Item 1.05 Form 8-K Cybersecurity Disclosure: 2026 Practitioner Walkthrough
This guide is for the GC, CFO, or compliance officer who needs to build or stress-test their company's cybersecurity incident disclosure process, not just understand the rule in the abstract. It walks through every operational decision point, in the order you will face them, from the moment an incident is detected to the moment your EDGAR filing is live.
Key takeaway: The four-business-day clock under Item 1.05 of Form 8-K does NOT run from the date you discover a cybersecurity incident. It runs from the date you determine the incident is material. Getting that sequencing wrong is the most common and most consequential mistake compliance teams make.
What Item 1.05 of Form 8-K Actually Requires
Item 1.05 is a mandatory, materiality-triggered disclosure. The SEC adopted it on July 26, 2023 as part of Release Nos. 33-11216 and 34-97989, and it became effective for most registrants on December 18, 2023 (smaller reporting companies had until June 15, 2024).
Once you determine a cybersecurity incident is material, you must file a Form 8-K under Item 1.05 within four business days. The filing must cover two things:
- The material aspects of the nature, scope, and timing of the incident.
- The material impact, or reasonably likely material impact, on the registrant, including its financial condition and results of operations.
That is the full statutory scope. The SEC deliberately kept the disclosure elements narrow compared to the proposed rules, but the materiality determination that triggers the obligation is where the real complexity lives.
For a broader view of how Item 1.05 fits alongside your other periodic disclosure obligations, see Finrep's SEC Filing Deadlines 2026: Complete Calendar by Filer Type.
Step 1: Triage the Incident Without Starting the Clock
The four-business-day window does not open at discovery. It opens at the materiality determination. This distinction is load-bearing for how you structure your internal response.
Practically, this means your incident response team can and should investigate before escalating to the disclosure decision. The rules require only that the materiality determination be made "without unreasonable delay" after discovery. That phrase is not defined with precision, but it signals that you cannot sit on a known incident indefinitely to avoid the disclosure clock.
What "without unreasonable delay" means in practice:
- Establish a written escalation protocol that routes incidents to legal and senior management within a defined window (many companies use 24 to 72 hours for initial triage).
- Document the date and time each escalation step occurs. If the SEC ever questions your timeline, your contemporaneous records are your defense.
- Do not conflate "we are still investigating" with "we have not yet started the materiality assessment." The two processes must run in parallel, not sequentially.
Common mistake: Treating the materiality determination as something that happens after the forensic investigation is complete. The SEC's rules require you to assess materiality as facts develop, not after they are fully known.
Step 2: Conduct the Materiality Determination
This is the step where most guidance is thin and where the SEC has been most explicit. The materiality standard is the same one you apply everywhere else in securities law: there is a substantial likelihood that a reasonable shareholder would consider the information important, or it would have significantly altered the total mix of information available.
The critical point, reinforced by Corp Fin Director Erik Gerding in his May 21, 2024 statement, is that the assessment must not be limited to financial condition and results of operations. You must consider qualitative factors alongside quantitative ones.
Quantitative factors to assess
- Direct financial losses (ransom payments, remediation costs, lost revenue from operational downtime)
- Insurance recovery and net exposure
- Expected litigation settlement costs
- Impact on quarterly or annual financial results
Qualitative factors to assess
- Reputational harm: will the incident damage customer or vendor relationships, or competitive position?
- Litigation and regulatory risk: does the incident create exposure to private suits, state AG investigations, FTC or sector-specific regulatory action, or non-U.S. regulatory proceedings?
- Nature of data compromised: health data, financial account data, and trade secrets carry different risk profiles than generic operational data.
- Breadth of systems affected: an attack on operational technology that halts production lines is qualitatively different from an attack that exfiltrates a marketing database.
As Gerding stated directly: companies should consider whether the incident will "harm its reputation, customer or vendor relationships, or competitiveness" and "the possibility of litigation or regulatory investigations or actions, including regulatory actions by state and Federal Governmental authorities and non-U.S. authorities."
Who makes the call, and how to document it
The rules do not specify which officer or committee makes the materiality determination, but your disclosure controls and procedures (DC&P) under Exchange Act Rule 13a-15 must be adequate to surface the information in time for the CEO and CFO to certify it under SOX Section 302. That means the determination cannot happen in a silo.
A defensible process typically looks like this:
- CISO or security team provides a technical incident summary to legal and the CFO's office within a defined window.
- Legal and finance jointly assess the qualitative and quantitative factors, with outside counsel involved for privilege protection where possible.
- Disclosure committee or equivalent makes the formal materiality determination and records it in writing, with the date and time stamped.
- CEO and CFO are briefed and the four-business-day clock is formally noted.
Document the reasoning, not just the conclusion. If the SEC later sends a comment letter, you want a contemporaneous record showing you considered the right factors, not a post-hoc reconstruction.
For the SOX 302 certification implications of this process, see Finrep's SOX Section 302 Certification Requirements: A Practitioner Walkthrough.
