophole and creates a subtler exposure: a company that takes three weeks to decide has not bought itself three weeks, it has created a second question about why the decision took three weeks. The judgement itself, and the record of how and when it was made, is what a regulator will examine.
What was actually adopted
Incident reporting. A new Form 8-K item requiring description of the nature, scope and timing of a material incident and its material impact or reasonably likely material impact, with amendments when information was unavailable at filing. Annual disclosure. A description of processes for assessing, identifying and managing material risks from cybersecurity threats, whether risks have materially affected or are reasonably likely to materially affect the business, the board's oversight of those risks, and management's role and relevant expertise. Foreign private issuers. Parallel requirements through Form 6-K and the annual report on Form 20-F. A narrow delay. Disclosure may be postponed where the Attorney General determines it would pose a substantial risk to national security or public safety, for an initial period of thirty days, extendable in defined circumstances. This is not a general extension for companies that are still investigating. One requirement dropped. The proposal would have required disclosure of board members' cybersecurity expertise. The final rule removed it, after substantial comment that it would drive box-ticking appointments rather than better oversight.
Materiality is a securities test, not a security test
This is where most organisations will fail, and the failure is organisational rather than technical. The standard is whether a reasonable investor would consider the information important. That takes in quantitative impact, but also reputational damage, litigation and regulatory exposure, effects on customer and supplier relationships, and harm to operations or strategy. It is not measured in records exfiltrated or systems encrypted. No security team can make that call, and no security team should be asked to. The determination belongs to the disclosure committee, with counsel and finance in the room. The problem is that in most companies the disclosure committee meets quarterly, has never seen an incident, and does not know it is now part of the incident response plan.
The five-month project
Wire the two processes together. Define the severity threshold at which security escalates to the disclosure committee, and make it a step in the incident response plan rather than a phone call someone remembers to make. Be able to convene in hours. A committee that cannot meet within a day of a serious incident will produce an unreasonable delay by simply existing. Document the negative decisions. Most incidents will be immaterial. The record of who assessed materiality, on what facts, and why the answer was no, is the entire defence when the same incident looks different a year later. Build a standard assessment template and use it every time. Track incidents for aggregation. Related occurrences that are individually immaterial may be material together, which requires a running log organised by cause and actor rather than a folder of closed tickets. Draft the filing in advance. Writing a public description of an incident at day four, with incomplete facts, under pressure, without a template, is how companies say things they later amend. Pre-draft the structure and agree what level of detail you will and will not provide.
Escalate
Connect incident severity to a named disclosure-review route.
Convene
Bring the decision-makers, counsel and finance together with deputies available.
Record the judgement
Document facts, timing and the reasoning, including a negative determination.
Prepare and rehearse
Maintain related-incident records, filing templates and a tabletop that reaches a disclosure decision.
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
The annual disclosure is the one that changes behaviour
The incident item will generate the headlines. The annual item will generate the enforcement. Once you describe your risk management processes in a filing, those statements are subject to the same accuracy expectations as everything else in the document. The distance between the programme as described and the programme as operated becomes a disclosure controls problem, and it is discoverable. Third-party and supplier risk processes are explicitly within the description, which is uncomfortable for the many companies whose vendor risk process is a questionnaire nobody reads. Write the description from what you do, not from what the framework says you should do. Then close the gaps you just documented.
Practical Guidance for Disclosure Readiness Review
- Add the disclosure committee to the incident response plan as a named step.
- Define the escalation threshold in severity terms security teams already use.
- Build a materiality assessment template and document every determination.
- Ensure the committee can convene within hours, with deputies named.
- Keep an aggregation log of related minor incidents.
- Pre-draft the filing and agree the detail boundary in advance.
- Write the annual description from actual practice, then remediate the gaps.
- Run one tabletop that ends in a filing decision, not in containment.
