4 DAYS
From the materiality call
Item 1.05 requires a Form 8-K within four business days of determining an incident is material — and that determination must be made without unreasonable delay.
The SEC's cyber rule turns a material incident into a Form 8-K filing due in four business days — and the clock starts the moment you call it material. Get the materiality judgment or the disclosure wrong and it's an enforcement problem, not just an IT one. We build the process before the clock ever starts.
Book a SEC Disclosure Strategy Call →// WHY THIS RULE, WHY NOW
4 DAYS
Item 1.05 requires a Form 8-K within four business days of determining an incident is material — and that determination must be made without unreasonable delay.
YEAR-ROUND
The annual 10-K requires disclosing your cyber risk management, strategy, and governance — including board oversight. The description itself must not be misleading.
ENFORCED
The SEC has brought settled enforcement actions over cyber disclosures that minimized incidents. A defensible, documented process is no longer optional.
// IT CAN'T MAKE THIS CALL ALONE
Containing the incident is security's job; deciding whether it's material and filing the 8-K is a securities-disclosure decision involving the board, general counsel, and the CFO — on a four-business-day clock. The rule doesn't grade your firewalls; it grades whether you made a defensible materiality determination without unreasonable delay and described the incident accurately. The companies that get into trouble are the ones improvising that judgment mid-crisis. We build the process so the decision is rehearsed, not invented under pressure.
// THE FOUR DISCLOSURE OBLIGATIONS
The rule has several moving parts, but everything pivots on one decision. The materiality determination is the trigger — it starts the four-day clock and is itself the hardest, most scrutinized call.
Everything flows from this one judgment: is the incident material? The determination must be made without unreasonable delay, and the four-business-day filing clock starts the moment you make it — not when you discovered the breach. Get this call documented and defensible and the rest is mechanics; get it wrong and it's an enforcement question. The three obligations below are what the determination sets in motion.
// ITEM 1.05 · FORM 8-K
Incident Disclosure
Describe the material nature, scope, timing, and impact within four business days of the determination.
// ITEM 106 · FORM 10-K
Governance Disclosure
Annual disclosure of cyber risk management, strategy, and board oversight. A year-round duty.
// AMENDMENT DUTY
8-K Amendment
If information was unavailable at filing, amend within four business days of obtaining it.
Item 1.05 is for material incidents only — immaterial ones go under Item 8.01.
// THE PATH
What actually happens when an incident hits. The amber stages are the regulator-facing moments — the materiality determination that starts the clock, and the 8-K filing that stops it.
Detect
Identify Incident
HOUR 0
Triage
Scope & Severity
DAY 0–1
Determine
Materiality Call
NO DELAY
Draft
8-K Disclosure
WITHIN 4 BD
File
Item 1.05 Filing
DAY 4
Amend
Update & 10-K
ONGOING
Amber stages are the regulator-facing moments — the materiality determination, which must come without unreasonable delay and starts the four-day clock, and the Item 1.05 filing that satisfies it. Everything before them is preparation that decides whether you make the window.
// IS THIS YOU?
// 01 // PUBLIC CO
You file with the SEC. Item 1.05 and the 10-K governance disclosure already apply to you — the only question is whether your process is ready.
// 02 // NO MATERIALITY PROCESS
If a breach hit tomorrow, no one could say who decides materiality, how, or how fast. That judgment can't be invented mid-crisis under a four-day clock.
// 03 // THIN 10-K
Your governance and risk-management disclosure is boilerplate, or describes a program you don't really run. The description itself must not mislead.
// WHAT WE DO
// Phase 01 · Prepare
We build the documented materiality-assessment framework and wire it into incident response, so the determination is fast, consistent, and defensible the moment an incident is identified.
// Phase 02 · Rehearse
We rehearse the four-day clock with the board, counsel, and finance through tabletop exercises, and pre-build the 8-K and Item 8.01 paths so the right item is filed the first time.
// Phase 03 · Govern
We help build the cyber risk-management program and board-oversight structure that the annual 10-K describes — and the evidence that the description is accurate, not aspirational.
// THE CLOCK STARTS AT THE MATERIALITY CALL
// FREQUENTLY ASKED
Almost, but the clock is widely misunderstood. Item 1.05 requires filing within four business days — but those days run from when you determine the incident is material, not from when you discover it. The catch: that determination must be made without unreasonable delay, so you can't postpone the clock by never making the call.
The real work happens before the four days start: a defined, documented process to assess materiality quickly and defensibly. The disclosure must describe the incident's material nature, scope, timing, and impact. A narrow national-security delay exists only if the U.S. Attorney General notifies the SEC in writing. For most companies, the path to compliance is a tested process in place long before an incident.
Materiality uses the same standard as any securities disclosure: information is material if there's a substantial likelihood a reasonable investor would consider it important, or that it would significantly alter the total mix of information. The SEC deliberately did not create a cyber-specific test, so you weigh a broad spectrum of quantitative and qualitative factors — financial impact, operational disruption, reputational harm, legal and regulatory consequences, customer impact.
Importantly, an incident isn't immaterial just because you paid a ransom, recovered quickly, or were insured. Because the judgment is fact-specific and made under pressure, the defensible approach is a documented materiality framework applied consistently, with the analysis preserved as evidence — exactly what regulators and your board will want to see afterward.
Item 1.05 is reserved for incidents you've determined to be material — it's by definition a material-incident disclosure. SEC staff guidance has clarified that companies shouldn't use 1.05 for immaterial incidents or ones where materiality hasn't been determined, because that confuses investors. For those, the SEC encourages voluntary disclosure under Item 8.01 instead.
The sequence matters: if you disclose under 8.01 before a materiality call and later determine it was material, you must then file a 1.05 within four business days of that determination, referencing the earlier filing. Choosing the wrong item, or hedging materiality in a misleading way, is exactly the kind of problem that has drawn SEC enforcement. We build the triage logic so the right item, with the right content, is filed the first time.
The 8-K is only half the rule. The annual Form 10-K (Regulation S-K Item 106) requires describing your cybersecurity risk management and strategy — how you assess, identify, and manage material cyber risks — and your governance, including the board's oversight and management's role. This is a year-round obligation that effectively requires a real program you can describe accurately, because the description is itself a disclosure that must not mislead.
There's also an amendment duty: if required information wasn't available at the original filing, you say so and file an amendment within four business days of obtaining it. Foreign private issuers make comparable disclosures on Forms 6-K and 20-F. In short, the rule rewards companies running a genuine, documented program and penalizes those whose disclosures outrun their reality.
// THE NEXT MOVE
Book a 30-minute SEC disclosure strategy call with a WatchUr6 advisor. Bring whether you're a public company or FPI, whether you have a documented materiality process, and how your board oversees cyber today. You'll walk away knowing your biggest disclosure gaps and a path to a defensible process — whether you hire us or not.
Book a SEC Disclosure Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED