SEC Cyber Disclosure Rule

The SEC Cyber Disclosure Rule (adopted July 2023) requires public registrants to disclose material cybersecurity incidents within four business days of determining materiality and to describe cyber risk management and governance in annual filings.

What the SEC Rule Actually Requires

The rule has two main components. Form 8-K Item 1.05 requires event-driven disclosure of material cyber incidents within four business days of the materiality determination. Regulation S-K Item 106 requires annual disclosure of cyber risk management, strategy, and governance in Form 10-K filings.

Together these disclosures give investors both event-specific and periodic visibility into cyber risk at SEC registrants.

Why the SEC Rule Has Changed Practice

The rule has substantially raised the stakes for cyber governance at public companies. Boards are increasingly formalizing cyber committees and expertise. Management is documenting materiality processes and quantifying cyber exposure. Legal and communications teams are pre-planning disclosure language and processes.

See how CISOs communicate cyber risk to boards for the resulting board dynamics.

Materiality Is the Central Concept

The rule ties disclosure obligations to materiality, applying the standard SEC framework. Registrants have to have a process for making materiality determinations under time pressure, and the process needs to be defensible after the fact. See materiality determination.

How Kovrr Approaches SEC Cyber Disclosure Compliance

Kovrr's Cyber Regulations and Materiality Analysis capability supports SEC Cyber Disclosure obligations with quantified analysis that connects specific incident scenarios to enterprise materiality thresholds, and provides board-ready reporting for Item 106 disclosures.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.