The Securities and Exchange Commission's cybersecurity disclosure rules have converted what was once treated as an operational information technology concern into a matter of formal board-level fiduciary responsibility. Adopted in 2023 and now fully enforced, the rules impose two distinct obligations on nearly every public company: a rapid incident-disclosure requirement built around a four-business-day clock, and an annual governance disclosure that forces boards to describe, in writing and for investors, how they actually oversee cybersecurity risk. Directors who assumed cybersecurity belonged to management can no longer make that claim in a filing without inviting scrutiny.
For general counsel, chief information security officers, and boards, the practical question is no longer whether these obligations apply. It is whether the company can execute them under pressure and whether the record it produces will survive regulatory and litigation review. The rules reward organizations that have rehearsed their decision-making and expose those that improvise.
The four-business-day clock and why it is misread
Item 1.05 of Form 8-K requires a registrant to disclose a material cybersecurity incident within four business days from the date it determines the incident to be material. The most common misreading of this rule is that the clock starts at discovery. It does not. As the SEC has been explicit, the materiality assessment itself must be made without unreasonable delay following discovery of the incident, and the four-day window begins only once materiality is determined.
That distinction is where enforcement risk concentrates. A company cannot indefinitely postpone the disclosure deadline by simply refusing to conclude that an incident is material. Delaying the materiality determination itself, or lacking the internal processes to reach that determination quickly, is precisely the conduct that draws enforcement attention. Early enforcement patterns documented by outside counsel have targeted organizations that took weeks to assess what should have been resolved in days.
The disclosure, once triggered, must describe the nature, scope, and timing of the incident, the material impact or reasonably likely material impact on the company's financial condition and operations, and any remediation steps taken or underway. There is only one narrow exception to the timeline. Disclosure may be delayed if the U.S. Attorney General notifies the SEC that immediate disclosure poses a substantial risk to national security or public safety. For every other organization, the four-day clock is effectively absolute.
The definitions matter because they widen the aperture. Under the rules, a cybersecurity incident is an unauthorized occurrence, or a series of related unauthorized occurrences, that jeopardizes the confidentiality, integrity, or availability of a registrant's information systems or the information residing in them. The phrase series of related unauthorized occurrences is significant. It means a string of smaller intrusions that individually appear immaterial can aggregate into a reportable event, and the materiality analysis must account for that possibility.
Annual governance disclosure puts oversight on the record
The second pillar of the rules operates on a slower cadence but carries lasting consequences. Item 106 of Regulation S-K requires companies to describe, in annual reports, their processes for assessing, identifying, and managing material risks from cybersecurity threats in sufficient detail for a reasonable investor to understand. It also requires disclosure of the board's oversight of those risks and management's role in assessing and managing them.
Specificity is the point. At the 2024 AICPA and CIMA Conference on Current SEC and PCAOB Developments, SEC staff noted that merely stating a process exists is not enough. The disclosure must clearly describe the process itself, including any processes tied to third-party service providers. Staff also observed that where a group is responsible for cybersecurity risk, the expertise of each individual should be described rather than the group in the aggregate, so investors can assess collective capability and understand the impact if the group's composition changes.
For governance, companies must identify which board committee or subcommittee is responsible for oversight, how that committee is informed about risks, and how management reports cyber matters to the board. This is not a drafting exercise that can be handled entirely by disclosure counsel at year end. The filing must reflect what the board genuinely does. That reality pushes boards to review how oversight responsibility is assigned, to ensure regular briefings and updates from management, and to document those discussions so the written record matches the disclosure.
SolarWinds and the personal stakes for directors and officers
The SEC's enforcement posture gives the rules their weight. On October 30, 2023, the SEC filed a complaint against SolarWinds and its chief information security officer, Timothy Brown, alleging that both made materially misleading statements and omissions about the company's cybersecurity practices and risks. The complaint asserted that the company's public security statement inaccurately claimed adherence to standards such as the NIST Cybersecurity Framework, strong password policies, and adequate access controls, while its filings, including the first disclosure of the SUNBURST incident, offered only generic and hypothetical risk statements that failed to address known vulnerabilities.
The case is the first time the SEC charged a CISO with fraud, and the remedies sought included penalties, injunctions, and a bar against Brown serving as an officer or director of any public company. The action did not stand alone. Two shareholder derivative suits were filed against SolarWinds directors for failure to oversee operations, and the company settled a securities class action brought by shareholders for 26 million dollars. The derivative suits were later dismissed, but the broader signal remains: inadequate board oversight of cybersecurity can produce consequences at both the corporate and individual level.
That signal connects the SEC rules to a longstanding fiduciary framework. Directors face personal exposure under the Caremark standard when they fail to implement any reporting or information system regarding cybersecurity risks, or when they consciously fail to monitor an existing system and thereby disable themselves from being informed of critical compliance risks. The disclosure rules effectively raise the evidentiary bar for demonstrating that a board met this duty, because the annual filing becomes a public statement about the oversight system the board claims to maintain.
What boards must be ready to say, and to do
Readiness under these rules is a matter of process built before an incident occurs. The obligation to disclose within four business days of a materiality determination is only meetable if the company can move information from technical responders to management and the board quickly, and if the parties who must make the materiality call know in advance who they are and what standard they apply.
Several concrete steps follow from the rules and the enforcement record:
- Establish a defined materiality-assessment process that begins without unreasonable delay after discovery, with named decision-makers and a documented standard, so the disclosure clock is triggered deliberately rather than by default.
- Integrate incident response so that communication between cybersecurity functions, management, and the board is designed in advance, including the steps a board or committee would take in its oversight role.
- Assign cybersecurity oversight to a specific committee, typically the audit committee or a dedicated cybersecurity committee, with a formal charter, because that committee's existence and procedures will appear in the 10-K and must be substantive rather than performative.
- Document governance activities, including board and committee discussions, regular management briefings, and incident notifications, so the written record aligns with the annual disclosure.
- Account for aggregation, treating a series of related intrusions as a potential single material incident rather than a set of isolated events.
The through-line is that the SEC has tied disclosure quality to governance quality. A board that has rehearsed its materiality decision, defined its reporting lines, and kept a contemporaneous record will produce disclosures that are both accurate and defensible. A board that treats the rules as a year-end drafting task, or that leaves the materiality determination to chance, is the one most exposed when an incident forces it to speak within four business days. What boards must be ready to say begins with what they are prepared to do long before the clock starts.


