Guide
What is SEC Form 8-K Item 1.05, and what counts as a disclosed cyber incident?
Published 2026-10-08. By the cisonews.net Desk.
A company discloses a cybersecurity incident under Item 1.05 of Form 8-K once it decides, on its own judgment, that the incident is material, and the filing is due four business days after that decision, not four business days after the company found the incident. The distinction between a decision date and a discovery date is the single most common source of confusion in reading these filings, and it is why two companies can disclose incidents of similar severity months apart in filing terms while having found them around the same time.
What does the filing actually have to say?
Item 1.05 does not call for a forensic writeup. It asks a company to describe the material aspects of the incident's nature, scope and timing, and separately to describe the incident's material impact or reasonably likely material impact on the company.
That wording points the filing toward consequence rather than technical detail: a company states broadly what happened and what it means for the business, not which specific vulnerability or exploit an attacker used. That is also why the entries on this site vary so much in technical specificity even when the underlying incidents are comparable.
When does the four-day clock start, exactly?
At the materiality determination, a judgment call the company itself makes and dates. The rule does not set a deadline from the date an incident is discovered, contained or even fully understood. A company can sit on an incident for weeks while it investigates, and the clock only starts once it concludes the incident is material, provided that determination itself is made without unreasonable delay. That single design choice is why days from detection to filing, a figure this site tracks for every Item 1.05 entry, is not the same measurement as compliance with the rule: the rule is measured from materiality, and only a minority of filings in this site's log state that date directly.
Can a company delay disclosure?
Only through one channel. The disclosure may be delayed if the United States Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the Commission of that determination in writing.
There is no general investigation-in-progress exception. A company that wants more time without an Attorney General determination has, in practice, one option under the rule as adopted: wait to make its materiality determination, while keeping that determination process itself free of unreasonable delay.
How is an Item 1.05 filing different from a voluntary Item 8.01 filing?
Item 8.01 is Form 8-K's general catch-all item, and companies used it for cybersecurity incidents long before Item 1.05 existed. The SEC's own Division of Corporation Finance has told companies to keep the two separate: an incident the company has determined is material goes under Item 1.05, while a company that wants to disclose an incident it has not determined to be material should use Item 8.01 instead, precisely so a reader can tell, from the item number alone, whether a materiality determination has already been made.
On this site, entries sourced to an Item 8.01 or Item 7.01 filing are labeled separately from Item 1.05 entries for exactly this reason: an Item 8.01 filing is not evidence the company has called the incident material.
Does a company have to say anything more once new facts come in?
Yes. If information required in the original Item 1.05 filing was undetermined or unavailable at the time, the company amends that filing by Form 8-K/A once the information becomes available, rather than waiting for its next periodic report. This site's incident entries track that amendment history explicitly: each entry records how many follow-up filings a company has made and summarizes what each one added.
Does Item 1.05 cover a company's ongoing cybersecurity program, not just incidents?
No. That is a separate requirement, Item 106 of Regulation S-K, which requires registrants to describe their processes, if any, for assessing, identifying and managing material risks from cybersecurity threats, and requires registrants to describe the board of directors' oversight of risks from cybersecurity threats, disclosed annually on Form 10-K rather than triggered by any single incident.
Foreign private issuers make a comparable disclosure on Form 20-F. Item 106 answers whether the company has a cybersecurity risk program at all, while Item 1.05 answers whether something material happened. The two items are frequently discussed together because they came from the same 2023 rulemaking, but they are triggered differently and read differently on the page.
Who had to start complying, and when?
Item 1.05 disclosures became due for most filers beginning the later of 90 days after publication in the Federal Register or December 18, 2023, whichever was later. Smaller reporting companies were given an additional 180 days before they had to begin providing the Form 8-K disclosure.
That is why this site's Item 1.05 entries start in December 2023: earlier cybersecurity-related 8-K filings in the log, where they exist, were made under Item 7.01 or Item 8.01, before the new item took effect.
Where does cisonews.net get the filings behind these numbers?
Every Item 1.05 entry on this site is pulled from SEC EDGAR's full-text search tool, which indexes the item codes EDGAR itself assigns to each 8-K, then read against the filing text directly. Nothing on an incident entry is estimated or inferred from a news summary of the filing; where a filing does not state a fact, such as a detection date, this site leaves that field blank rather than guessing.
Sources
- 2023-07-26 · AU.S. Securities and Exchange Commission, press release 2023-139, published July 26, 2023
- 2024-05-21 · AU.S. Securities and Exchange Commission, statement by Erik Gerding, Director, Division of Corporation Finance, published May 21, 2024
Tier A: the organization itself (including notices it filed with a state attorney general), a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.