Public companies filed more than 240 material cybersecurity incidents on Form 8-K in the twelve months following the SEC's July 2023 adoption of Item 1.05 disclosure rules, creating the first quantified dataset of breach-to-disclosure timing across listed equities. The median time between incident discovery and Form 8-K filing landed at fourteen days, though 22% of filers reported within the SEC's four-business-day window. The disclosure variance matters: firms trading above $5 billion market capitalization filed an average nine days faster than sub-$1 billion names, suggesting board-level cyber governance correlates with reporting velocity.
The filings concentrated in three sectors. Technology and software companies accounted for 38% of Item 1.05 submissions, followed by healthcare at 29% and financial services at 18%. Healthcare's overrepresentation aligns with private-sector loan defaults now running at record highs in that vertical, per separate midmarket lender data, though no public filing explicitly linked cyber events to credit facility breaches. Of the 240+ incidents disclosed, 61 triggered subsequent restatement or material weakness disclosures within 90 days, indicating initial materiality assessments undercounted operational and financial fallout. The SEC has not yet published enforcement actions under the new rule, but the restatement rate suggests the Commission's Division of Enforcement is cataloging repeat filers and late reporters.
The disclosure gap creates a valuation problem for allocators running concentrated books in software and cloud infrastructure names. A fourteen-day median lag means earnings calls and quarterly filings often precede formal breach disclosure, leaving analysts to reverse-engineer incident timing from vague management commentary or forensic billing anomalies. Firms with $10+ billion in market cap tend to pre-announce via press release before the Form 8-K, compressing the information asymmetry window to three days on average. Names below $2 billion rarely pre-announce, and 41% of their Item 1.05 filings landed outside the four-day threshold. The timing variance is widest in dual-listed foreign issuers, where 19 of 27 filers reported beyond twenty days, suggesting coordination friction between non-U.S. regulators and SEC counsel.
Allocators should track three follow-on datasets in the next six months. First, the SEC's Division of Corporation Finance is expected to publish interpretive guidance on "material" versus "potentially material" cyber events by Q3 2025, which will tighten or loosen the 240+ filing baseline. Second, cyber insurance carriers are now requiring policyholders to file Item 1.05 within seventy-two hours of incident confirmation as a condition of coverage above $50 million limits, per recent policy-language shifts at three top-five carriers. That contractual pressure will compress disclosure windows for well-capitalized names but may push undercapitalized issuers to self-insure and delay filings. Third, the first wave of SEC enforcement actions under Item 1.05 is likely in Q4 2025, targeting late filers or firms whose restatements contradicted initial "immaterial" designations. The enforcement pipeline will clarify whether the Commission treats disclosure timing as a reporting violation or a materiality judgment error.
Software names trading above 25x forward earnings now carry an implicit disclosure-lag premium that neither sell-side models nor credit default swaps properly price.