SEC Cybersecurity Disclosure Rules
Regulation
United States (federal)
· 2023
SEC rules require public companies to disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining materiality, and to describe their risk management processes and board oversight annually in Form 10-K Item 1C. It is the regime that made a security incident a securities-disclosure event, and its reach extends well past registrants to every vendor whose outage could be material to one.
Horizontal regime. It binds companies by what they do with data, software or
customers, not by the sector they sit in. The industries below are where it creates
specific, additional duties — not the limit of who has to comply.
Regions
Industries
Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.