Nation-State Cyberattacks and SEC Disclosure: A 2026 Practitioner Walkthrough
Your forensics team just confirmed a sophisticated intrusion. Attribution is pointing toward a foreign intelligence service. The four-business-day clock may already be running. What do you file, when, and how do you invoke the only formal carve-out in the SEC's cybersecurity disclosure rules?
This walkthrough is for the CFO, General Counsel, and CISO triad managing an active nation-state incident. It assumes you already know the basics of Item 1.05 Form 8-K cybersecurity disclosure and focuses on the decisions that generic rule summaries never address: how nation-state attribution changes your materiality analysis, how the Attorney General delay mechanism actually works in practice, and what the Salt Typhoon and Midnight Blizzard filings teach us about getting this right under pressure.
Key takeaway: The SEC's final cybersecurity disclosure rules (effective December 18, 2023 for most domestic registrants) were explicitly designed with nation-state attacks in mind. The SUNBURST, Colonial Pipeline, and Microsoft Exchange incidents are cited in the adopting release. Nation-state incidents are squarely within scope, and the rules provide only one formal delay mechanism: a written determination from the U.S. Attorney General.
The Decision Tree: Discovery to Filing
Nation-state incidents fail the standard incident-response playbook because the scope, attribution, and impact are all uncertain at the same time. Here is the sequence that keeps you compliant without forcing a premature or inadequate filing.
Step 1: Contain and Investigate (Day 0)
Activate your incident response team and outside counsel immediately. The four-business-day clock does not start at discovery. It starts at the moment you determine the incident is material. That distinction is critical: the SEC's rules instruct registrants to make the materiality determination "without unreasonable delay" after discovery, but they do not collapse discovery and determination into the same moment.
The practical implication: you have a window to investigate. Use it. But document every day of that window, because "without unreasonable delay" will be judged in hindsight by SEC staff who can see your internal communications.
Step 2: Assess Nation-State Attribution (Days 1-3)
Attribution to a nation-state is rarely certain within the first 72 hours. You do not need certainty to disclose, and the rules do not require you to name a threat actor. What you must assess is whether the attribution evidence, even if preliminary, changes the materiality calculus.
Ask these questions at this stage:
- Has the FBI, CISA, or another government agency contacted you about the incident? That contact itself is a signal.
- Are indicators of compromise consistent with known nation-state tooling (e.g., Volt Typhoon's "living off the land" techniques, Salt Typhoon's telecom targeting)?
- Is the intrusion consistent with espionage or pre-positioning rather than ransomware or financial theft?
If the answer to any of these is yes, escalate to Step 3 immediately and in parallel with your forensic investigation.
Step 3: Run the Materiality Analysis (Days 1-4)
The materiality standard is the TSC Industries test: a substantial likelihood that a reasonable shareholder would consider the information important, or that it would significantly alter the total mix of information available. The SEC explicitly requires both quantitative and qualitative factors, and for nation-state incidents, the qualitative factors dominate.
For a ransomware attack, financial impact is usually the primary driver. For a nation-state espionage intrusion, the analysis looks different:
| Factor | Ransomware | Nation-State Espionage |
|---|---|---|
| Immediate financial impact | Often quantifiable (ransom, downtime) | Often zero or deferred |
| Reputational harm | Moderate | Severe (state-sponsored targeting signals vulnerability) |
| Competitive harm | Low to moderate | High (IP theft, strategic intelligence) |
| Regulatory/litigation risk | Moderate | High (government scrutiny, class actions) |
| Customer/vendor relationship harm | Moderate | High (especially in defense, telecom, financial services) |
| Duration of access | Usually short | Often months or years |
As KPMG's analysis notes, the qualitative materiality factors are particularly significant for nation-state incidents involving IP theft or espionage, where financial impact may not be immediately quantifiable but strategic harm is severe. Document this analysis contemporaneously. That documentation is what SEC staff will ask for first.
