CISO Tribune

Guide

SEC Cybersecurity Disclosure Rules for CISOs: Item 1.05, Item 106 and Item 1C Explained

What the SEC's 2023 cybersecurity rules actually require: the four-business-day Item 1.05 incident clock, the annual Item 106 governance disclosure that shows up as 10-K Item 1C, and the 2024 guidance narrowing Item 1.05 to material incidents only.

By Hadass Liza Bitton · Published October 8, 2026 · Last reviewed October 8, 2026 · 6 min read

TL;DR: The SEC's 2023 cybersecurity rules created two separate obligations, and CISOs get pulled into both. Item 1.05 of Form 8-K requires disclosure of a material cybersecurity incident within four business days of determining it is material, a clock the SEC's own Division of Corporation Finance clarified in May 2024 does not start until that determination is made, and does not apply to incidents still being assessed or already found immaterial. Separately, Item 106 of Regulation S-K requires an annual disclosure, filed as Item 1C of Form 10-K, describing the company's cybersecurity risk management processes and the board's and management's oversight of them. Neither rule tells a CISO how to run a security program; both tell the company what it must say publicly about how that program is governed and how incidents move through it.

The two rules are not the same rule

It is easy to collapse "the SEC's cybersecurity rules" into one requirement. They are two, adopted together but triggered differently, and a CISO's role differs in each:

  • Item 1.05 (Form 8-K) is event-driven. It fires once, per material incident, on a four-business-day clock.
  • Item 106 of Regulation S-K, filed as Item 1C of Form 10-K, is calendar-driven. It is an annual disclosure about the company's cybersecurity governance and risk management, not about any specific incident.

Both came out of the same SEC rulemaking: Release No. 33-11216, "Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure," adopted July 26, 2023 and effective September 5, 2023. The annual Item 106/1C disclosure applies starting with fiscal years ending on or after December 15, 2023. Item 1.05 incident disclosure applied to non-smaller reporting companies beginning December 18, 2023, with smaller reporting companies given until June 15, 2024, per the SEC's own small entity compliance guide.

Item 1.05: the four-business-day incident clock

The SEC's compliance guide states the trigger plainly: a domestic registrant must file "within four business days of the registrant determining that a cybersecurity incident is material." That determination itself must be made "without unreasonable delay" once the company has enough facts to assess materiality, so the clock does not start on the day an incident is discovered, the day it is reported to law enforcement, or the day it is discussed internally. It starts on the day the company decides the incident is material.

What goes in the filing matters too. The required content covers the material aspects of the incident's nature, scope and timing, and its material or reasonably likely material impact, not a technical play-by-play. The SEC's compliance guide is explicit that Item 1.05 does not require disclosing "specific or technical information" about the company's planned response if that detail would itself impede remediation.

There is one narrow escape hatch. If the U.S. Attorney General determines that disclosure would pose a substantial risk to national security or public safety and notifies the SEC of that determination in writing, the company may delay. The compliance guide describes an initial delay of up to 30 days, a possible second 30-day extension, and, in extraordinary circumstances, a final 60-day delay if the Attorney General finds the risk is still substantial. This is a national-security determination made by the Department of Justice, not a business judgment the company or its CISO can invoke on its own.

The May 2024 correction: Item 1.05 is not for maybes

Within months of the rule taking effect, companies started filing Item 1.05 disclosures for incidents they had not yet determined were material, or had already determined were not. That defeated the point: an Item 1.05 filing was supposed to signal "this is material," and instead it was signaling "something happened, we're not sure yet."

On May 21, 2024, Erik Gerding, Director of the SEC's Division of Corporation Finance, issued a statement that corrected course. Its central line: Item 1.05 "is not a voluntary disclosure, and it is by definition material because it is not triggered until the company determines the materiality of an incident." For an incident that has not yet been assessed, or one that has been assessed and found immaterial, the statement says the Division "encourages the company to disclose that cybersecurity incident under a different item of Form 8-K," naming Item 8.01 (Other Events) as the example.

The practical consequence for a CISO: an incident response plan that routes every incident toward an Item 1.05 filing "to be safe" is now working against the SEC's own guidance, not with it. The materiality call has to happen first, and it belongs under Item 8.01 until it does.

