SEC Cybersecurity Disclosure Rules: What You Need to Know
By the Legal Cyber Academy editorial team ·
The SEC's Cybersecurity Disclosure Framework: A Legal Overview
The Securities and Exchange Commission's cybersecurity disclosure rules—formally adopted in July 2023—represent one of the most significant shifts in securities compliance in recent memory. For lawyers advising public companies, boards, and executive teams, these rules are no longer a distant regulatory concern. They are an active compliance obligation demanding practical legal guidance.
This article breaks down what practicing attorneys must understand about the rules, the disclosure triggers, the liability exposure, and how to counsel clients before a crisis hits.
What the Rules Actually Require
The SEC's final rules impose two distinct but interconnected sets of obligations on public companies registered under the Securities Exchange Act of 1934:
1. Material Incident Disclosure (Form 8-K, Item 1.05)
Public companies must disclose material cybersecurity incidents on Form 8-K within four business days of determining that an incident is material. Critically, this clock starts at the point of materiality determination—not at the point of discovery.
The required disclosure must include:
- The nature, scope, and timing of the incident
- The material impact or reasonably likely material impact on the company
The SEC deliberately avoided defining "material cybersecurity incident" with technical precision, instead defaulting to the long-standing securities law standard: whether there is a substantial likelihood that a reasonable investor would consider it important. This means lawyers—not just IT professionals—must be central to the materiality determination process.
Key nuance: The rules allow a delay of up to 30 additional days if the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety. This is a narrow exception, not a routine safe harbor.
2. Annual Disclosure of Cybersecurity Risk Management and Governance (Form 10-K)
Companies must include in their annual reports a description of:
- Their processes for assessing, identifying, and managing material risks from cybersecurity threats
- Whether any risks from cybersecurity threats have materially affected the company
- The board's oversight of cybersecurity risks
- Management's role in assessing and managing cybersecurity risks, including whether management has relevant expertise
These disclosures are not boilerplate exercises. The SEC has signaled it will scrutinize vague or generic language, and plaintiffs' attorneys are already watching for inconsistencies between disclosed risk management practices and actual company behavior.
The Materiality Determination: Where Lawyers Earn Their Value
The most legally consequential—and practically difficult—obligation under the new rules is making timely, defensible materiality determinations.
Lawyers advising clients should help establish a structured materiality assessment process that:
- Convenes the right stakeholders immediately after incident detection, including legal counsel, the CISO, CFO, and relevant business unit leaders
- Documents the reasoning behind every materiality determination, whether the conclusion is to disclose or not
- Applies both quantitative and qualitative factors, including operational disruption, reputational harm, litigation risk, regulatory exposure, and customer notification obligations
- Establishes internal escalation protocols so that the four-business-day clock is understood and monitored at the executive level
Remember: the SEC has made clear that companies cannot delay the materiality assessment indefinitely while investigating technical details. The obligation to assess materiality runs concurrently with the investigation itself.
Board Governance and Management Expertise Disclosures
The annual 10-K requirements create specific governance obligations that general counsel and outside counsel must help clients satisfy.
Board Oversight
Companies must describe how the board—or a committee of the board—oversees cybersecurity risk. This does not mandate a dedicated cybersecurity committee, but it does mean boards can no longer treat cyber risk as purely a technical matter delegated entirely to management.
Practical tip: Lawyers should recommend that boards integrate cybersecurity risk into their formal risk oversight frameworks, schedule regular briefings from the CISO, and ensure that board minutes reflect substantive engagement with cyber risk topics.
Management Expertise
The rules require disclosure of whether any member of management has cybersecurity expertise, and if so, the nature of that expertise. This is descriptive, not a mandate—but it creates reputational and litigation exposure if companies overstate expertise in their disclosures.
Liability Exposure Lawyers Must Anticipate
The cybersecurity disclosure rules intersect with existing securities fraud liability under Section 10(b) of the Exchange Act and Rule 10b-5. Lawyers should help clients understand several distinct risk vectors:
- Disclosure timing liability: Delayed or incomplete 8-K filings can trigger SEC enforcement and private securities litigation, particularly if investors suffered losses during the gap between incident discovery and disclosure.
- Insider trading exposure: The rules implicitly reinforce that executives and directors with knowledge of an undisclosed material incident cannot trade company securities. Counsel should immediately review and update trading blackout policies to address cybersecurity incidents.
- Inaccurate 10-K disclosures: Describing robust risk management processes that do not reflect operational reality invites both SEC scrutiny and shareholder suits if a subsequent incident occurs.
Practical Steps for Lawyers Advising Clients Now
If you have public company clients who have not yet fully operationalized these rules, the following action items should be priorities:
- Audit existing incident response plans to confirm they include legal counsel in the materiality assessment process and account for the four-business-day disclosure timeline.
- Draft or update the cybersecurity section of the Form 10-K with defensible, specific language about actual risk management processes—not aspirational generalities.
- Conduct a tabletop exercise that simulates a material cyber incident, walking executives and board members through the decision-making and disclosure process in real time.
- Review disclosure controls and procedures (required under Rules 13a-15 and 15d-15) to confirm they now formally capture cybersecurity incidents as disclosure-relevant events.
- Coordinate with insurance counsel to assess whether directors and officers (D&O) and cyber insurance policies address regulatory enforcement costs related to disclosure failures.
The Bottom Line for Legal Practitioners
The SEC's cybersecurity disclosure rules are fundamentally a legal compliance challenge dressed in technical clothing. The disclosure triggers, materiality thresholds, governance narratives, and liability consequences are squarely within the domain of legal expertise. Companies that treat these rules as an IT problem alone will be underprepared.
Lawyers who position themselves as knowledgeable guides through these obligations—bridging the gap between the security team's technical findings and the board's disclosure responsibilities—will provide enormous value to their clients and significantly reduce the risk of costly enforcement actions and shareholder litigation.
Go deeper — courses on this
Cyber IncidentsCounsel's How To: Advising the Board on Cyber Incident Response Planning
Panelists explain the board's role in cybersecurity oversight and what that looks like in practice…
Daniel B. Garrie
FreeCISO & CTOManaging Technical and Regulatory Cybersecurity Risks
Panelists cover how cyber threats work and what attackers typically target, then walk through the 2023…
Daniel B. Garrie
Securities LawUser Guide: New SEC Cyber Rules and Balancing the Risk to Trade Secrets
Panelists explain the background and intent of the SEC's 2023 cybersecurity rules, covering reporting…
Daniel B. Garrie
Keep reading
- DeFi Protocols Under the Bank Secrecy Act: The Compliance ReckoningFinCEN's 2023 proposed rulemaking on convertible virtual currency mixing signals that DeFi protocols face real BSA obligations. Here is what…
- Blockchain & Smart Contracts: Legal Risks You Need to KnowBlockchain and smart contracts introduce unique legal risks around enforceability, liability, and regulation. Here's what practicing lawyers…
- Cyber Insurance: What Attorneys Should Advise Their ClientsCyber insurance is now a frontline risk-management tool. Learn what practicing attorneys need to know to guide clients toward the right cove…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.