Step 4: Assess Whether to Invoke the AG Delay (Days 1-4, in parallel)
This is the step that no generic rule summary explains in operational depth. Here is what the rules actually say and what the process looks like in practice.
How the Attorney General National-Security Delay Actually Works
What the rule provides: Item 1.05 of Form 8-K allows delay if the U.S. Attorney General determines in writing that disclosure poses a substantial risk to national security or public safety. The initial delay is up to 30 days. The AG can extend it for an additional 30 days, and in extraordinary circumstances for up to 60 additional days, for a maximum total delay of approximately 120 days. Beyond 120 days, an SEC exemptive order is required.
The SEC's guidance is direct: "Registrants should work with the Department of Justice if they believe national security or public safety may be implicated by a material cybersecurity incident."
What the operational process looks like: The SEC provides no step-by-step guidance on how to contact DOJ, what evidence is required, or how long the AG's internal review takes. Based on the structure of the rule and the Deloitte guidance on FBI/DOJ coordination, here is the practical sequence:
- Contact the FBI field office or DOJ National Security Division as soon as you suspect a nation-state incident. Do not wait for materiality determination.
- Brief DOJ on the incident, the attribution evidence, and why you believe disclosure could compromise an active investigation or national security equities.
- Request that DOJ initiate the AG determination process. This is not automatic. DOJ must affirmatively determine that disclosure poses a "substantial risk" and notify the SEC in writing.
- Simultaneously, notify the SEC's Division of Corporation Finance that you are seeking an AG determination and that you expect to delay filing. Do not simply miss the deadline without notice.
- If the AG determination arrives before your four-day deadline, you may delay. If it arrives after, you have a problem. File the 8-K and note that additional information may be forthcoming.
Critical warning: An FBI or CISA request to delay public disclosure during an active investigation does NOT legally excuse you from the four-business-day requirement. The SEC's adopting release explicitly declined to create a broader law-enforcement-request carve-out. Only the AG's written determination to the SEC triggers the delay. A phone call from an FBI agent asking you to hold off is not sufficient.
The classified information problem: Companies briefed by government agencies on nation-state threat intelligence may receive information they cannot publicly disclose. As of mid-2026, the SEC has published no formal guidance on how to handle classified threat intelligence in the context of the disclosure obligation. The practical approach: work with cleared outside counsel and DOJ to determine what can be disclosed in general terms without revealing classified sources or methods. The rules do not require you to disclose specific technical information that would impede your response or remediation, and this carve-out provides some room to describe the incident at a level of generality that protects sensitive intelligence.
How Nation-State Attribution Changes the Qualitative Materiality Analysis
The SEC's rules do not require you to attribute an attack to a specific threat actor. The disclosure obligation is triggered by the material impact of the incident, not its source. But if attribution is known and material to investors' understanding of the risk, omitting it could itself be misleading.
Consider the Volt Typhoon scenario: a Chinese state-sponsored group has pre-positioned itself in your network for potential future disruption. No data has been stolen. No systems have been disrupted. Immediate financial impact: zero. Is this material?
The answer depends on your industry and the strategic significance of the access. For a utility, a water system, or a defense contractor, pre-positioning by a foreign intelligence service is arguably material under the qualitative factors even with no immediate financial harm. The CISA/FBI advisory on Volt Typhoon (February 2024) described exactly this scenario: "living off the land" intrusions designed for future disruption rather than immediate data theft. The rules provide no bright-line answer. Document your reasoning.
For the SEC's materiality standard applied to these qualitative factors, the key question is whether a reasonable investor in your company, knowing that a foreign intelligence service has persistent access to your operational systems, would consider that important. In most cases involving critical infrastructure or defense, the answer is yes.
What the Real-World Filings Teach Us
Microsoft and Midnight Blizzard (January 2024): Microsoft filed an Item 1.05 8-K on January 19, 2024, one of the first high-profile uses of the new form item, disclosing that Russian state-sponsored actor Midnight Blizzard (Cozy Bear/APT29) had accessed its corporate email accounts, including those of senior leadership and cybersecurity teams. The initial filing was brief. A subsequent disclosure approximately seven weeks later revealed the breach was broader than initially reported.
