SECURITIES COMPLIANCE | 2026-09-29

SEC Cybersecurity Disclosure Rules: The Form 8-K Item 1.05 Four-Day Clock for California Public Companies

Public companies must now report a material cybersecurity incident on Form 8-K within four business days of deciding it is material — and describe their cyber risk management in annual reports. Here is what the rules require.

Cybersecurity is now a securities-disclosure issue. Under the SEC’s 2023 cybersecurity rules, a public company that experiences a material cybersecurity incident must disclose it on Form 8-K within four business days of determining materiality, and must describe its cybersecurity risk management, st

A cyberattack is now also a potential disclosure event. The SEC’s cybersecurity rules require timely public reporting of material incidents and annual disclosure about how a company manages cyber risk. This guide explains the requirements for California public companies.

Form 8-K Item 1.05 — the Four-Business-Day Rule

Under new Item 1.05 of Form 8-K, a public company must disclose a material cybersecurity incident within four business days of determining that the incident is material. The disclosure must describe the material aspects of the incident’s nature, scope, and timing, and its material impact or reasonably likely material impact on the company — including its financial condition and operations. Notably, the clock runs from the materiality determination, not from discovery of the incident, but companies must make that determination without unreasonable delay after discovery.

The Materiality Determination

Materiality follows the traditional securities-law standard: information is material if there is a substantial likelihood that a reasonable investor would consider it important. Applying that to a cyber incident requires assessing both quantitative and qualitative factors — harm to operations, reputation, customer relationships, litigation and regulatory exposure — not just dollars. Because the determination triggers a four-day clock, companies need a defined process to assess materiality promptly and defensibly.

The National-Security / Law-Enforcement Delay

The rules provide a narrow delay: if the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the SEC in writing, disclosure may be delayed for a specified period. This exception is limited and controlled by the government, so companies should not assume a delay will be available.

Annual Disclosure — Regulation S-K Item 106

Beyond incident reporting, Regulation S-K Item 106 requires companies to describe, in their annual report (Form 10-K), their processes for assessing, identifying, and managing material cybersecurity risks, the material effects or reasonably likely material effects of cyber risks and prior incidents, and the board’s oversight and management’s role in cybersecurity risk. This makes cyber governance a standing disclosure item, not just an incident-driven one.

What Companies Should Do

  • Integrate disclosure counsel into the incident-response plan so materiality is assessed on the securities timeline.
  • Establish a documented, prompt materiality-assessment process.
  • Prepare Item 106 disclosures describing real risk-management processes and board oversight.
  • Coordinate with law enforcement early, understanding the narrow delay exception.

Frequently Asked Questions

When must a public company disclose a cyber incident?

On Form 8-K Item 1.05 within four business days of determining the incident is material — and the materiality determination must be made without unreasonable delay after discovery.

Does the four days run from the attack?

No — from the materiality determination. But companies cannot unreasonably delay making that determination.

Can disclosure be delayed?

Only in narrow circumstances where the U.S. Attorney General determines immediate disclosure poses a substantial national-security or public-safety risk and notifies the SEC.

What annual disclosure is required?

Regulation S-K Item 106 requires describing cyber risk-management processes, material impacts, and board and management oversight in the 10-K.

Related Securities & Governance Guides

Talk to a Securities Attorney About Cyber Disclosure

If your California public company could face a material cyber incident, the four-day 8-K clock and Item 106 disclosures require preparation now. Trembach Law Firm advises on SEC cybersecurity disclosure. Call (818) 514-7680.

Contact Trembach Law Firm at (818) 514-7680 for a confidential consultation.

Trembach Law Firm | 27001 Agoura Road, Suite 350, Calabasas, CA 91301