Form 8-K Item 1.05
Form 8-K Item 1.05 is the specific SEC disclosure requirement for material cybersecurity incidents, requiring public registrants to file within four business days of determining that an incident is material.
What Item 1.05 Requires
When a registrant experiences a cybersecurity incident and determines it is material, Item 1.05 requires disclosure of the material aspects of the incident's nature, scope, and timing, and its material impact or reasonably likely material impact on the registrant. The disclosure is due within four business days of the materiality determination.
The four-day clock is deliberately short. It reflects the SEC's view that material cyber events should reach investors promptly rather than being disclosed in the next scheduled filing.
Materiality Is the Key Determination
The trigger is not the incident itself, it is the determination of materiality. Registrants have to have a process for making that determination when incidents occur, and the process has to be defensible after the fact. Delaying the determination unreasonably does not extend the four-day clock.
See materiality determination and cybersecurity materiality threshold.
Delayed Disclosure Provisions
Item 1.05 allows delayed disclosure if the Attorney General determines that disclosure would pose a substantial risk to national security or public safety, and notifies the SEC. This is a narrow exception and does not apply to the typical breach or ransomware event.
Item 1.05 in Practice
Filings under Item 1.05 have accumulated since the rule took effect, providing a growing body of practice. Common themes include the challenge of assessing materiality in real time during evolving incidents, the interaction with insurance and legal counsel, and the tension between prompt disclosure and complete information.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


