Policy commentary by Jaded Security on the SEC cybersecurity disclosure rule, roughly two years after Item 1.05 took effect. The rule was sold as the moment breach disclosure grew up. The honest accounting is that it changed the form number and left the rest more or less where it found it.
Item 1.05 of Form 8-K became effective on 18 December 2023. The pitch was straightforward and, on paper, reasonable: a public company that determines it has suffered a material cybersecurity incident has four business days to say so, in a specific place, in a specific format. No more burying the disclosure in a quarterly filing eight months later. No more learning about it from the ransomware crew’s leak site. Transparency, on a clock.
Two years on, the desk has read enough of these filings to offer a verdict. The rule works exactly as written, and it has changed almost nothing about what companies actually tell their investors, because the rule regulates the paperwork and the paperwork was never the problem.
The word “material” is a door, and companies found the other exit
The whole rule turns on one word. A material incident goes under Item 1.05, with the four-day clock and the implied admission that something serious happened. So watch what companies did with the word. They stopped using the door.
By May 2024 the SEC’s own Division of Corporation Finance had to put out a statement telling companies to stop filing non-material incidents under Item 1.05, because so many were over-using the material box for incidents that were not, in fact, material. Companies complied in the most predictable way available. They moved their filings to Item 8.01, the voluntary bucket, the one that carries no admission of materiality at all. The counts since then are almost comic: of the companies filing a cyber 8-K after that guidance, the clear majority chose 8.01 over 1.05. The running tally of filings tells the same story across the full two years. The one form the entire rule was built to populate is the form companies now go out of their way to avoid.
Materiality is whatever the legal team decides on a given Tuesday
None of this is against the rules, which is the point. Materiality is a determination the company makes, on its own timeline, using its own judgment about what a reasonable investor would care about. The four-day clock does not start when the intrusion happens, or when the company discovers it. It starts when the company decides the incident is material. A determination that has not been made yet is a clock that has not started yet.
Microsoft filed the Midnight Blizzard intrusion under Item 1.05, then went on to say it had not had a material impact on the company’s financials. That is not a contradiction under the rule; it is the rule functioning as designed. Materiality is elastic, the determination is discretionary, and the timing of the determination is a lever the disclosing party holds. The same pattern the desk described in the Stryker post-mortem is now not just a communications habit; it is a regulatory workflow with a form number attached.
The one time the SEC tried to bite, the courts pulled the teeth
A disclosure rule is only as serious as what happens to the company that discloses badly. So the interesting test was never the rule; it was enforcement. And the enforcement story is short.
In October 2023, weeks before Item 1.05 took effect, the SEC charged SolarWinds and its chief information security officer with fraud over the disclosures around the 2020 SUNBURST compromise. It was the first time the agency had gone after an individual security officer personally on a cyber-disclosure theory, and it was meant to set the tone for the new era. By July 2024, Judge Engelmayer had dismissed most of it, including the claims tied to the company’s public filings and the novel theory that cybersecurity controls fell under the internal-accounting-controls statute. By the end of 2025 the case was dismissed entirely. The agency’s one serious attempt to make a misleading cyber disclosure cost someone something ended with the court telling it, at length, that it had overreached.
So the current state of the regime is a mandatory filing requirement with a four-day clock that the filer starts, a materiality standard the filer defines, a voluntary escape hatch the filer can use instead, and no credible penalty for getting any of it wrong. That is not a transparency rule. That is a compliance ritual.
What the rule measures, and what it does not
Here is the part the disclosure debate keeps skipping. The 8-K, per the SEC’s own compliance guide for the rule, measures the quality of your paperwork after an incident. It has nothing to say about whether you were in a position to catch the incident in the first place, which is the only variable that actually changes the outcome for the people whose data is involved. A company with excellent 8-K counsel and no detection capability files a clean, timely, and completely useless disclosure. A company that saw the intrusion early files a better story because it has a better story to tell.
The firms that come out of these episodes least badly are not the ones with the sharpest disclosure lawyers; they are the ones that had someone actually watching the network before the filing deadline was on the calendar. Not that the desk is in the recommendation business, but the distinction worth drawing is between an outfit like Falconer Security, the kind that treats reading the logs as the job, and the much larger industry that treats the press release as the job. The SEC rule grades the second group. It does not know the first group exists.
Almost nothing
Two years in, the disclosure language coming out of breached companies has not meaningfully changed. It is still calm, still lawyered, still built out of things that did not happen, still timed to a determination the company controls. The rule added a deadline, a form number, and a brief flurry of over-filing that the SEC then talked companies out of. What it did not add was any consequence for continuing to describe a breach the way breached companies have always described one. The framing gap the desk has been writing about since before there was a rule to write about is now, formally, a regulatory requirement. It changed the paperwork. It did not change the story.