The Securities and Exchange Commission's cybersecurity disclosure rules, effective December 2023, require publicly traded companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining that an incident is material. The rule did not create a new obligation out of whole cloth — material information has always required disclosure under the securities laws. What the rule did was eliminate the ambiguity that allowed companies to delay cyber breach disclosure for weeks or months while "investigating" an incident whose materiality was evident from the moment the intrusion was detected. Four business days. Not four weeks. Not "when the forensic investigation is complete." Four business days from the materiality determination — a timeline that transformed corporate breach response from a crisis communications exercise managed by public relations teams into a securities law compliance obligation enforced by federal regulators.
The Materiality Standard: What Triggers the Clock
Materiality in securities law is not defined by a dollar figure, a record count, or a technical severity score. It is defined by the Supreme Court's 1976 decision in TSC Industries v. Northway: information is material if there is a "substantial likelihood that a reasonable shareholder would consider it important" in making an investment decision. The standard is deliberately qualitative, and the SEC has declined to provide quantitative bright lines for cyber materiality. A breach affecting 10,000 customer records may be immaterial for a company with 100 million customers. A breach affecting 100 records may be material if those records contain the proprietary technology on which the company's competitive advantage depends.
The four-business-day clock begins not when the incident occurs and not when the company discovers the incident, but when the company completes its materiality determination. This distinction is critical and frequently misunderstood. A company that discovers a breach on Monday but requires two weeks of forensic analysis to assess its scope, impact, and financial implications does not trigger the clock until the materiality assessment concludes. The SEC has acknowledged that materiality assessments require time — incident response is complex, forensic evidence is ambiguous, and the full scope of a breach may not be apparent for days or weeks. What the SEC does not permit is an unreasonable delay in conducting the assessment itself — a company that takes six months to "determine materiality" on a breach that encrypted its entire production environment is not conducting a good-faith assessment. It is managing a disclosure timeline.
The 8-K must describe the material aspects of the nature, scope, and timing of the incident and its material impact or reasonably likely material impact on the company's financial condition and results of operations. It need not disclose specific technical details — the attack vector, the vulnerability exploited, the indicators of compromise — that could aid the attacker or compromise ongoing remediation. The disclosure is financial, not forensic. It tells investors what happened and what it costs, not how it happened and how to replicate it.
The National Security Exception
The only statutory exception to the four-business-day deadline is a determination by the United States Attorney General that disclosure would pose a substantial risk to national security or public safety. The Department of Justice may grant an initial delay of up to 30 business days, renewable for an additional 30 days, and in extraordinary circumstances involving classified information, up to 60 additional days beyond that. The company must request the delay through the FBI's Cyber Division — not unilaterally decide to withhold disclosure on national security grounds.
The exception is designed for a narrow class of incidents: breaches of defense contractors whose disclosure would reveal intelligence collection methods, intrusions into critical infrastructure whose public announcement could trigger follow-on attacks, or compromises of classified systems whose acknowledgment would damage ongoing counterintelligence operations. The exception is not a general-purpose extension for companies that would prefer additional time to manage the public narrative. The SEC has indicated that it will scrutinize any reliance on the national security exception and that the exception does not relieve the company of its obligation to disclose once the delay period expires.
The Weaponization Problem: Hackers Filing SEC Complaints
The disclosure rule has produced an unintended tactical consequence that illuminates the structural tension between transparency and security. In November 2023, the ALPHV/BlackCat ransomware group filed a complaint with the SEC alleging that MeridianLink, a financial software company, had failed to disclose a breach that ALPHV itself had perpetrated. The filing was a strategic escalation — an attempt to weaponize the regulatory framework against the victim, using the threat of SEC enforcement as additional leverage to extract a ransom payment.
The tactic exploits a genuine regulatory asymmetry. The company faces pressure from two directions simultaneously: the attacker demands payment to prevent data publication, and the regulator demands disclosure within four business days. If the company pays the ransom and the breach is never publicized, the materiality question becomes ambiguous — was the breach material if no data was released and no customers were affected? If the company refuses to pay and the attacker publishes the data, the materiality is clear, and the four-day clock has already started. The attacker's SEC complaint forces the materiality question into the open, eliminating the ambiguity that the company might have used to defer disclosure.
The SEC has not publicly addressed the weaponization tactic. But the tactic's existence demonstrates that the cyber disclosure rule operates in an adversarial environment where the parties subject to the rule are not the only actors with an interest in its enforcement. The company's general counsel must now account for the possibility that the attacker will attempt to use the regulatory framework as an instrument of extortion — a consideration that was absent from corporate breach response before the rule took effect.
Annual Disclosure: The 10-K Cyber Governance Requirements
Beyond incident disclosure, the rule requires companies to describe their cybersecurity risk management processes, governance structures, and board-level oversight in their annual 10-K filings. Companies must disclose whether they have a dedicated cybersecurity risk management program, whether they engage third-party assessors, how the board of directors oversees cybersecurity risk, and whether management includes individuals with cybersecurity expertise.
These annual disclosures serve a different function than the incident 8-K. They provide investors with a baseline assessment of the company's cybersecurity posture — a standing evaluation of whether the company takes cyber risk seriously as a governance matter, not just as a technical one. A company that discloses robust board-level oversight, regular third-party assessments, and dedicated CISO-level leadership is presenting a different risk profile than a company whose 10-K reveals that cybersecurity is managed by the IT department with no board reporting line.
How to Evaluate Cyber Disclosure as an Investor
The investor reading a cyber incident 8-K should evaluate three dimensions. First, the specificity: does the company describe the nature of the incident and the systems affected, or does it use vague language designed to minimize perceived severity? "A cybersecurity event impacting certain systems" tells the investor nothing. "Unauthorized access to customer payment data in our North American retail operations" tells the investor what is at stake.
Second, the timeline: how long elapsed between discovery and the materiality determination? A company that takes 45 days to determine materiality on a breach affecting millions of records may be managing the clock rather than genuinely assessing impact. The SEC has indicated that unreasonable delays in the materiality assessment can themselves constitute a violation.
Third, the financial quantification: does the filing estimate costs (remediation, legal, notification, revenue impact) or defer all quantification? Deferral in the initial 8-K is common and acceptable — the investigation is ongoing. But subsequent 10-Q and 10-K filings should provide increasing specificity. A company that files three consecutive quarterly reports without quantifying the financial impact of a material cyber incident is either concealing the magnitude or unable to assess it. Neither inspires confidence.