Between December 2023 and November 2024, 106 public companies filed Item 1.05 Form 8-Ks disclosing material cybersecurity incidents under the SEC's new mandatory disclosure rules. The median time between incident discovery and public filing was 4.4 business days, precisely at the regulatory deadline. Fifty-three filers disclosed ransomware. Thirty-two disclosed data exfiltration with no ransom demand. The rest split between denial-of-service attacks and third-party vendor compromise.
The SEC adopted final cybersecurity incident disclosure rules in July 2023, effective December 18, 2023. The rule requires 8-K filing within four business days of determining an incident is material, with a narrow exception for delays requested by the Attorney General on national security grounds. No company in the first-year dataset invoked that exception. Filings cluster in three sectors: healthcare (28 incidents), financial services (24), and technology (19). Median market cap at filing was $1.7 billion. Eight filers were in the S&P 500. The SEC has not yet brought an enforcement action for late filing, but three companies amended initial 8-Ks within ten days to expand incident scope after forensic reviews deepened.
The disclosure requirement changes allocation math in two directions. First, it converts cybersecurity from an abstract operational risk into a timestamped, board-attributable event with defined legal consequences. Boards that fail to establish incident detection and materiality assessment processes now carry personal liability under Caremark doctrine, and plaintiffs' firms are already testing derivative suits in Delaware. Second, it creates a tradable volatility event with 72 to 96 hours of advance notice for prepared desks. Stocks of 8-K filers declined an average of 4.1 percent in the five trading days post-disclosure, with a 9.2 percent average drawdown for incidents involving customer financial data. The variance is wide — some filers saw no reaction, three saw double-digit single-day drops — but the pattern is now observable and the dataset is growing monthly.
Allocators should track three follow-on developments. First, the SEC's Division of Corporation Finance is conducting a quiet review of companies that disclosed incidents in earnings calls or press releases before filing 8-Ks, which suggests selective enforcement may begin in Q2 2025. Second, cyber insurers are repricing D&O and breach policies based on this dataset, with premium increases of 18 to 35 percent for sectors in the top tercile of filing frequency. Third, proxy advisors are beginning to flag repeat filers — four companies filed twice in twelve months — as governance concerns in Say-on-Pay votes. The second-order effect is that boards are now hiring fractional CISOs and independent cybersecurity committee members, creating a small but measurable M&A premium for firms that sell board-level risk advisory services.
The compliance deadline for annual cybersecurity risk management disclosure in 10-Ks arrives in March 2025 for calendar-year filers. That disclosure requires narrative description of board oversight and management processes, which will provide the first public benchmark for comparing incident response maturity across sectors.