Two years in, the most important cybersecurity regulation of the decade is not from the cybersecurity agencies. It is from the Securities and Exchange Commission.
The SEC’s 2023 cybersecurity disclosure rules went into effect in December 2023, with the smaller company phase in through June 2024. By the middle of 2026, the early enforcement actions have settled into a pattern, and the pattern is not what most boards expected. The companies getting in trouble are not, mostly, the companies that got breached. They are the companies that got breached, then took too long to disclose, or described the breach in language that minimised the impact, or failed to describe their board’s oversight of cyber risk in their annual filings.
The shift this represents is structural. Cyber risk has become a financial reporting problem, and the consequences now flow through the same machinery as any other financial misstatement.
What the SEC actually requires
Two requirements, both of which are now enforceable. First, public companies must disclose material cybersecurity incidents on Form 8-K within four business days of determining that the incident is material. The materiality determination is left to the company, but it must be made promptly, and it must be documented. Second, public companies must describe in their annual 10-K filings their board’s oversight of cybersecurity risk, management’s role in assessing and managing that risk, and the processes in place to do so.
Both requirements are deceptively simple. The first is a timing and judgement requirement. The second is a governance disclosure requirement. Neither is a technical security requirement. Neither tells a company how to secure its systems. Both, however, change what the company has to be able to prove, on a deadline, in a public filing.
The early enforcement actions and what they signal

The enforcement actions to date share a common shape. A company experienced a cybersecurity incident. The company began an investigation. The investigation took longer than four business days. The 8-K disclosure was either late, vague, or both. The SEC then brought an enforcement action not for the underlying breach but for the disclosure failures around it. The pattern is consistent: the breach serves as the setup, the disclosure serves as the violation.
The signal is clear. The SEC is not the FTC, the Department of Homeland Security, or the FBI. The SEC’s job is to make sure investors have accurate, timely information about the companies they own. A material cyber incident that is not disclosed in time is a securities law violation, full stop. The fact that the underlying breach is embarrassing or costly is not a defence. The fact that the company is cooperating with other agencies is not a defence. The disclosure timeline amounts to the test.
Why “we are investigating” is no longer an acceptable holding pattern
For the first 20 years of mandatory cyber disclosure at the state level, the standard pattern was to disclose as little as possible, as late as possible, with as much reassuring language as the lawyers would allow. The new SEC rules reject that pattern. The four business day clock starts when the company determines materiality, not when the company discovers the incident, but the determination must be made promptly. “We are still investigating” is not, in itself, grounds to delay indefinitely. “We do not yet know the scope” is not, in itself, grounds to delay indefinitely.
The legal standard is whether the company has determined materiality, and the company has an affirmative obligation to make that determination in a reasonable time. If the determination is reasonable, a late disclosure is fine. If the determination is delayed by design, the disclosure is a violation. The cases so far have been about the second scenario, companies that had enough information to determine materiality and chose not to act on it.
The shift from cyber as a technical problem to cyber as a financial reporting problem
This sits as the deeper shift. For most of the last 20 years, cybersecurity was owned by the IT organisation, with some board reporting and a budget that grew roughly in line with the security vendor industry’s marketing. The technical team decided what mattered, the technical team decided what to disclose, and the technical team’s decisions were largely invisible to the finance and legal functions.
The SEC rules make that posture impossible. A cyber incident that crosses the materiality threshold is now a 10-Q footnote, a 10-K item, a 8-K filing, an investor relations event, a class action lawsuit waiting room, and a board level decision. The technical team can still decide what happened. The finance team, the legal team, the disclosure committee, and the auditors now decide what to say about it. The disclosure committee structure that has existed for financial reporting for decades is now the structure that handles cyber.
This stands as the change. Cyber is no longer a thing the IT team owns and reports on. Cyber is a thing the company owns and discloses. The IT team is now a source of input to a process the company runs.
What material means in a cyber context and why it is now a legal question
Materiality is a legal standard, not a technical one. Information is material if there is a substantial likelihood that a reasonable investor would consider it important in deciding whether to buy, sell, or hold the security. In the cyber context, that has historically meant: would the incident affect the company’s revenue, expenses, assets, liabilities, or competitive position in a way a reasonable investor would care about?
The SEC has not, in any public guidance, drawn a clear line. The enforcement actions suggest the line is drawn around the kinds of things a reasonable investor would obviously care about. Customer data exposure. Operational outages that affect revenue. Ransomware payments. Material regulatory exposure. Litigation risk. Reputational damage that the company itself is treating as material in other contexts (insurance claims, board communications, internal reports).
The test is consistency. If the company is treating the incident as material internally, it is probably material for disclosure purposes too. If the company is downplaying it publicly while preparing for significant consequences internally, that counts as the fact pattern the SEC has been going after.
How boards are reorganising around cyber
The visible effect of the rules is a reorganisation of the board. Three patterns have emerged. The first is a dedicated cyber committee, modelled on the audit committee, with independent directors and a charter. The second runs as the addition of a cyber expert to the audit committee, recognising that the disclosure function becomes the main board lever on cyber. The third is a separate risk committee that includes cyber alongside financial, operational, and regulatory risk.
All three work, in the sense of satisfying the disclosure obligation. None of them stands as the right answer if the board is treating cyber as a quarterly presentation rather than a standing concern. The disclosure requirement is satisfied by structure, but the actual risk reduction requires engagement. A board that has added a cyber committee and still gets briefed once a year on phishing statistics is technically compliant and practically exposed.
The international spillover
The SEC is not the only regulator moving in this direction. The UK has required material cyber disclosure under existing listing rules for several years, with active enforcement. The EU’s NIS2 directive, fully in force across member states by 2024, requires incident reporting for critical infrastructure operators on tight timelines. Australia, Singapore, Japan, Canada, and Brazil have all updated their cyber disclosure or reporting frameworks in the last 18 months, generally in the same direction. The pattern is global: shorter timelines, more explicit board responsibility, more public visibility.
For multinational companies, the practical effect is that the most aggressive timeline wins. The SEC’s four business days is now the de facto global standard, because the consequences of a US filing are the most severe and the public visibility sits as the highest.
What mid-cap and small-cap companies are doing that public companies are not
The SEC rules apply to public companies. Private companies, even very large ones, are not directly subject. The pattern emerging in 2026 is that mid cap and small cap private companies, especially in regulated industries or with significant enterprise customers, are voluntarily adopting the same disclosure discipline. The reason is not regulatory. The reason is contractual. Major enterprise customers, especially in financial services and healthcare, are starting to require suppliers to disclose material cyber incidents on the SEC timeline, regardless of whether the supplier is public. The contractual penalty for missing the deadline is often larger than the SEC penalty would be.
The result is a quiet extension of the SEC’s effective jurisdiction, through procurement contracts, to private companies that have never filed an 8-K. The cyber disclosure discipline is becoming a market norm, not a regulatory one.
The bottom line
Cybersecurity has been, for 20 years, an IT problem the board tolerated. The SEC’s 2023 rules made it a financial reporting problem the board owns. The early enforcement actions made it clear that the SEC is willing to enforce. The international spillover has made it a global norm. The procurement pressure from enterprise customers has extended it to private companies.
The companies that have reorganised around the new reality, with cyber in the disclosure committee, in the audit committee charter, in the board calendar, in the contracts with vendors, are the companies that will handle the next incident well. The companies that have not are the companies whose next breach will be a securities filing as well as a security event. That stands as the structural change. The rest is detail.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