Item 106 and Form 10-K Item 1C: the annual governance disclosure

Regulation S-K Item 106 is the rule; Item 1C is where it shows up in the filing itself. The SEC's compliance guide describes two components:

  • Risk management and strategy. The company's processes, if any, for assessing, identifying and managing material risks from cybersecurity threats, and whether cybersecurity risks have materially affected, or are reasonably likely to materially affect, the company's business strategy, results of operations or financial condition.
  • Governance. The board's oversight of cybersecurity risk, including which board committee or subcommittee (if any) is responsible, and management's role and expertise in assessing and managing cybersecurity risk.

What this looks like in practice varies enormously by company. Ryder System's Form 10-K for fiscal year 2024, filed with the SEC, describes its Item 1C section this way: "We utilize the National Institute of Standards and Technology's Cybersecurity Framework (NIST CSF) to inform our cybersecurity program and maintain International Organization for Standardization 27001 (ISO 27001) certification. Our Chief Information Officer supervises our cybersecurity program, and our Chief Information Security Officer (CISO) manages its daily operation." That single sentence does three things a CISO should recognize as the minimum: names a recognized framework, names who oversees the program, and names who runs it day to day.

Smaller or earlier-stage filers disclose far less, sometimes stating only that no formal cybersecurity risk management program exists yet. The rule does not require a company to have a mature program; it requires the company to say, accurately, what it has.

What this means for the CISO specifically

The rules are disclosure rules aimed at the company, not job-description rules aimed at the CISO, but they reshape what the job actually involves in two concrete ways. First, materiality assessment has to be fast and repeatable: a four-business-day filing clock means the incident response process needs a defined path to a materiality decision, not an ad hoc one assembled after the fact. Second, the annual Item 1C disclosure is public, which means whatever the CISO tells the board about the program's maturity and the CISO's own role in overseeing it can end up, in substance, in a filing investors and competitors both read. Neither rule is legal advice on how to write a specific filing; both are reasons the CISO's seat at the disclosure-drafting table is no longer optional.

The honest version

Two rules, two clocks: Item 1.05 fires once per material incident on four business days, and the SEC's own May 2024 guidance narrowed it to incidents already determined material, pushing everything else to Item 8.01. Item 106, filed as Form 10-K Item 1C, is the once-a-year disclosure of how the company governs cybersecurity risk and who is accountable for it, and the range of what companies actually say, from Ryder System's named framework and named roles to a shell company admitting it has no program, shows the rule sets a floor on disclosure, not a floor on security maturity.

Frequently asked questions

What is Item 1.05 of Form 8-K?
Item 1.05 is the SEC's current-report item for material cybersecurity incidents. A company must file it within four business days of determining, without unreasonable delay, that an incident is material; the clock starts at the materiality determination, not at discovery, under the SEC's final rule (Release No. 33-11216).
Is Item 1.05 disclosure required for every cyber incident?
No. The SEC's Division of Corporation Finance clarified in a May 21, 2024 statement that Item 1.05 "is not a voluntary disclosure, and it is by definition material." Incidents not yet assessed for materiality, or assessed and found immaterial, belong under a different Form 8-K item, which the statement names as Item 8.01, not Item 1.05.
What is 10-K Item 1C?
Item 1C, "Cybersecurity," is the section of Form 10-K where companies disclose the information Regulation S-K Item 106 requires: their processes for assessing, identifying and managing material cybersecurity risk, and management's and the board's role overseeing it. Ryder System's own Form 10-K, filed with the SEC, is one example on the public record that uses this exact item number and title.
Can a company delay disclosing a material cybersecurity incident?
Only if the U.S. Attorney General determines disclosure would pose a substantial risk to national security or public safety and notifies the SEC in writing. The SEC's compliance guide describes an initial delay of up to 30 days, a possible 30-day extension, and in extraordinary circumstances a final 60-day delay if the Attorney General finds the risk still substantial.
When did these SEC cybersecurity rules take effect?
The SEC adopted the rules on July 26, 2023 (Release No. 33-11216), effective September 5, 2023. Annual Item 106/1C disclosure applies to fiscal years ending on or after December 15, 2023; Item 1.05 incident disclosure applied to non-smaller reporting companies from December 18, 2023, and to smaller reporting companies from June 15, 2024.

Sources

Hadass Liza Bitton

Writer

Hadass Liza Bitton is a writer at CISO Tribune covering security leadership: the people who take the top security seat, the ones who leave it, and what each move signals. Reach her at hadass@cisotribune.com.

The Briefing

Every verified CISO move of the week, in your inbox Friday.

Every verified CISO move and one piece of analysis, weekly.

Unsubscribe any time. See the privacy policy.