WATCHUR6 // SEC ITEM 1.05 // AUDIT READINESS

A breach is now a
four-day disclosure event.

The SEC's cyber rule turns a material incident into a Form 8-K filing due in four business days — and the clock starts the moment you call it material. Get the materiality judgment or the disclosure wrong and it's an enforcement problem, not just an IT one. We build the process before the clock ever starts.

Book a SEC Disclosure Strategy Call
ITEM 1.05 FORM 8-K 4 BUSINESS DAYS 10-K GOVERNANCE VETERAN-LED

// WHY THIS RULE, WHY NOW

The breach is the easy part. The disclosure is what regulators grade.

4 DAYS

From the materiality call

Item 1.05 requires a Form 8-K within four business days of determining an incident is material — and that determination must be made without unreasonable delay.

YEAR-ROUND

Not just at incident time

The annual 10-K requires disclosing your cyber risk management, strategy, and governance — including board oversight. The description itself must not be misleading.

ENFORCED

The SEC is already acting

The SEC has brought settled enforcement actions over cyber disclosures that minimized incidents. A defensible, documented process is no longer optional.

// IT CAN'T MAKE THIS CALL ALONE

Our security team will handle a breach if one happens.
Item 1.05 is a disclosure decision, made under a clock, by the board and counsel.

Containing the incident is security's job; deciding whether it's material and filing the 8-K is a securities-disclosure decision involving the board, general counsel, and the CFO — on a four-business-day clock. The rule doesn't grade your firewalls; it grades whether you made a defensible materiality determination without unreasonable delay and described the incident accurately. The companies that get into trouble are the ones improvising that judgment mid-crisis. We build the process so the decision is rehearsed, not invented under pressure.

// THE FOUR DISCLOSURE OBLIGATIONS

Four obligations. One judgment that triggers them all.

The rule has several moving parts, but everything pivots on one decision. The materiality determination is the trigger — it starts the four-day clock and is itself the hardest, most scrutinized call.

The Materiality Determination The trigger · starts the 4-business-day clock

Everything flows from this one judgment: is the incident material? The determination must be made without unreasonable delay, and the four-business-day filing clock starts the moment you make it — not when you discovered the breach. Get this call documented and defensible and the rest is mechanics; get it wrong and it's an enforcement question. The three obligations below are what the determination sets in motion.

// ITEM 1.05 · FORM 8-K

Incident Disclosure

Describe the material nature, scope, timing, and impact within four business days of the determination.

// ITEM 106 · FORM 10-K

Governance Disclosure

Annual disclosure of cyber risk management, strategy, and board oversight. A year-round duty.

// AMENDMENT DUTY

8-K Amendment

If information was unavailable at filing, amend within four business days of obtaining it.

Item 1.05 is for material incidents only — immaterial ones go under Item 8.01.

Final Rule · ADOPTED JULY 2023, IN EFFECT FPIs · FORM 6-K / 20-F EQUIVALENT 4 Business Days · FROM THE MATERIALITY CALL

// THE PATH

From incident to filing, on the clock.

What actually happens when an incident hits. The amber stages are the regulator-facing moments — the materiality determination that starts the clock, and the 8-K filing that stops it.

Detect

Identify Incident

HOUR 0

Triage

Scope & Severity

DAY 0–1

Determine

Materiality Call

NO DELAY

Draft

8-K Disclosure

WITHIN 4 BD

File

Item 1.05 Filing

DAY 4

Amend

Update & 10-K

ONGOING

Amber stages are the regulator-facing moments — the materiality determination, which must come without unreasonable delay and starts the four-day clock, and the Item 1.05 filing that satisfies it. Everything before them is preparation that decides whether you make the window.

// IS THIS YOU?

Three signs this rule is already your problem.

// 01 // PUBLIC CO

You're a public company or FPI

You file with the SEC. Item 1.05 and the 10-K governance disclosure already apply to you — the only question is whether your process is ready.

// 02 // NO MATERIALITY PROCESS

You have no materiality playbook

If a breach hit tomorrow, no one could say who decides materiality, how, or how fast. That judgment can't be invented mid-crisis under a four-day clock.

// 03 // THIN 10-K

Your 10-K cyber disclosure is thin

Your governance and risk-management disclosure is boilerplate, or describes a program you don't really run. The description itself must not mislead.

