Insights · Governance

Cyber materiality:
deciding before the clock starts.

Article

Governance · 7 min read

Public companies have four business days to disclose a material cybersecurity incident. Most coverage of that rule focuses on the four days. The harder part is the word before it. Deciding whether an incident is material is a financial judgment a company has to make while the incident is still unfolding, and the filing record since the rule took effect suggests it is the part boards are least prepared for. Here is what the rule actually requires, and why the work that makes it survivable happens long before anything goes wrong.

What the rule requires

Two obligations matter. The first is Item 1.05 of Form 8-K: when a public company determines that a cybersecurity incident is material, it files a current report describing the nature, scope, and timing of the incident and its material impact or reasonably likely material impact. That filing is due within four business days of the determination. The second is Item 106 of Regulation S-K, an annual obligation to describe how the company assesses, identifies, and manages cyber risk, and how the board oversees it. Both took effect in December 2023.

Read those together and the design becomes clear. The annual disclosure asks whether a company has a process. The incident disclosure tests whether that process works under pressure.

The detail that trips people up

The four-day clock does not start when an incident is discovered. It starts when the company determines the incident is material. That sounds like breathing room, and it is not. The determination itself has to be made without unreasonable delay, so a company cannot simply decline to reach a conclusion while the days pass. What the structure really does is move the pressure onto the judgment rather than the paperwork. Four days to draft a filing is manageable. Deciding, mid-incident, with partial forensics, whether a reasonable investor would consider this important is not.

The filing record shows where the difficulty sits

There is now a public evidence base for how companies handle this. Since the SEC staff clarified in May 2024 that Item 1.05 is meant for incidents actually determined to be material, roughly twice as many issuers have disclosed cyber incidents voluntarily under Item 8.01, the general disclosure item, as have filed under Item 1.05. Incidents first disclosed under Item 8.01 have generally not been followed later by an Item 1.05 filing.

That pattern is worth sitting with. Companies are choosing to tell the market something happened while declining to label it material. Some of that is sound lawyering. But it also describes a set of organizations that would rather disclose than decide, because they do not have a defensible basis for the decision. A company confident in its materiality threshold does not need the ambiguity.

Materiality is a financial threshold, not a severity rating

The instinct inside most security organizations is to reach for technical severity. A critical vulnerability score, a high-severity alert, a compromised domain controller. None of those are materiality. Materiality is the long-standing securities concept of whether there is a substantial likelihood that a reasonable investor would consider the information important. It is measured in consequences to the business, not in the sophistication of the attack.

A ransomware event that encrypts a non-critical system and is restored from backup in a day may be technically severe and immaterial. A quiet, unglamorous exposure of a customer database may be the reverse. The only way to tell them apart quickly is to have already expressed the company's risk in the same units the judgment is made in, which is dollars, and to have agreed in advance roughly where the line sits.

Set the threshold before you need it

The practical response is not a faster incident response plan. It is a materiality threshold established while nothing is happening, and documented well enough that it holds up later. In practice that means four things.

  • A quantified starting point. Exposure modeled by loss category, so the company knows what a breach, an outage, or an extortion event is actually worth to it before one occurs.
  • A dollar band the board has agreed. Not a single number pretending to be precise, but a range with a clear basis, reviewed alongside the other thresholds the board already sets.
  • The qualitative factors, written down. Regulatory exposure, customer concentration, contractual commitments, and reputational consequence do not reduce cleanly to a figure, and the method should say how they get weighed rather than leaving it to the room.
  • A named decision owner and a record. Who makes the call, who is consulted, and where the reasoning is captured. The defensibility of a materiality determination rests almost entirely on being able to show the reasoning afterward.

None of this is exotic. It is the same discipline a board applies to any other threshold it governs against. Cyber has simply been the risk where the threshold was never set.

The rules may change. The question will not.

These requirements are under active pressure. In April 2026 five banking and securities trade associations asked the SEC to rescind both Item 106 and Item 1.05, arguing that the four-day timeline forces premature disclosure while incidents are still being contained. The rules remain in effect, and nobody should plan around a repeal that has not happened.

The more useful point is that the underlying question survives any rulemaking. If a company suffers a serious cyber incident, its board will be asked how it decided what the incident was worth and whether that decision was reasonable. That question comes from regulators, and it also comes from acquirers, insurers, litigants, and institutional investors. A company that can answer it has something durable. A company relying on the rule being withdrawn has an exposure it has not priced.

Where this connects to the rest of the program

A materiality threshold is only as good as the numbers underneath it. That is why this work sits on top of cyber risk quantification rather than beside it: once exposure is expressed in dollars by loss category, the threshold conversation becomes a governance decision instead of a guess. It also belongs in the board's standing reporting rather than in a binder, which is the subject of reporting cyber risk to the board.

Core3 quantifies exposure on Know, runs the program against it on Own, and builds the reporting and board readiness that makes a determination defensible on Prove.

Could you defend
the determination?

Core3 builds the quantified basis and the documented method behind a materiality threshold, before the question is urgent. No pitch on the first call.