Forensic · 8-K items
In July 2023 the SEC adopted final rules requiring registrants to disclose material cybersecurity incidents on Form 8-K, Item 1.05. The rule took effect December 18, 2023 — making cyber disclosure one of the newest items in the 8-K taxonomy.
Item 1.05 requires disclosure when a registrant experiences a cybersecurity incident "that is determined by the registrant to be material." The 4-business-day clock starts on the date of materiality determination — not the date of the incident itself.
The rule asks filers to describe:
The SEC didn't redefine materiality for Item 1.05 — it applies the standard Supreme Court test: an event is material if a reasonable investor would consider it important. In cyber terms, that usually means an incident that meaningfully impacts operations, customer data at scale, financial systems, or strategic plans.
Despite the rule, our scans find cybersecurity-language 8-Ks filed under Item 8.01 ("Other Events") instead of Item 1.05. Sometimes this is because the filer determined the incident was not material — but the disclosure language suggests otherwise. These cases are interesting because they represent the filer's judgment about materiality, which can become contested later if facts develop.
Search SEC EDGAR for filings tagged Item 1.05 (still relatively few — under 100 per quarter). Then run a body-text search for cybersecurity language under Item 8.01 to find the gap.
Forensic surfaces both: clean Item 1.05 filings, and the buried-cyber-under-8.01 pattern. Every flagged event cites the specific accession number so you can verify the filing on EDGAR yourself.
Free risk score per ticker: filingfirehose.com/forensic
Free risk score 0-100 grounded in cited SEC filings. $9 for the full bear case.
filingfirehose.com/forensic →