// WHAT WE DO

The materiality process, the filing, and the governance.

// Phase 01 · Prepare

Materiality & Response Process

We build the documented materiality-assessment framework and wire it into incident response, so the determination is fast, consistent, and defensible the moment an incident is identified.

  • Documented materiality decision framework
  • Incident severity triage and escalation
  • Disclosure controls and procedures

// Phase 02 · Rehearse

Tabletop & Filing Readiness

We rehearse the four-day clock with the board, counsel, and finance through tabletop exercises, and pre-build the 8-K and Item 8.01 paths so the right item is filed the first time.

  • Board and C-suite tabletop exercises
  • Item 1.05 vs. 8.01 triage logic
  • Draft 8-K templates and amendment workflow

// Phase 03 · Govern

10-K Governance & Evidence

We help build the cyber risk-management program and board-oversight structure that the annual 10-K describes — and the evidence that the description is accurate, not aspirational.

  • Item 106 risk-management and strategy program
  • Board cyber-oversight structure and cadence
  • Disclosure evidence and accuracy review

// THE CLOCK STARTS AT THE MATERIALITY CALL

You can't draft a defensible 8-K in four days if the process starts the day of the breach.

Book a SEC Disclosure Strategy Call

// FREQUENTLY ASKED

The SEC cyber-disclosure questions boards keep asking.

Do we really have only four days to disclose a breach to the SEC?

Almost, but the clock is widely misunderstood. Item 1.05 requires filing within four business days — but those days run from when you determine the incident is material, not from when you discover it. The catch: that determination must be made without unreasonable delay, so you can't postpone the clock by never making the call.

The real work happens before the four days start: a defined, documented process to assess materiality quickly and defensibly. The disclosure must describe the incident's material nature, scope, timing, and impact. A narrow national-security delay exists only if the U.S. Attorney General notifies the SEC in writing. For most companies, the path to compliance is a tested process in place long before an incident.

What makes a cybersecurity incident "material"?

Materiality uses the same standard as any securities disclosure: information is material if there's a substantial likelihood a reasonable investor would consider it important, or that it would significantly alter the total mix of information. The SEC deliberately did not create a cyber-specific test, so you weigh a broad spectrum of quantitative and qualitative factors — financial impact, operational disruption, reputational harm, legal and regulatory consequences, customer impact.

Importantly, an incident isn't immaterial just because you paid a ransom, recovered quickly, or were insured. Because the judgment is fact-specific and made under pressure, the defensible approach is a documented materiality framework applied consistently, with the analysis preserved as evidence — exactly what regulators and your board will want to see afterward.

Item 1.05 versus Item 8.01 — which do we file?

Item 1.05 is reserved for incidents you've determined to be material — it's by definition a material-incident disclosure. SEC staff guidance has clarified that companies shouldn't use 1.05 for immaterial incidents or ones where materiality hasn't been determined, because that confuses investors. For those, the SEC encourages voluntary disclosure under Item 8.01 instead.

The sequence matters: if you disclose under 8.01 before a materiality call and later determine it was material, you must then file a 1.05 within four business days of that determination, referencing the earlier filing. Choosing the wrong item, or hedging materiality in a misleading way, is exactly the kind of problem that has drawn SEC enforcement. We build the triage logic so the right item, with the right content, is filed the first time.

Beyond the 8-K, what does the rule require year-round?

The 8-K is only half the rule. The annual Form 10-K (Regulation S-K Item 106) requires describing your cybersecurity risk management and strategy — how you assess, identify, and manage material cyber risks — and your governance, including the board's oversight and management's role. This is a year-round obligation that effectively requires a real program you can describe accurately, because the description is itself a disclosure that must not mislead.

There's also an amendment duty: if required information wasn't available at the original filing, you say so and file an amendment within four business days of obtaining it. Foreign private issuers make comparable disclosures on Forms 6-K and 20-F. In short, the rule rewards companies running a genuine, documented program and penalizes those whose disclosures outrun their reality.

// THE NEXT MOVE

Rehearse the four-day clock before it ever starts.

Book a 30-minute SEC disclosure strategy call with a WatchUr6 advisor. Bring whether you're a public company or FPI, whether you have a documented materiality process, and how your board oversees cyber today. You'll walk away knowing your biggest disclosure gaps and a path to a defensible process — whether you hire us or not.

Book a SEC Disclosure Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED