Analysis
Two years of SEC cyber incident disclosures: what companies actually said
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
Companies that reported a material cybersecurity incident under Form 8-K Item 1.05 usually filed within a week of detecting it, and by 2026 most of them were in health care or medical technology. Across the 56 Item 1.05 incidents in the cisonews.net log, the median gap between the detection date a filing states and the company's first 8-K about the incident is six days.
This piece reads the log as a dataset. Every figure below is computed from entries already published on this site, each of which links the underlying filing. Where an entry is named, the link goes to it.
The rule being measured
The SEC adopted the incident disclosure requirement in July 2023. Item 1.05 filings are due four business days after a company decides an incident is material, not four days after it finds the incident. The 8-K requirement began for most filers on December 18, 2023. A company can also delay if the U.S. Attorney General finds that disclosure would pose a substantial risk to national security or public safety.
In May 2024 the head of the SEC's Division of Corporation Finance said companies reporting incidents they had not found material should use Item 8.01 instead, so that an Item 1.05 filing would signal materiality.
How many, and when
The log holds 56 incidents with an Item 1.05 filing: 2 first disclosed in December 2023, 23 in 2024, 15 in 2025 and 16 in 2026 through September 23. The 2024 total is lopsided. Sixteen of those incidents were first disclosed in the first half of the year and seven in the second half. The drop follows the May 2024 staff statement, and the log cannot show whether one caused the other. From 2025 onward the pace held at seven to nine per half-year.
A further 21 entries are incidents disclosed only under Items 7.01 or 8.01, most of them from 2022 and 2023, before Item 1.05 applied. They are excluded from the counts in this piece unless stated.
Detection to disclosure
Of the 56 Item 1.05 incidents, 47 give a detection date precise to the day. For those, the gap to the first 8-K about the incident breaks down this way:
| Days from detection to first 8-K | Incidents |
|---|---|
| 0 to 4 | 15 |
| 5 to 7 | 15 |
| 8 to 30 | 12 |
| More than 30 | 5 |
The five long gaps have different explanations in the filings themselves. Two companies had a Justice Department delay under Item 1.05(c): AT&T, whose filing came 84 days after it learned of the claim, and F5, at 67 days. Conduent, at 91 days, restored systems within days but filed only after specialists had analysed the stolen files. BayFirst Financial was told of a vendor's incident 77 days before it filed, and the vendor confirmed customer exposure two days before the filing. Hewlett Packard Enterprise filed 43 days after being notified.
For entries where a company first reported under Item 8.01 and later moved to Item 1.05, such as Stryker and Boston Scientific, the gap is measured to the first 8-K, because that is when investors first heard of the incident.
The materiality date
Because the deadline runs from the materiality decision, the date of that decision matters more than the detection date for compliance. Only nine of the 56 filings state it. Eight of the nine were filed in 2026, and in each of the nine the filing followed the stated decision within five calendar days. CareCloud is typical of the 2026 pattern: an eight-hour disruption, contained the same day, judged material a week later because of the data involved. Navient reached the same kind of conclusion about an incident at an outside law firm, with no disruption to its own systems.
That reasoning, material because of what was taken rather than what it cost, runs through most 2026 filings in the log. Many of the same filers said in the same document that they did not expect a material effect on their financial condition.
Who is filing
By sector, the 56 incidents split into financial services (10), consumer and retail (9), technology (9), health care (8), life sciences and medical devices (7), industrials and manufacturing (5), telecommunications (3), transportation and logistics (2), and one each in real estate, media, and energy and utilities. The mix changed over time. In 2026, 11 of the 16 Item 1.05 incidents so far are at health care providers or life sciences and medical device companies, against 3 of 23 in 2024 and 1 of 15 in 2025.
Follow-up filings
Item 1.05 expects companies to amend when information missing at filing becomes available. In the log, 29 of the 56 incidents have no follow-up filing, 20 have one, and 7 have two or more. The most amended is River Financial, with four 8-K/As in five weeks, none of which had yet settled whether personal information was involved.
What the log cannot tell you
The log records what companies chose to say. A filing that gives no detection date may reflect a company's drafting choice rather than an unknown date, so the 47-incident timing sample is not random. The EDGAR sweep that built the log relies on the item codes EDGAR assigns, and an Item 1.05 filing coded differently could be missing. Corrections and additions are welcome through the contact page.
Sources
- 2023-07-26 · AU.S. Securities and Exchange Commission, press release 2023-139, published July 26, 2023
- 2024-05-21 · AU.S. Securities and Exchange Commission, statement by Erik Gerding, Director, Division of Corporation Finance, published May 21, 2024
- 2024-07-12 · AAT&T Inc., Form 8-K (SEC EDGAR), published July 12, 2024
- 2025-10-15 · AF5, Inc., Form 8-K (SEC EDGAR), published October 15, 2025
- 2025-04-14 · AConduent Incorporated, Form 8-K (SEC EDGAR), published April 14, 2025
- 2026-03-27 · ACareCloud, Inc., Form 8-K (SEC EDGAR), published March 27, 2026
- 2026-07-02 · ANavient Corporation, Form 8-K (SEC EDGAR), published July 2, 2026
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.