Step 3: Choose the Right Form 8-K Item Before You File
One of the most consequential operational decisions is which item to file under. The SEC's June 2024 CDIs and the Gerding statement made the routing rule explicit:
| Situation | Correct Item | Notes |
|---|---|---|
| Incident determined to be material | Item 1.05 | Mandatory; four-business-day deadline applies |
| Incident determined to be immaterial | Item 8.01 (voluntary) | Encouraged by Corp Fin; not required |
| Materiality not yet determined | Item 8.01 (voluntary) | Encouraged by Corp Fin; still must determine materiality without unreasonable delay |
| Incident later upgraded to material after Item 8.01 filing | Item 1.05 | New four-business-day clock starts from the subsequent materiality determination |
Why this routing matters: Before the Gerding statement in May 2024, approximately 72% of cybersecurity-related Form 8-K filings were under Item 1.05 and 28% under Item 8.01. After the statement, that ratio shifted sharply toward Item 8.01, according to Wilson Sonsini's first-year tracking study. Companies that had been filing under Item 1.05 as a precaution, even when materiality was undetermined, were effectively confusing investors and diluting the signal value of true Item 1.05 filings.
As Gerding put it: "If all cybersecurity incidents are disclosed under Item 1.05, then there is a risk that investors will misperceive immaterial cybersecurity incidents as material, and vice versa."
Filing an immaterial or undetermined incident under Item 1.05 is not just a technical error. It risks investor confusion, SEC comment letters, and reputational consequences if the market treats a precautionary filing as a material event.
Step 4: Draft the Initial Item 1.05 Filing
You have four business days from the materiality determination. In most real incidents, the investigation will not be complete by then. The rules account for this.
What the initial filing must include:
- The material aspects of the nature, scope, and timing of the incident (what happened, what systems were affected, when it occurred or was discovered)
- The material impact or reasonably likely material impact on financial condition and results of operations
- If the impact has not yet been determined: a statement saying so, and a commitment to amend once the information is available
What the initial filing does not need to include:
- A complete forensic account of the attack
- Precise dollar quantification of losses (only about 15% of first-year filers provided dollar estimates, per the Wilson Sonsini data)
- The identity of the threat actor (though if known, it may be material)
From the first year of filings, Wilson Sonsini found that almost all Item 1.05 filings stated the company was still investigating. Only seven filings (all amendments or updates) stated the investigation was complete. This is normal and expected. The SEC's rules are designed for real-time disclosure under uncertainty, not post-incident reports.
One practical note on ransomware: 18% of first-year incidents involved ransomware, but none of those filings used the word "ransomware" directly. Companies signaled it through references to data encryption and, in some cases, external posting of data. Whether this approach fully satisfies the "nature, scope, and timing" requirement is an open question that the SEC has not yet resolved through enforcement, but it is a drafting risk worth flagging with outside counsel.
On law enforcement notification: 63% of companies mentioned notifying law enforcement in their initial filing. This is not an explicit Item 1.05 requirement, but it has become a near-standard disclosure element, likely because it signals responsible incident response to investors.
Step 5: Manage the Amendment Obligation
The final rules require companies to amend their Form 8-K as new information becomes available, using an amended Form 8-K rather than a 10-Q or 10-K update. This was a deliberate change from the proposed rules.
When an amendment is required:
- When information that was unavailable at the time of the initial filing becomes available (for example, the determined financial impact after the investigation concludes)
- Within four business days after the company, without unreasonable delay, determines such information, or within four business days after it becomes available
Amendment mechanics in practice:
- Approximately one-third of first-year filers filed more than one Form 8-K for the same incident.
- Of 19 amendments tracked by Wilson Sonsini, 74% were first amendments and 26% were second amendments.
- Seven additional filings were updates not labeled as amendments but functioned as such.
Structure your amendment to clearly identify what information is new, reference the original filing date, and confirm whether the investigation is now complete. Amended filings that simply confirm "no material impact" without explaining what changed between the initial and amended filing have drawn SEC staff attention.
Step 6: Apply the National Security Delay Exception (If Applicable)
The rules include a narrow exception: a registrant may delay filing if the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety.
The four scenarios the SEC identified where this may apply:
- Incidents involving a new hacking technique with no widely known patch or defense, where disclosure could enable more attacks.
- Incidents involving sensitive government information.
- Incidents where the registrant is still remediating a vulnerability affecting critical infrastructure or a critical system.
- Incidents where a U.S. Government agency (rather than the registrant) is likely aware of a substantial risk to national security or public safety.
How the process works in practice: The FBI, in coordination with the Department of Justice, has issued guidance on how to request a temporary delay. The company must notify the AG and the SEC. The AG must then notify the SEC that disclosure poses a substantial risk. In practice, as Debevoise noted in their tracker, this exception is not expected to be invoked frequently. It is designed for genuine national security scenarios, not as a general extension mechanism for companies that need more time to investigate.
If you believe this exception may apply, engage outside counsel and your government affairs team immediately. The process involves direct coordination with federal law enforcement and is not something to navigate without experienced guidance.
