The clock nobody can start for you
Item 1.05 of Form 8-K requires disclosure of material cybersecurity incidents, covering the nature, scope and timing of the incident and its material impact or reasonably likely material impact, including on financial condition and results of operations. The filing is due within four business days of the registrant determining that the incident is material. Where information is not available at filing, the registrant says so and amends within four business days of it becoming available.
The structure is unusual. Most regulatory clocks start at an event. This one starts at a judgement, made by the company, about its own incident. That design puts the weight on the determination process rather than on the filing, and the determination process is what examiners, plaintiffs' lawyers, and boards ask about afterwards.
What the first years of filings showed
The filing pattern since the rule took effect is informative. Of the companies that filed a Form 8-K for a cybersecurity incident in the period after April 2024, a clear majority filed under Item 8.01 - the general voluntary disclosure item - rather than under Item 1.05.
That split is not evasion. It reflects a real position: a company that has not determined an incident to be material but judges that investors should know about it files under 8.01. The SEC's own guidance encourages exactly this separation, so that Item 1.05 retains its meaning as a materiality signal.
What it does mean is that the disclosure decision is now a two-stage judgement under time pressure, with a securities law consequence attached to each stage, made while an incident response is still running. That is a difficult decision to make well, and an extremely difficult one to reconstruct later if you did not record it as you went.
What the determination record should contain
- When the organisation first became aware of the incident, distinguished clearly from when it was escalated and from when the determination was made
- What was known at the point of determination, as distinct from what was learned afterwards - the determination is judged on the information available at the time
- Who participated in the determination and in what capacity, since materiality is a judgement the rule assigns to the registrant, not to the security team
- The reasoning applied, including quantitative impact estimates and the qualitative factors considered
- Why the incident was or was not determined material, with the negative determinations recorded as carefully as the positive ones
- What subsequently changed and whether it triggered an amendment obligation
Why contemporaneous matters more than thorough
A determination memo written a week later, however carefully, has a problem that no amount of care fixes: it was written with knowledge of what happened next.
If the incident turned out to be minor, the memo will unconsciously reflect that. If it turned out to be severe, so will that. Neither is dishonest, and both are visible to anyone reading the memo in the context of the outcome. The value of a determination record comes almost entirely from being made at the time, before anyone knew how it would go.
This is why the record needs a verifiable date rather than a stated one. A document asserting it was written on 14 March, in a system where dates can be set, establishes considerably less than the same document with an independently verifiable timestamp. In a securities context, where the question of what management knew and when is often the entire dispute, that difference carries real weight.
The overlap with European obligations
US-listed companies with European operations are running two incident regimes at once. The mechanics differ - NIS2's 24-hour early warning is faster and lower-threshold than Item 1.05, and DORA adds its own major-incident reporting for financial entities - but the underlying evidence requirement is nearly identical: a defensible, dated record of what was known, when, and what was decided.
Building one incident evidence process that feeds several regulatory outputs is meaningfully cheaper than running parallel ones, and it removes a specific risk: inconsistency between what you told a European supervisor within 72 hours and what you told the market a week later. The consolidation pattern is set out in building one evidence layer for dual-regulated entities, and the US-specific rule detail is in SEC cybersecurity disclosure rules: what US companies must know in 2026.
- Define the determination process and the participants before an incident, not during one
- Record awareness, escalation, and determination as three distinct timestamped events
- Document negative determinations with the same rigour as filings
- Anchor determination records so their dates do not depend on your own systems
- Reconcile US and European disclosure narratives before either is issued
If you want incident determination records whose dates are verifiable by a third party, you can anchor your first one in a few minutes, or read how the model works on the ROOTKey platform page.
Recevez nos analyses sur la cyber-résilience par e-mail
Des conseils pratiques et prêts pour l'audit sur l'intégrité des données, la conformité et la continuité - dès leur publication.





