Skip to content
    Back to Regulatory Radar
    CriticalNew RegulationJuly 26, 2023

    SEC Adopts Cybersecurity Disclosure Rules

    The SEC adopted final rules requiring public companies to disclose material cybersecurity incidents within four business days on Form 8-K and to provide annual disclosures of cybersecurity risk management, strategy, and governance on Form 10-K. The rules apply to all SEC registrants and mandate that companies describe board oversight of cybersecurity risk, management's role in assessing and managing risk, and the processes used to identify and manage threats. This represented the most significant federal cybersecurity disclosure mandate for public companies to date.

    SECSaaSFinTech

    Key Analytics

    July 26, 2023
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Public companies must now maintain incident response capabilities that can determine materiality and produce an 8-K filing within four business days of that determination. Annual 10-K disclosures require documented cybersecurity governance structures, forcing boards to formalize their oversight mechanisms. The rules create a new category of legal and compliance risk, as inadequate or delayed disclosures may trigger SEC enforcement and shareholder litigation. As of mid-2026 the rules remain in effect, but the SEC has opened a broad reconsideration of Regulation S-K disclosure requirements and industry groups have petitioned to rescind the Item 1.05 incident reporting requirement; no amendment has been adopted, so compliance obligations are unchanged.

    Recommended Actions

    • Establish a formal materiality determination process for cybersecurity incidents with defined criteria, responsible parties, and escalation timelines
    • Prepare 8-K and 10-K disclosure templates and conduct tabletop exercises simulating the four-business-day filing requirement
    • Document board cybersecurity oversight structures, management roles, and risk assessment processes for annual 10-K disclosure readiness

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate60-120 hours
    Key Workstreams
    • Disclosure-controls gap assessment
    • 8-K playbook integration

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 60-120 hours
    Start cold under pressureSignificant · 140-280 hours

    Roughly 80 to 160 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events