filing.firehose

← All posts · Published 2026-07-04

8-K Item 1.05: Cybersecurity Incident Disclosures

The SEC's new 8-K Item 1.05 rule mandates real-time disclosure of material cybersecurity incidents. Here's what triggers reporting, filing timelines, and what traders should monitor.

The New Cybersecurity Disclosure Rule: 8-K Item 1.05

In December 2023, the SEC formalized what had long been a gray area: the mandatory disclosure of material cybersecurity incidents via 8-K filing under Item 1.05. For quant traders and fundamental researchers, this represents a structural shift in how information asymmetry works. A breach that might have been buried in next quarter's 10-K now hits EDGAR in real time, creating both alpha opportunities and regulatory land mines for those who trade on it.

What Triggers Item 1.05

The rule requires filing "without unreasonable delay" (but no later than four business days) when a cybersecurity incident is both "material to investors" and has been "identified" by the company. The key threshold: would a reasonable investor consider this incident important to their investment decision?

The SEC's examples in the adopting release are helpful. A ransomware attack that forces shutdown of a manufacturing facility: triggered. Exfiltration of customer payment data that exposes payment card information: triggered. A botnet infection affecting internal non-critical systems with rapid remediation and no customer impact: likely not triggered.

What makes this tricky for compliance teams (and valuable for discerning readers): the "materiality" test is context-dependent. For a software-as-a-service company where uptime is revenue, even a brief DDoS might cross the threshold. For a holding company, the same attack on a portfolio company might not.

Item 1.05 vs. Prior Disclosure Practice

Before December 2023, cybersecurity breaches were disclosed under the catch-all Item 8.01 (Other Events) or sometimes Item 1.01 (Business Combinations, Costs Associated with Exit or Disposal Activities), creating a compliance lottery. Different registrants disclosed different incidents with wildly different timing and detail.

The new rule standardizes this. More importantly, it requires narrative disclosure of:

  • The nature and scope of the incident
  • The date it was identified
  • Whether the company is still investigating
  • The effect on operations and data
  • Whether sensitive personal information was accessed or misused
  • Any business interruption or financial impact known to date

If the company doesn't yet know the impact (which is honest, given incident response timelines), it must say so. That's valuable signal. A company's reluctance to provide numbers in the first filing, paired with aggressive disclosure in updates, suggests either sloppy forensics or a widening damage estimate.

The Four-Business-Day Clock

This is where execution risk lives. The clock starts on "identification," not discovery or public report. A breach discovered by a third party and reported to the company still doesn't trigger the four-day clock until the company acknowledges it internally and launches investigation.

In practice, large companies with mature IR teams will file within 1-2 days. Smaller or less-prepared registrants may ride out closer to day four. This creates a window where the breach is known in security circles but hasn't hit EDGAR. For traders, this matters: hedge funds with intelligence pipelines might front-run the 8-K.

The SEC has been explicit that materiality determinations can't be delegated away. A CFO can't claim they didn't know the breach was material. The rule also explicitly rejects "phased disclosure" - you can't file a vague 8-K on day four and promise details in an amendment three weeks later just because investigation is ongoing. If you don't have the facts, say so. File again when you do.

What Investors Should Watch For

As a trader or analyst, scan EDGAR for 8-K filings with Item 1.05. A few patterns signal material incidents:

  • **Ransomware with operational impact**: "Production facility offline," "customer-facing systems unavailable." These correlate with revenue recognition delays and often spark insider selling.
  • **Supply chain infections**: Incident affects the registrant's ability to fulfill orders or a critical third-party relationship. Look for vendor risk escalation in subsequent 10-K amendments.
  • **Compliance fines implied**: Incident involves personally identifiable information from EU residents, healthcare data under HIPAA, or payment card data. The 8-K disclosure often precedes regulatory action notices by 30-90 days.
  • **Vague first filing, detailed amendment**: First 8-K says "investigating scope of incident" but amend within 2-3 days with dollar figures or data volume. Usually signals worse-than-initial assessment.

Regulatory Risk and Safe Harbor Confusion

The rule creates an asymmetry that trips up even experienced SEC filers: there's no safe harbor for speculative disclosures. If you file an 8-K claiming a breach will cost $5 million and later adjust to $50 million, that's a 10b-5 violation risk even if you disclosed "unknown" in the first filing.

The safest practice is to disclose known impact (confirmed forensics, business interruption duration, payment card data volume) and flag unknowns explicitly. But many companies over-disclose first, then walk back in amendments. This is actually more flagrant than silent bad news because it suggests intentional narrative management.

Also note: there's still no bright-line definition of "material" in the rule itself. The SEC references its existing Regulation S-K guidance under Item 105 (Disclosure of Material Risks), which includes the CFIUS/national security angle. A breach involving espionage or nation-state involvement probably crosses the threshold faster than commodity ransomware.

Filing Strategy for IR Departments

If you're responsible for disclosure, understand the four-day timeline is a floor, not a target. Companies that file on day one see stock stabilize faster. Companies that file on day four invite questions from shareholders and short-sellers about why the delay.

The narrative template should include:

  • Incident type (ransomware, data exfiltration, DDoS, insider theft)
  • Date identified (not discovery date if different)
  • Investigation status and expected completion date
  • Confirmed financial impact in actual dollars or as a range
  • Regulatory notifications required (CISA? State attorneys general?)
  • Insurance recovery expected (only if already filed or substantially certain)

Avoid platitudes about cybersecurity investments. Investors want facts, not reassurance theater.

Screening for Alpha

One practical angle: 8-K Item 1.05 disclosures cluster in certain sectors. Technology companies, financial services firms, and healthcare providers file more frequently than industrial conglomerates. But when an industrial company files Item 1.05, the incident is often more severe relative to their size and risk profile, making it a higher signal-to-noise ratio for short thesis development.

Also track amendments. A registrant that files Item 1.05, then amends the same 8-K twice within a week signals a rapidly evolving incident. This often precedes credit rating downgrades, debt covenant violations, or material weaknesses in internal control disclosures in later filings.

For ongoing monitoring, tools like FilingFirehose make it easy to set alerts on Item 1.05 filings by sector or name, so you don't miss filings in the 4-24 hour window when markets are still pricing in the announcement.

The Bottom Line

Item 1.05 standardizes cybersecurity disclosure, which should theoretically improve market efficiency. In practice, it's created a new form of information cascades: 8-K filing, analyst questions, management guidance, short-seller reports, and regulatory follow-up often arrive in overlapping waves. The disciplined reader who flags Item 1.05 filings within hours of posting and cross-references them against vendor relationships, insurance filings, and peer benchmarking has a real edge.

The rule is less than two years old, so both compliance teams and investors are still calibrating materiality thresholds. Expect more amendments, SEC comment letters, and litigation to shape interpretation. For now, treat Item 1.05 as a leading indicator of operational and reputational risk, not a fully resolved disclosure framework.


Start a free FilingFirehose trial →

Try it on your stack

Get an API key in 2 minutes. Self-serve via Stripe, cancel anytime.

View pricing → Read API docs