Data Breaches

Item 1.05 of Form 8-K: What Public Companies Tell Investors About a Cyber Incident

Key Takeaways

  • The trigger is the registrant's materiality determination, which Instruction 1 requires to be made without unreasonable delay after discovery; the filing is then due four business days later.
  • Item 1.05(a) asks for the material aspects of the nature, scope and timing of the incident and its material or reasonably likely material impact, including on financial condition and results of operations.
  • Delay is available only where the Attorney General determines disclosure poses a substantial risk to national security or public safety and notifies the Commission in writing.
  • SEC staff have said an incident not yet determined material, or determined immaterial, belongs under Item 8.01 rather than Item 1.05.
  • EDGAR's Item-1.05-tagged set held 81 filings — 55 on Form 8-K and 26 on Form 8-K/A — between the December 18, 2023 compliance date and August 31, 2026.

Item 1.05 and the Materiality Trigger

The Commission adopted its cybersecurity disclosure rules on July 26, 2023, published at 88 FR 51896, effective September 5, 2023. The rules do two separate things: they add Item 1.05 to Form 8-K for individual incidents, and they add Item 106 to Regulation S-K for annual disclosure about how a registrant manages cyber risk generally.

Item 1.05(a) as adopted reads: "If the registrant experiences a cybersecurity incident that is determined by the registrant to be material, describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations." The operative words are "determined by the registrant to be material." The trigger is not the incident, and it is not discovery of the incident — it is the registrant's own conclusion about materiality.

That construction creates an obvious risk of a determination that never quite gets made, and the Commission addressed it in Instruction 1: "A registrant's materiality determination regarding a cybersecurity incident must be made without unreasonable delay after discovery of the incident." The adopting release explains that the instruction was proposed to guard "against any inclination on the part of a registrant to delay making a materiality determination with a view toward prolonging the filing deadline."

"Cybersecurity incident" is not defined in the form. Instruction 3 imports the definition from Item 106(a) of Regulation S-K: "an unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through a registrant's information systems that jeopardizes the confidentiality, integrity, or availability of a registrant's information systems or any information residing therein." Nothing in that definition requires personal data to be involved. An availability event that touches no customer records at all can be an incident under Item 1.05, which is one of the clearest signals that this rule is aimed at investors rather than at data subjects.

The Filing Deadline

The release states the deadline in one sentence: "An Item 1.05 Form 8-K must be filed within four business days of determining an incident was material." That is the ordinary Form 8-K deadline, applied to a trigger the registrant itself sets. Commenters had proposed measuring instead from containment, remediation or mitigation; the Commission did not adopt any of them.

Compliance dates were staggered. All registrants other than smaller reporting companies began complying with Item 1.05 on December 18, 2023. Smaller reporting companies were given an additional 180 days and began on June 15, 2024 — a phase-in the Commission justified partly on the ground that smaller registrants "could benefit from additional time" and from seeing how larger companies implemented the disclosure first. Item 106 disclosure was required beginning with annual reports for fiscal years ending on or after December 15, 2023.

What Must Be Disclosed

The version of Item 1.05 the Commission proposed asked for incident detail: when the incident was discovered, whether it was ongoing, the data compromised, the effect on operations, and whether remediation was underway. The version adopted asks for much less of that. The release says the Commission was "streamlining Item 1.05 to focus the disclosure primarily on the impacts of a material cybersecurity incident, rather than on requiring details regarding the incident itself."

Two instructions bound the disclosure in the registrant's favor. Instruction 4 provides that a registrant "need not disclose specific or technical information about its planned response to the incident or its cybersecurity systems, related networks and devices, or potential system vulnerabilities in such detail as would impede the registrant's response or remediation." Instruction 2 handles the common case where impact is unknown on day four: the registrant states that in the filing, and then must file an amendment under Item 1.05 within four business days after it determines the information, without unreasonable delay, or after the information becomes available.

Item 1.05(b) requires the disclosure to be tagged in Inline XBRL under Rule 405 of Regulation S-T, on a one-year lag from the initial compliance date for the related requirement.

The National Security Delay

Item 1.05(c) is the only route to a late filing, and it does not belong to the registrant. Notwithstanding General Instruction B.1 to Form 8-K, disclosure may be delayed where the United States Attorney General determines it poses a substantial risk to national security or public safety and notifies the Commission in writing — for a period the Attorney General specifies, up to 30 days beyond the original due date. A further 30 days is available on a second written determination, and in extraordinary circumstances a final 60 on a third. Beyond that, the Commission says it will consider additional requests and may grant relief by exemptive order.

A separate and narrower delay sits in Item 1.05(d) for registrants subject to the FCC's customer proprietary network information breach rule at 47 CFR 64.2011. Where that rule requires a carrier to delay disclosing a breach, the registrant may delay the Item 1.05 filing for the applicable period and in no event more than seven business days after the FCC-required notification has been made, so long as it tells the Commission in correspondence submitted to EDGAR by the original due date.

