The SEC’s Four-Business-Day Cyber Disclosure Clock Starts After Materiality
US public companies do not receive four days to investigate every cyber incident. They generally receive four business days after determining that an incident is material.
The Securities and Exchange Commission’s cybersecurity disclosure rules changed the way public companies connect incident response to corporate disclosure. The current-report requirement began applying to most registrants on 18 December 2023, with a later date for smaller reporting companies.
The rule is frequently reduced to “report a breach within four days”. That shortcut is wrong in two important ways.
First, the disclosure requirement concerns a cybersecurity incident determined to be material, not every security event. Second, the four-business-day period begins after the company makes that materiality determination—not necessarily when the incident occurred or was first discovered.
Materiality is the decision point
A company must determine materiality without unreasonable delay. It applies the established securities-law standard, considering whether a reasonable investor would view the information as important.
The analysis is not limited to the number of records or size of a ransom demand. Relevant effects may be qualitative as well as quantitative: operational disruption, lost revenue, safety consequences, customer departure, legal exposure, intellectual-property loss or damage to critical relationships.
Related incidents may need to be considered together. A series of individually small intrusions can become material when it represents one campaign or collectively creates a significant effect.
The filing is not a forensic report
Item 1.05 of Form 8-K generally requires disclosure of material aspects of the incident’s nature, scope and timing, together with its material impact or reasonably likely material impact.
The SEC does not require technical detail that would impede response or remediation. A company should not publish exploitable indicators, unpatched vulnerabilities or a roadmap to its recovery environment merely to make the filing look complete.
If required information is not yet determined or available, the filing can say so and be amended after the information becomes available, following the rule’s requirements.
Incident response and disclosure must run in parallel
Traditional incident response often moves from technical investigation to management and then to legal review. That sequence may be too slow.
A better model creates parallel tracks:
- containment and recovery;
- evidence preservation and scoping;
- financial and operational impact assessment;
- legal and regulatory notification analysis;
- executive and board escalation;
- preparation of accurate public disclosure.
The tracks must exchange information without allowing the demand for certainty to delay the materiality decision unreasonably.
Annual reports also change
The rules add annual disclosure about processes for assessing, identifying and managing material cybersecurity risk. Registrants also describe management’s role and the board’s oversight.
This is not a requirement to publish a sensitive control catalogue. It is a requirement to explain the governance and risk process in decision-useful terms.
The public description should match reality. If an annual report says that cyber risks are integrated into enterprise risk management, the organisation should be able to show the reporting, ownership and decisions that make the integration real.
A practical readiness exercise
Public companies and foreign private issuers should test:
- Who has authority to determine materiality?
- What technical and business evidence reaches that group?
- How are related incidents identified and aggregated?
- Can legal, finance, communications and security work simultaneously?
- Who prepares and approves an Item 1.05 filing?
- How are incomplete facts and later amendments handled?
- Do annual governance disclosures still describe the real process?
Four days is the final clock, not the first conversation
The rule does not require an immediate public conclusion before facts are understood. It does require the organisation to reach an informed materiality decision without avoidable delay and then act quickly.
Companies that wait until an incident is obviously catastrophic to introduce the CISO to disclosure counsel have already lost the time the rule is designed to protect.
Official sources
- SEC final rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
- SEC statement explaining the disclosure trigger
This article provides general information and is not legal advice.
Continue the series: AMER Cyber & Digital Law Series index