The Microsoft example illustrates the central tension: file quickly with incomplete information, or wait for completeness and risk "unreasonable delay." The answer the rules push toward is file quickly and amend. Item 1.05 explicitly provides for amended disclosures when information that was unavailable at the time of the initial filing later becomes available. Use that mechanism. Do not hold the initial 8-K until you have a complete picture.
Salt Typhoon (2024-2025): At least nine major U.S. telecommunications companies were compromised in the Salt Typhoon campaign attributed to Chinese state-sponsored actors, according to CISA and FBI. Companies filed 8-Ks at different times and with varying levels of specificity. The inconsistency reveals a core problem: "material" is being applied very differently across companies facing the same campaign, where the primary harm is intelligence collection rather than financial disruption.
The lesson: in a nation-state espionage campaign, do not benchmark your materiality determination against what your industry peers are doing. The SEC's comment letter practice is increasingly pushing back on companies that appear to have calibrated their disclosure to competitors rather than to the actual facts of their incident.
SolarWinds and SUNBURST (the enforcement precedent): The SEC brought its first enforcement action under the cybersecurity disclosure framework against SolarWinds and its CISO Timothy Brown in October 2023. The SUNBURST attack was attributed to Russian SVR intelligence and affected approximately 18,000 customers who downloaded the compromised Orion software update. The SEC alleged that SolarWinds made materially misleading statements about its cybersecurity posture in risk factors and that its CISO knew of specific vulnerabilities that were not disclosed.
A federal court partially dismissed the SEC's claims in July 2024, finding the SEC overreached on some pre-incident risk factor theories. But claims related to SUNBURST-specific disclosures were allowed to proceed. The Harvard Law School Forum on Corporate Governance noted that naming the CISO as an individual defendant signals that personal liability for disclosure failures is a real risk for senior executives in nation-state incident response.
The SolarWinds case also established that generic, boilerplate risk-factor language about nation-state threats can itself become the basis for an SEC enforcement action if management knew of specific vulnerabilities that the generic language obscured.
Drafting the 8-K: What to Say and What to Omit
The rules require you to disclose the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact. They explicitly do not require you to disclose specific or technical information about your planned response, your cybersecurity systems, networks, devices, or potential system vulnerabilities "in such detail as would impede the registrant's response or remediation of the incident."
For a nation-state incident, this carve-out is operationally significant. You can describe:
- That an unauthorized intrusion occurred
- The systems or data categories affected at a general level
- The timing (when detected, approximate duration if known)
- The material or reasonably likely material impact on operations, financial condition, or customer relationships
- That you are investigating and have engaged law enforcement
You do not need to disclose:
- Specific vulnerabilities exploited
- Technical indicators of compromise
- Details of your remediation approach
- Attribution to a specific threat actor (though omitting known attribution can be risky if it is material)
As SEC Division of Corporation Finance Director Erik Gerding stated in December 2023: "A registrant need not disclose specific or technical information about its planned response to the incident or its cybersecurity systems, related networks and devices, or potential system vulnerabilities in such detail as would impede the registrant's response or remediation of the incident."
Keep the initial 8-K factual and brief. File an amendment when you have more complete information. The average word count of the first 17 Item 1.05 8-Ks filed under the new rules was approximately 200 words, according to Baker McKenzie's analysis cited in NACD research. Brevity is not a problem if the material facts are covered.
Drafting the 10-K: Item 106 and Nation-State Risk Factors
The annual Form 10-K Item 106 disclosure requires three things:
- Risk management and strategy: Describe your processes for assessing, identifying, and managing material risks from cybersecurity threats, and whether any such risks have materially affected or are reasonably likely to materially affect you.
- Board oversight: Describe the board's oversight of cybersecurity risks, including which committee has primary responsibility and how the board is informed.
