Cybersecurity Disclosure
Cybersecurity disclosure refers to the information that public companies are required to report about how they handle cybersecurity risks and about significant cyber incidents affecting them. In the United States, rules adopted by the Securities and Exchange Commission (SEC) require companies to describe their approach to managing cybersecurity risk and to report material cybersecurity incidents to investors. The aim is to give investors consistent, comparable information about cybersecurity matters that could affect a company.
Cybersecurity disclosure denotes the reporting obligations established under the SEC's 2023 final rules (Release No. S7-09-22) requiring registrants to make disclosures in two principal areas. First, registrants provide periodic (typically annual, within the Form 10-K) disclosures regarding their processes for assessing, identifying, and managing material cybersecurity risks, as well as their cybersecurity strategy and governance. Second, registrants disclose material cybersecurity incidents, with the SEC rules requiring such disclosure within four business days of determining that an incident is material; under the final rule, a 'cybersecurity incident' is defined broadly to include occurrences that jeopardize information systems. The requirements apply to companies subject to SEC reporting and should be distinguished from internal cybersecurity risk-management controls themselves; disclosure is a compliance reporting obligation and does not, on its own, address the adequacy or effectiveness of the underlying controls. Scope and specific applicability may vary by registrant type, and this entry does not address implementation specifics or constitute legal advice.
Why it matters
Cybersecurity disclosure addresses a longstanding gap in the information available to investors about how public companies manage cyber risk and how they respond when significant incidents occur. Before consistent reporting requirements, disclosures about cybersecurity matters varied widely in timing, content, and depth, making it difficult for investors to compare companies or assess how a given incident might affect an investment. The SEC's 2023 final rules seek to provide more consistent and comparable information by requiring both periodic disclosures about cybersecurity risk management, strategy, and governance and timely disclosure of material cybersecurity incidents.
For compliance and governance professionals, the significance lies in the fact that this is a securities-law reporting obligation rather than a technical control requirement. The rules create a compliance-driven trigger tied to a materiality determination, requiring incident disclosure within four business days of concluding that an incident is material. This places pressure on organizations to establish clear internal processes for identifying incidents, escalating them, and making timely and defensible materiality judgments. The disclosure obligation intersects governance because it also calls for reporting on how cybersecurity risk is overseen and managed at an organizational level.
It is important to note that disclosure does not, by itself, improve the underlying security posture; it reports on it. A company can meet its disclosure obligations while still carrying significant residual cyber risk. The value to investors comes from transparency and comparability, not from any assurance that the disclosed processes are adequate or effective. Observations from surveys of early disclosures suggest wide variation in length and detail among companies, reflecting differing approaches to satisfying the requirements.
Who it's relevant to
Inside Cybersecurity Disclosure
Common questions
Answers to the questions practitioners most commonly ask about Cybersecurity Disclosure.