The Regional Angle
Three implications matter for groups here, and the first affects more organisations than they realise. Regional issuers with securities registered in the United States are foreign private issuers, and their version of this rule works differently in a way that reverses the usual sequence. The requirement operates through the form used for home-country disclosures: if a material cybersecurity incident is disclosed, or required to be disclosed, in your home jurisdiction, to a stock exchange, or to security holders, it must be furnished to the Commission. Your American filing obligation is therefore driven by your local one. That makes the analysis of what your home market requires the primary question rather than the secondary one, and it means a group listed in both places cannot manage the two timelines separately. Map the two obligations against each other now, and be clear about which disclosure triggers which. The second applies to purely regional issuers who assume none of this reaches them. Every major exchange in the Gulf already requires listed companies to disclose material developments to the market without delay, and the market authorities have been steadily sharpening those continuous disclosure obligations. Almost no regional issuer has ever treated a cyber incident as a disclosable material development, not because the rule excludes it but because nobody has tested the question. The American rule provides a fully worked template for how a securities regulator thinks about this, and templates travel. The useful move is not to wait for a local rule but to run one materiality assessment against your existing listing obligations and see what your own counsel says. Most will conclude that a serious incident was always disclosable and that the absence of precedent is not the same as the absence of duty. The third is about who finds out first, and it deserves a decision at board level rather than in a crisis. The regional instinct after an incident is containment and silence, supported by a genuine concern about reputational damage in markets where commercial relationships are personal. For any group with an American filing obligation, silence has stopped being available, and the consequence is that a public filing may become the first notice your local regulator, your banks, your largest customers and your family shareholders receive. Reading about it in a foreign regulatory document is the worst possible way for any of them to learn. Sequence the notifications deliberately in the plan: who is told in the hours before the filing, in what order, by whom, and with what message. That sequencing is a communications decision with real relationship consequences, and it cannot be improvised at two in the morning.
The objection worth taking seriously
The dissents make the strongest version of the argument and they are not frivolous. Requiring public description of an incident four days after a materiality determination can force disclosure while systems are still being restored and while an attacker who reads the filing learns what the victim knows. Prescriptive annual disclosure of risk management processes hands adversaries a map of controls and their gaps. And the Commission already had a materiality regime: companies were always obliged to disclose material information, so the new rule adds mechanism rather than substance, at real cost to smaller registrants. The operational half of this is correct and will produce genuine harm in specific cases. Some companies will file while an intrusion is live. What it understates is how badly the previous arrangement worked. Research into incident disclosure consistently found delays measured in months, disclosure buried in risk factors written in the conditional tense, and material events reported only when a journalist forced the issue. A general obligation that nobody operationalises is not a regime, it is an aspiration. The new rule is narrower on content than the proposal, excludes technical detail that would impede response, and leaves the materiality judgement with the company. The cost is a real compliance burden. The benefit is that the judgement now has to be made by named people, on a schedule, with a record — which is the part that was actually missing.
Common Questions
Does a ransomware attack automatically require a filing?
No. It requires a materiality determination made without unreasonable delay. Many incidents, including some that feel severe internally, will not be material to a reasonable investor.
Can we delay while law enforcement investigates?
Only through the narrow national security and public safety mechanism, which requires an Attorney General determination. An ongoing investigation is not by itself a basis for delay.
What if we do not know the impact within four days?
File what you know, state what remains under investigation, and amend. The rule anticipates incomplete information; it does not accept silence while facts are gathered.
What should we expect over the next twelve months?
Expect a legal challenge, given the vote and the tone of the dissents, though a stay before the compliance dates is unlikely. Expect the first incident filings shortly after the December date, followed by a period in which nobody knows the norm and companies copy whichever early filing looked least damaging. Expect plaintiff firms to run the annual descriptions against subsequent incidents looking for inconsistency, which makes the annual item the more dangerous of the two. And expect other regulators to borrow the structure within a year or two, because a workable definition of what to disclose and when is exactly what most markets have been missing.
Disclosure Readiness Review — we connect your incident response plan to your disclosure committee, build the materiality assessment record that protects you when the answer is no, and rehearse the version that ends in a filing.