- Management's role: Describe which management positions or committees are responsible, their relevant expertise, and how they report to the board.
For companies in sectors known to be targeted by nation-states (defense, telecom, energy, financial services), the SEC's comment letter practice since the rules took effect has been increasingly specific. Staff have pushed back on:
- Boilerplate language that does not describe actual processes
- Risk factor language that does not name the types of threats the company actually faces
- Board oversight descriptions that do not explain the actual frequency and mechanism of board briefings
- Generic references to "sophisticated threat actors" without acknowledging nation-state targeting where it is a known material risk
The fear that detailed nation-state risk factor language will itself become a roadmap for attackers is understandable but largely misplaced. The rules do not require you to describe your vulnerabilities. They require you to describe the risk environment you operate in and how you manage it. A defense contractor can say it faces nation-state targeting without disclosing which systems are vulnerable.
Drafting guidance: If your company has experienced a nation-state incident, your 10-K risk factor and Item 106 disclosure must be consistent with what management knew at the time of filing. The SolarWinds enforcement action turned, in part, on the gap between what the CISO knew and what the risk factors said. After a nation-state incident, audit your risk factor language against your internal incident documentation before filing.
Managing the Overlapping Reporting Timelines
Nation-state incidents affecting critical infrastructure companies trigger multiple reporting obligations simultaneously:
| Obligation | Regulator | Timeline | Trigger |
|---|---|---|---|
| Item 1.05 Form 8-K | SEC | 4 business days from materiality determination | Material cybersecurity incident |
| CIRCIA incident report | CISA | 72 hours from discovery | Covered cyber incident at critical infrastructure entity |
| Banking notification rule | OCC/FDIC/Federal Reserve | 36 hours from discovery | "Notification incident" at banking organization |
| TSA cybersecurity directive | TSA | Varies by directive | Pipeline, aviation sector incidents |
| NIS2 / EU obligations | National authorities | 24 hours (early warning) / 72 hours (notification) | Significant incidents at EU-regulated entities |
CIRCIA's 72-hour reporting requirement runs concurrently with the SEC's four-business-day window and is shorter. For a critical infrastructure company, you may be filing with CISA before you have completed your SEC materiality determination. Coordinate these filings through a single incident-response command structure. The CISA report does not satisfy the SEC obligation, and the SEC filing does not satisfy CISA. They are separate.
For multinational companies, a nation-state attack on operations in multiple jurisdictions may trigger EU NIS2 obligations, UK reporting requirements, and SEC obligations simultaneously. Build cross-border coordination into your incident-response plan before an incident occurs.
Board Governance: What the 10-K Must Show
If the board has been briefed by government agencies on classified threat intelligence related to a nation-state incident, the 10-K governance disclosure creates a specific challenge: how do you describe the board's oversight without revealing sensitive information?
The answer is to describe the process, not the content. The 10-K must show:
- Which committee (typically audit or risk) has primary cybersecurity oversight responsibility
- How frequently the board or committee receives cybersecurity briefings
- What the escalation path is from management to the board during an active incident
- That the board was briefed on the incident (if material) without disclosing classified details of those briefings
Deloitte's guidance emphasizes that the Item 106 governance disclosure is not a checkbox exercise. The SEC expects companies to describe the actual mechanisms, not aspirational ones. If your board was briefed by the FBI during a nation-state incident, you can describe that government law enforcement was engaged and briefed senior leadership and the board without disclosing the substance of those briefings.
The SolarWinds case also highlighted personal liability for the CISO. For companies facing nation-state attacks, the CISO's disclosure decisions during incident response are now a documented legal risk. Ensure your CISO has outside counsel engaged personally, not just company counsel, before making any public statement or filing.
Pre-Incident Governance Checklist
The time to build this infrastructure is before an incident, not during one. EY's guidance on the SEC cybersecurity rules stresses that the "without unreasonable delay" standard will be judged in hindsight, and that pre-designated decision-makers, escalation paths, and documentation requirements must exist before an incident.