Annual Item 106 Disclosure

Item 106 is where the registrant describes its program rather than an event, and it is furnished in the annual report — Item 1C of Form 10-K. Paragraph (b) requires a description of the registrant's processes, if any, for assessing, identifying and managing material risks from cybersecurity threats, in sufficient detail for a reasonable investor to understand them, addressing as applicable whether those processes are integrated into overall risk management, whether third-party assessors or consultants are engaged, and whether there are processes to oversee risks associated with third-party service providers.

Paragraph (b)(2) then asks whether risks from cybersecurity threats — "including as a result of any previous cybersecurity incidents" — have materially affected or are reasonably likely to materially affect the registrant, including its business strategy, results of operations or financial condition. Paragraph (c) covers governance: board oversight, any committee responsible for it, the processes by which the board is informed, and management's role, including which positions or committees are responsible and the relevant expertise of those persons. Instruction 2 to Item 106(c) says expertise may include prior work experience in cybersecurity, relevant degrees or certifications, or other background.

Item 8.01 as the Voluntary Alternative

Nothing in Item 1.05 expressly prohibits filing under it voluntarily, and in the months after the compliance date some registrants used it for incidents whose materiality was undetermined. On May 21, 2024 the Director of the Division of Corporation Finance issued a staff statement asking them not to. Where a company chooses to disclose an incident for which it has not yet made a materiality determination, or one it has determined was not material, the Division "encourages the company to disclose that cybersecurity incident under a different item of Form 8-K (for example, Item 8.01)."

The reasoning rests on what the adopting release already said: "Item 1.05 is not a voluntary disclosure, and it is by definition material because it is not triggered until the registrant determines the materiality of an incident." Filing immaterial incidents under the material-incident item, the statement says, risks investors misperceiving immaterial incidents as material and vice versa.

The statement is explicit that it is not meant to discourage voluntary disclosure, and it sets out the sequence where an Item 8.01 filing is later overtaken by events: the registrant files an Item 1.05 Form 8-K within four business days of the subsequent materiality determination, and may refer back to the earlier Item 8.01 filing so long as the new one satisfies Item 1.05. Its footnote 4 adds that filing under Item 8.01 does not relieve the registrant of the duty to determine materiality without unreasonable delay. On materiality itself, the statement points registrants back to the release's instruction to weigh qualitative factors alongside quantitative ones, including harm to reputation, customer or vendor relationships or competitiveness, and the possibility of litigation or regulatory action.

How Registrants Have Filed So Far

EDGAR tags each Form 8-K with the items it reports, and its full-text search can be filtered on that tag. A query restricted to root form 8-K and item 1.05, run on September 1, 2026, returns 92 indexed documents corresponding to 81 distinct accession numbers filed between December 18, 2023 — the compliance date itself — and August 31, 2026.

  • 55 of the 81 are original filings on Form 8-K, from 54 distinct registrants; the remaining 26 are amendments on Form 8-K/A.
  • Original filings by year: 2 in the final fortnight of 2023, 24 in 2024, 15 in 2025 and 14 in the first eight months of 2026.
  • Amendments cluster in the first full year — 14 of the 26 were filed in 2024 — which is consistent with Instruction 2 being used to supply impact information unavailable at the original deadline.

Two caveats belong with those numbers. They count filings tagged with item 1.05, not incidents: a registrant that determines an incident immaterial files nothing under this item, and one that follows the staff statement files under Item 8.01, where the tag does not appear. And a single incident can produce several documents, as the amendment count shows. What the figures do establish is the order of magnitude. Across roughly thirty-two months in which US registrants were subject to the rule — smaller reporting companies from June 15, 2024 — the Item 1.05 population is measured in tens.

Background

For the underlying law rather than this development: Financial Services privacy law, Technology & SaaS privacy law.

Frequently Asked Questions

Does Item 1.05 require disclosure of every data breach at a public company?
No. The obligation arises only once the registrant determines an incident is material. Instruction 1 requires that determination to be made without unreasonable delay after discovery, but an incident determined immaterial produces no Item 1.05 filing.
When is the Form 8-K due after a cyber incident?
Four business days after the registrant determines the incident is material — not four days after the incident or its discovery. The adopting release states the deadline in those terms and declined commenters' proposals to measure from containment or remediation instead.
What is the difference between filing under Item 1.05 and Item 8.01?
Item 1.05 is the item for incidents the registrant has determined to be material. The Division of Corporation Finance's May 2024 staff statement encourages registrants disclosing an incident whose materiality is undetermined, or that has been determined immaterial, to use a different item such as Item 8.01 instead.
Can a company delay an Item 1.05 filing because an investigation is ongoing?
Item 1.05(c) permits delay only on a written determination by the Attorney General, communicated to the Commission, that disclosure poses a substantial risk to national security or public safety. Item 1.05(d) provides a narrower delay tied to the FCC's breach rule at 47 CFR 64.2011. An ongoing internal investigation is not among the grounds; Instruction 2 instead contemplates filing with the impact undetermined and amending later.
Does a cybersecurity incident have to involve personal data to be reportable under Item 1.05?
No. Instruction 3 imports the Item 106(a) definition, which covers an unauthorized occurrence that jeopardizes the confidentiality, integrity or availability of the registrant's information systems or any information in them. An availability event affecting no personal data can meet it if the registrant determines it is material.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.