The four-business-day incident disclosure
Public companies must file a Form 8-K under Item 1.05 within four business days after determining that a cybersecurity incident is "material." The disclosure must describe the nature, scope, and timing of the incident, as well as its material impact (or reasonably likely material impact) on the company.
What it means
The trigger for this requirement is not the date the incident was discovered, but the date the company concludes that the incident is "material." Materiality is generally defined by whether there is a substantial likelihood that a reasonable investor would consider the information important in making an investment decision.
In practice, this requires a tight integration between technical incident response teams and legal/financial executives. The organization must be able to distinguish between a routine security event and one that reaches the threshold of materiality quickly enough to meet the strict filing window.
The scope covers both actual impacts (e.g., data theft already occurred) and anticipated impacts (e.g., an incident is likely to disrupt operations significantly). While certain delays are permitted for national security or public safety reasons, these require notification to the U.S. Attorney General.
How to meet it
- Establish a formal materiality determination process that defines who is responsible for making the call and what criteria they use.
- Integrate a "materiality trigger" into the existing Incident Response Plan (IRP), ensuring technical teams notify legal/compliance as soon as a potential material event is identified.
- Create a cross-functional committee (including Legal, CFO, CISO, and IR) tasked with reviewing incident data to make the formal materiality determination.
- Develop a pre-approved 8-K drafting template for Item 1.05 to ensure all required elements—nature, scope, timing, and impact—are addressed without delay.
- Maintain a "disclosure clock" log that records the exact date and time a determination of materiality was reached to track the four-business-day deadline.
Evidence an auditor asks for
- The written Cybersecurity Incident Response Plan (CIRP) showing the specific workflow for escalating incidents for materiality review.
- Documented evidence of materiality assessments, such as meeting minutes or signed memos, showing when a determination was made and the reasoning used.
- Copies of filed Form 8-Ks that correspond to documented material incidents within the audit period.
- A timestamped log comparing the date of incident discovery versus the date of materiality determination and the subsequent filing date.
Common pitfalls
- Confusing "discovery" with "materiality": Filing too early based on initial detection or filing too late by waiting until a full forensic investigation is complete before making a materiality decision.
- Lack of documentation: Making the materiality determination verbally without a written record, leaving the company unable to prove when the four-business-day clock actually started.
- Siloed communication: Technical teams failing to alert legal/compliance in time for them to evaluate materiality and draft the filing within the window.