RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Policy & law

Policy & law / From the archive · 26 July 2023 event · prepared 16 September 2026

Public companies must now disclose material breaches within days

An SEC rule adopted in 2023 requires an 8-K within four business days of determining a cyber incident is material.

Visual for this record: Public companies must now disclose material breaches within days
Visual published by img.decrypt.co, shown for identification of the record. Credit: img.decrypt.co · source page ↗ Rights: owner-review-pending.

What the document says

On 26 July 2023, the Securities and Exchange Commission adopted rules requiring public companies to disclose material cybersecurity incidents. The SEC's press release describes a new Item 1.05 on Form 8-K, requiring a company to describe the material aspects of an incident's nature, scope and timing, and its material impact or reasonably likely material impact, generally within four business days of determining that the incident is material. Disclosure can be delayed if the Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety. A separate rulemaking page records that the rule took effect on 5 September 2023, with the 8-K disclosure obligation itself phased in from 18 December 2023, and that filings must use Inline XBRL formatting. The rule also added Item 106 to Regulation S-K, requiring an annual description, in Form 10-K, of a company's processes for assessing and managing cybersecurity risk, the material effects of such risks, and how the board oversees them.

An early example shows how the requirement worked in practice. VF Corporation, the apparel company, filed an Item 1.05 report on 18 December 2023, the day the requirement took effect, saying it had detected unauthorised activity on 13 December in which a threat actor deployed ransomware, encrypted some IT systems and stole data including personal data. The filing said the full scope, nature and impact of the incident were not yet known and that VF had not determined whether the incident would materially affect its financial results.

Confidence and limits

The rule's requirements and effective dates are established directly from the SEC's own materials. What an Item 1.05 filing must contain in the abstract, and what a company actually chose to disclose in its first days of investigating an incident, are two different things; VF's filing illustrates the latter, not a template every company follows identically.

Why it mattered

Before this rule, disclosure of a material cyber incident to investors depended on a company's own judgment about existing, more general disclosure obligations, with no specific clock attached. A four-business-day trigger tied to a materiality determination gives investors and regulators a benchmark against which a company's timeline can be measured, even though the materiality determination itself is still made by the company.

Defensive takeaway

If you work at a public company, confirm that your incident-response plan includes a defined path to a materiality determination, with named decision-makers, so that a security team's technical findings can reach the people who must start a four-business-day clock without unnecessary delay.

  • Does your incident-response plan name who makes the materiality determination, and how quickly technical findings reach that person?
  • Would your organisation's first Item 1.05-style disclosure, if drafted today, honestly state what is not yet known, the way VF Corporation's did?
  • Is your board briefed on its oversight role for cybersecurity risk in a way that could support an annual Item 106 disclosure?

The rule creates a disclosure clock, not a security standard, and a company can comply with its timing requirements while still describing an incident whose full scope remains genuinely unknown at the time of filing.

Defensive takeaway

Confirm your incident-response plan names who makes the materiality determination and how quickly technical findings reach that person, so a four-business-day disclosure clock can be met without unnecessary delay.

The rule's text, effective dates and Item 1.05 requirement are drawn directly from the SEC's own materials. VF Corporation's filing illustrates one company's early compliance choices; it is an example, not a template every filer follows identically.

Sources & reading trail

SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies ↗

States the adoption date, the four-business-day Item 1.05 trigger, the national-security delay provision, and the annual Item 106 risk-governance disclosure.

court-or-regulator-primary · Source published: 26 July 2023 · Retrieved: 16 September 2026

Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (Release Nos. 33-11216; 34-97989) ↗

Records the rule's effective date, the phased-in 8-K compliance date of 18 December 2023, and the Inline XBRL requirement.

court-or-regulator-primary · Source published: 26 July 2023 · Retrieved: 16 September 2026

V.F. Corporation Form 8-K (Item 1.05) ↗

An early Item 1.05 filing showing a company disclosing a ransomware incident while stating the full scope was not yet known.

company-primary · Source published: 18 December 2023 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.