Step 7: Align with Your Annual 10-K Cybersecurity Disclosures
Item 1.05 does not stand alone. The same July 2023 rulemaking added annual cybersecurity disclosure requirements to Form 10-K under Item 106 of Regulation S-K. These companion obligations cover three areas:
Risk management and strategy (Item 106(b)):
- Whether and how cybersecurity processes are integrated into the company's overall risk management system
- Whether the company engages third-party assessors, consultants, or auditors
- Whether the company has processes to oversee material risks from cybersecurity threats associated with third-party service providers
Governance (Item 106(c)):
- The board's oversight of cybersecurity risks, including any committee responsible
- The processes by which the board or committee is informed of cybersecurity risks
- Which management positions or committees are responsible for assessing and managing such risks, and their relevant expertise
- How management reports cybersecurity information to the board
The consistency trap: If your 10-K says the board receives quarterly cybersecurity briefings and your Item 1.05 filing reveals an incident that apparently bypassed that process, you have a disclosure inconsistency problem. Align your incident response governance with what you have disclosed in the 10-K, or update the 10-K to reflect reality.
Note that the final rules removed the proposed requirement to disclose cybersecurity expertise of the board of directors, and also removed the proposed aggregation of immaterial incidents for 10-Q and 10-K disclosure. However, a series of related unauthorized occurrences may still collectively trigger an Item 1.05 obligation even if each individual incident appeared immaterial on its own.
Step 8: Tag the Filing in Inline XBRL
All Item 1.05 disclosures must be presented in Inline XBRL (iXBRL). This is a technical compliance requirement that sits on top of the substantive disclosure obligation and is easy to overlook in the urgency of a four-business-day window.
Build the XBRL tagging requirement into your filing workflow before an incident occurs, not during one. Your EDGAR filing agent or in-house XBRL team should have a template ready for Item 1.05 filings that can be populated quickly. Common tagging errors in new disclosure items tend to cluster around incorrect element selection and missing required context periods. Run a validation check before submission.
For a broader view of how XBRL requirements interact with your disclosure controls, see Finrep's SEC AI-Powered Review: What It Means for 10-K and 10-Q Filings.
Enforcement Signals: What the SEC Has Shown It Will Pursue
The SEC charged SolarWinds and its CISO with fraud and internal control failures related to cybersecurity disclosures in October 2023, before Item 1.05 even took effect. The case was partially dismissed in July 2024, but it established that the SEC is willing to pursue enforcement against individuals, not just companies, for cybersecurity disclosure failures.
The SEC's comment letter program has also been active. The first comment letter under the new rules went to V.F. Corporation in January 2024, challenging a filing that stated the company had not yet determined whether the incident was reasonably likely to be material, while simultaneously filing under Item 1.05. That tension between the filing item chosen and the materiality language used is exactly the kind of inconsistency the SEC staff flags.
The practical enforcement risk is not just a formal SEC action. A poorly routed or inadequately detailed Item 1.05 filing can trigger a comment letter, require a public response, and draw investor and media attention to the disclosure process itself.
FAQ
When exactly does the four-business-day clock start? It starts on the date the registrant determines the incident is material, not the date of discovery or the date the incident occurred. The materiality determination must be made without unreasonable delay after discovery, but the disclosure deadline runs from the determination date.
Can we file under Item 1.05 before we know the full financial impact? Yes. If the incident is so significant that you determine it to be material before you have quantified the impact, file under Item 1.05 with a statement that the impact has not yet been determined, then amend the filing once that information is available. The initial filing must still describe the material aspects of the nature, scope, and timing of the incident.
What happens if we filed under Item 1.05 but the incident turned out to be immaterial? This is the scenario the Gerding statement was designed to prevent. Going forward, route undetermined or immaterial incidents to Item 8.01. If you have already filed under Item 1.05, you may need to address the inconsistency in an amendment or subsequent filing, particularly if the SEC sends a comment letter.
Do third-party incidents trigger Item 1.05? Yes, if the incident at a third party has a material impact on the registrant. In the first year of filings, 26% of reported incidents involved a third party. The four-business-day clock runs from the registrant's materiality determination, but the practical challenge is that the registrant is often dependent on the vendor to provide information about the incident's scope. Build contractual notification rights and SLAs into your vendor agreements before an incident occurs.
Does a series of small incidents ever require an Item 1.05 filing? Possibly. The rules removed the proposed aggregation requirement for 10-Q and 10-K disclosure, but a series of related unauthorized occurrences may collectively constitute a single material cybersecurity incident under the Item 1.05 definition. If you are seeing repeated intrusions that appear related, treat them as a single incident for materiality assessment purposes.
What are the XBRL tagging requirements for Item 1.05? All Item 1.05 disclosures must be tagged in Inline XBRL using the applicable EDGAR taxonomy elements. Build a pre-approved tagging template into your filing workflow so the technical requirement does not become a bottleneck during the four-business-day window.







