Cybersecurity incident: Item 1.05
Four business days from the determination — not from discovery. Which means the deadline is set by a date you choose, and choosing it late is its own problem.
They do different jobs
Discovery starts the obligation to determine without unreasonable delay. Determination starts the four business days. Today is taken as 2026-09-13, Eastern.
What counts as the incident, and who can pause the clock
Every route by which this becomes material
Item 1.05(a) asks for material impact or reasonably likely material impact. “Not sure” is carried through as unanswered rather than rounded down to no.
This does not decide materiality and will never tell you an incident is immaterial. It computes the deadline, surfaces the aggregation question, and reports the gap that gets read afterwards.
A deadline you set yourself is one you can miss twice
Almost every summary of Item 1.05 leads with “four business days,” and almost every one of them leaves the reader with the wrong mental model. The four days do not run from the breach. They do not run from discovery. They run from the moment the registrant determines that the incident is material — a date the registrant itself fixes. Read quickly that sounds like control. It is the opposite of control: a deadline anchored to an external event can only be missed by being slow, while a deadline anchored to your own decision can be missed twice over, once by filing late against the date you chose and once by choosing the date late.
The second failure is the one without a number. Instruction 1 to the item requires the materiality determination to be made without unreasonable delay after discovery, and “unreasonable” is argued afterwards by people who already know how the story ended. Both halves of the arithmetic end up in the same place: the 8-K states when you determined, EDGAR stamps when you filed, and the incident response timeline, the insurer notification and the internal email traffic all exist and are all discoverable. Nobody has to reconstruct the gap.
Then there is the definition, which does more work than its placement suggests. A cybersecurity incident is an unauthorised occurrence or a series of related unauthorised occurrences. That phrase converts a pattern of individually unremarkable events into a single thing that must be assessed as a single thing, and it produces a failure mode that looks exactly like diligence — every intrusion triaged, every one found immaterial, every one closed, a file full of careful decisions and not one of them the decision the rule asked for.
Finally, the two delays. Neither is elective. The national security delay belongs to the Attorney General and requires written notification to the Commission; the telecommunications delay is capped at seven business days and evaporates unless correspondence reaches EDGAR by the original due date. A company that believes it is inside an extension it never obtained is in a worse position than one that simply filed late, because the record will show it knew the date.
What this tool does not do
The deadline arithmetic is reliable: it runs on the same federal holiday and weekend calendar as the rest of this product, and it counts from the determination date you give it, which is what General Instruction B.1 says to count from. Everything else here is structure rather than conclusion. It does not decide materiality, it does not tell you an incident is immaterial, and it deliberately does not score the discovery-to-determination gap - the rule says 'without unreasonable delay' and sets no number, so any threshold this tool displayed would be one it made up.
- Whether your incident is material - that is a judgment on the total mix of information available to a reasonable investor, and this tool has seen none of it
- Whether your discovery-to-determination gap was reasonable; it reports the number and names who will read it
- Whether occurrences are in fact related, which is a forensic question for your incident response provider
- Drafting the disclosure, or deciding how much of the nature, scope and timing to describe
- The Item 106 annual disclosures in your 10-K on risk management, strategy and governance - a different obligation on a different timetable
- State breach notification laws, GDPR, HIPAA, and every sector regulator's own notification clock, all of which run independently of this one
- Whether to make a voluntary Item 8.01 disclosure about an incident you concluded was not material
- Insurance notification, law enforcement engagement, and the Regulation FD consequences of telling anyone selectively
Frequently asked questions
Does the four business days run from discovery or from the determination?
From the determination. General Instruction B.1 to Form 8-K says a report under Item 1.05 is to be filed within four business days after the registrant determines that it has experienced a material cybersecurity incident. That is not relief — it means the deadline is set by a date you choose, and Instruction 1 separately requires that determination to be made without unreasonable delay after discovery. There are two exposures, and only one of them has a number.
How long is 'without unreasonable delay'?
The rule does not say, and this tool will not invent a threshold. What it does instead is report the gap between your discovery date and your determination date, and tell you who reads that number: it appears in the 8-K itself, and it gets compared against the forensic timeline, the insurer notification and the first internal email that used the word material. If the gap was long, the contemporaneous record of why is the defence — and it has to have been written at the time.
We had several small intrusions, each immaterial. Do we file?
Possibly, and this is the most commonly missed part of the rule. Item 106(a) of Regulation S-K defines a cybersecurity incident as an unauthorized occurrence or a series of related unauthorized occurrences. If they are related, they are one incident, and the materiality assessment is on the series. Six careful decisions that each occurrence was immaterial are not the decision the rule asked for — and the determination date for the series is not the date you cleared the last one.
Law enforcement asked us to delay. Can we?
Not on that basis. The delay in Item 1.05(c) requires the United States Attorney General to determine that disclosure poses a substantial risk to national security or public safety and to notify the Commission in writing. An agent's request, an open investigation, or a prosecutor's preference are none of those things. Unless you know the Commission has been notified, the deadline is running.
We do not know the full impact yet. Should we wait?
No. Instruction 2 contemplates exactly this: state in the filing that the information is not determined or unavailable, file on the date, and amend within four business days of determining it or of it becoming available. Holding the filing for a complete picture is what converts a permitted incomplete filing into a late one.
Do we have to disclose technical detail about the attack?
No. Instruction 4 says a registrant need not disclose specific or technical information about its planned response, its systems, networks and devices, or potential vulnerabilities in such detail as would impede response or remediation. That carve-out is real but narrower than it is usually read: it protects operational detail, not the material aspects of nature, scope, timing and impact — which is what the item actually asks for.