Auditen
Home / Frameworks / SEC Cyber Disclosure / Determining whether an incident is material

Determining whether an incident is material

Determining whether an incident is material requires establishing a formal process to evaluate if a cybersecurity event would be considered important by a reasonable investor. This involves analyzing both quantitative financial impacts and qualitative operational or reputational damages to decide if a public disclosure (Form 8-K) is required.

What it means

Under SEC rules, materiality is not defined by the technical severity of a breach, but by its impact on the company's overall financial condition and business operations. An incident is material if there is a substantial likelihood that a reasonable shareholder would consider the information important in making an investment decision.

In practice, this means companies cannot rely solely on IT or security teams to make the call. The determination must be a cross-functional effort involving legal counsel, finance, and executive leadership to ensure the "total mix" of available information is considered.

The rules also emphasize timing. While a company does not have to disclose an incident immediately upon detection, it must make the materiality determination without unreasonable delay and file the disclosure within four business days of that determination.

How to meet it

Evidence an auditor asks for

  • The formal Cybersecurity Materiality Policy or Framework document detailing the criteria used for assessment.
  • Completed materiality assessment worksheets or checklists for recent significant incidents (including those deemed non-material).
  • Meeting minutes or signed memos from the Materiality Committee documenting the rationale behind a specific determination.
  • Incident timelines showing the gap between detection, the start of the materiality analysis, and the final determination date.

Common pitfalls

  • Confusing "technical severity" with "materiality"; for example, assuming a high-severity vulnerability that was patched before exploitation is automatically material.
  • Allowing the CISO or IT department to make the materiality decision in isolation without input from Legal or Finance.
  • Failing to document why an incident was determined to be *non-material*, leaving the company unable to justify its silence if the event later becomes public.
  • Waiting for a full forensic investigation to conclude before making a determination, which may lead to "unreasonable delay" under SEC expectations.