For nation-state incidents specifically, your pre-incident governance should include:
- Designated materiality decision-maker: Identify who makes the materiality call (typically the CFO and General Counsel, with CISO input) and document that designation.
- DOJ/FBI contact protocol: Establish a relationship with your FBI field office and outside counsel with national security clearance before an incident. Do not try to find the right DOJ contact at 2 a.m. during an active breach.
- AG delay request template: Draft a template request for the AG national-security delay determination, including the categories of information DOJ will need to evaluate the request.
- Board escalation protocol: Define the trigger for board notification (e.g., any suspected nation-state intrusion, regardless of confirmed materiality) and the format of that notification.
- Multi-regulator notification matrix: Map every reporting obligation that applies to your company by sector and jurisdiction, with the timeline and responsible owner for each.
- Classified information handling protocol: Establish procedures for receiving and handling government threat intelligence, including which personnel have appropriate clearances and how that information factors into the materiality analysis without being publicly disclosed.
- CISO personal counsel protocol: Establish that the CISO will have access to independent outside counsel during any incident that may result in SEC disclosure.
All of this must be documented in a way that can be described in your 10-K Item 106 governance disclosure. If you cannot describe your actual process in the 10-K, you do not have an adequate process.
One final note on the AI dimension: SEC Director Gerding specifically flagged that AI may enhance the capacity of threat actors to launch sophisticated attacks. AI-accelerated vulnerability discovery and AI-assisted social engineering are already features of nation-state toolkits. As these techniques evolve, the materiality analysis for AI-enhanced nation-state intrusions will need to account for the speed and scale at which damage can occur, potentially compressing the window between discovery and material impact. Build that into your materiality determination protocols now.
FAQ
Does a suspected nation-state attack automatically trigger the four-business-day 8-K clock?
No. The clock starts when you determine the incident is material, not at discovery or attribution. Nation-state attribution may be a factor in the qualitative materiality analysis, but it does not by itself trigger the clock. You must make the materiality determination "without unreasonable delay" after discovery, and that determination must account for both quantitative and qualitative factors.
Can the FBI ask us to delay our SEC disclosure?
An FBI or CISA request to delay disclosure does not legally excuse you from the four-business-day requirement. The only formal carve-out is a written determination from the U.S. Attorney General that disclosure poses a substantial risk to national security or public safety. A law-enforcement request to hold off, without that AG determination, is not sufficient under the SEC rules.
Do we have to name the nation-state in our 8-K?
No. The rules do not require attribution to a specific threat actor. But if attribution is known and material to investors' understanding of the risk, omitting it could be misleading. The safer approach is to describe the incident at a level of generality that is accurate without providing operational intelligence to adversaries or revealing classified attribution information.
What does "without unreasonable delay" mean in practice?
The SEC has not defined a specific number of days. The standard will be judged in hindsight based on the complexity of the incident, the steps taken to investigate, and the documentation of the decision-making process. For a nation-state incident with a complex forensic picture, a thorough investigation spanning several weeks before a materiality determination is more defensible than a rushed determination, provided the investigation is genuinely ongoing and documented.
What should our 10-K say about nation-state threats if we have not had an incident?
For companies in sectors known to be targeted (defense, telecom, energy, financial services), generic references to "sophisticated threat actors" are increasingly inadequate under the SEC's comment letter practice. Name the category of threat (nation-state actors, state-sponsored groups) where it is a known material risk to your industry, describe your processes for managing that risk, and ensure the language is consistent with what management actually knows about the threat environment.
How do CIRCIA and the SEC rules interact?
CIRCIA requires critical infrastructure entities to report covered cyber incidents to CISA within 72 hours of discovery, a timeline that is shorter than the SEC's four-business-day materiality determination window. The two obligations run concurrently and independently. Filing with CISA does not satisfy your SEC obligation, and vice versa. Coordinate both through a single incident-response command structure with pre-assigned owners for each reporting obligation.







