Four business days. That is the entire deadline at the center of the SEC's cybersecurity disclosure rule, and most board members who could recite that number could not tell you what starts the clock. It is not the breach. It is the moment the company determines the incident is material. Get that distinction wrong and a board can either file too early, before it knows enough to say anything accurate, or too late, after the SEC decides the determination should have happened sooner.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
Two separate rules, doing two separate jobs
The SEC finalized these requirements in July 2023, and they function as two distinct obligations that leadership and the board need to track separately, because they trigger on different events and live in different filings.
Item 1.05 of Form 8-K is the incident rule. It requires public companies to disclose a cybersecurity incident once the company determines that incident is material, using both quantitative and qualitative factors. The SEC has been explicit that this determination should weigh more than direct financial loss. Reputational harm, damage to customer or vendor relationships, competitive position, and the likelihood of litigation or regulatory investigation all count. Once that materiality determination is made, the company has four business days to file, describing the incident's nature, scope, and timing, along with its material impact or reasonably likely material impact. Critically, the SEC has stated that Item 1.05 disclosure is not voluntary. By definition, a company only files under this item once it has already concluded the incident is material, so there is no version of an Item 1.05 filing that understates the situation without becoming a separate accuracy problem. Companies that want to disclose an incident before completing a materiality determination, or that conclude an incident is not material but choose to say something anyway, are directed to Item 8.01 instead, specifically to avoid investors confusing a voluntary disclosure with a mandatory materiality finding.
Item 106 of Regulation S-K is the annual rule, filed as part of the 10-K, and it asks a different question entirely. It requires companies to describe their processes for assessing, identifying, and managing material risks from cybersecurity threats, to state whether cybersecurity risks have materially affected or are reasonably likely to materially affect the company, and to describe the board's oversight of cybersecurity risk along with management's role and expertise in assessing and managing it. This is not an incident disclosure. It is a standing description of the governance structure itself, reviewed and refiled every year, which means the quality of a board's actual oversight process becomes a disclosed fact rather than an internal matter.
When these rules actually started to bite
The compliance dates were staggered by company size, and boards should know which category they fall into. For accelerated and large accelerated filers, both the annual Item 106 disclosure and the incident-based Item 1.05 requirement became effective for fiscal years ending on or after December 15, 2023, with the 8-K incident requirement itself starting the later of 90 days after Federal Register publication or December 18, 2023. Smaller reporting companies received extra runway on the incident rule, with compliance required by the later of 270 days from the rule's effective date or June 15, 2024. There is one narrow escape valve. The Attorney General can authorize a delay to the four-business-day clock if immediate disclosure would pose a substantial risk to national security or public safety, and the SEC can grant additional exemptive relief on further request. This provision exists for genuinely rare cases, not as a general grace period, and boards should not assume it will be available when they need it.
What enforcement has actually shown, not what companies feared
The rule's most consequential test case is instructive precisely because of how it ended. The SEC's case against SolarWinds and its CISO, stemming from the 2020 Orion supply-chain attack, was largely gutted by a July 2024 court ruling that dismissed most of the SEC's claims, leaving only allegations about statements in the company's public security disclosures. On November 20, 2025, the SEC agreed to dismiss the remaining claims against both SolarWinds and the CISO entirely, with prejudice and without settlement conditions. Notably, in its own summary judgment filing, the SEC acknowledged that SolarWinds had in fact implemented the practices it described. That outcome, after roughly two years of litigation that many boards treated as a preview of aggressive cyber enforcement, instead signals a narrower approach going forward, one focused on egregious misstatements and outright fraud rather than second-guessing good-faith disclosure judgment calls. Individual liability for a CISO, which SolarWinds had made every board nervous about, turned out to require a much higher bar than the initial complaint suggested.
A worked example
A mid-sized manufacturer I advised discovered a ransomware intrusion that encrypted a portion of its order management system. The technical team had containment within 36 hours, and the instinct in the room was to treat the fast recovery as evidence the incident did not need disclosure. That reasoning conflates operational severity with materiality, and they are not the same test. The board's outside counsel walked through the qualitative factors specifically, whether the incident would need to be disclosed to key customers under existing contracts, whether it affected competitive standing during an active sales cycle, and whether it created litigation exposure regardless of how quickly systems were restored. The materiality determination process itself, not the incident, is what the SEC rule actually governs, and a company needs a documented, repeatable process for making that call before an incident happens, not while the clock is already running.
The strongest case against treating this as a board-level rule at all
The fair objection here is that Item 1.05 and Item 106 are, at bottom, legal and disclosure-controls matters that belong with general counsel and the audit committee, not something every director needs to master in technical detail. Boards are not equipped to independently assess whether a materiality determination process was executed correctly, and pushing this rule into full-board territory risks directors second-guessing legal judgment calls they are not positioned to make. That argument has merit for the mechanics. But Item 106 itself makes this a board matter by requirement, not by choice, because the rule explicitly asks companies to disclose how the board oversees cybersecurity risk. A board that delegates the substance entirely to counsel and never engages with the materiality framework directly has nothing accurate to disclose about its own oversight when the 10-K comes due. The rule does not need every director to be a lawyer. It needs the board to be able to describe, honestly, what its oversight process actually is, and that requires more than delegation.
Monday questions for leadership and the board
Do we have a documented, tested process for making a materiality determination, or would we be building one for the first time during an actual incident. Does our Item 106 description of board cybersecurity oversight in the last 10-K accurately describe what the board actually does, or does it describe an aspiration. Who owns the four-business-day clock once a materiality determination is made, and has that person run a drill. Would our qualitative materiality factors, reputational harm, customer relationships, litigation risk, actually get raised in the room, or does the conversation stop at direct financial loss. If the SEC's enforcement posture is narrowing toward fraud and away from disclosure nuance, are we still holding ourselves to a documentation standard that would survive scrutiny either way.
The rule was never really about the four days. It was about whether a board can prove, after the fact, that its materiality judgment was real.