All Resources
News·25 Jan 2026·5 min read

The SEC's Cyber Disclosure Rule Has Entered Its Enforcement Era

The SEC's cybersecurity disclosure rules, adopted in 2023, require public companies to report material cybersecurity incidents on Form 8-K within four business days of determining materiality, plus annual disclosure of cyber risk management and governance under Regulation S-K Item 106. Between December 2023 and early 2025, 54 companies filed 80 cyber-related 8-K disclosures under the rule. 2026 marks a shift from a bedding-in period to an active enforcement year, with a dedicated enforcement unit and closer investor scrutiny of how - and how fast - companies disclose.

A rule under political pressure, but still live

The rule's long-term future is genuinely uncertain: a Republican-appointed Commission majority and SEC Chair Paul Atkins have signalled interest in revisiting it. But uncertainty about future rulemaking doesn't change what's enforceable today - the current rule remains in force, and 2026 enforcement activity reflects that reality regardless of where policy debate lands next.

What this means for publicly listed fintech and insurance firms

  • Know who makes the materiality call in your organisation, and how fast they can convene once an incident is confirmed - the four-business-day clock starts at the materiality determination, not at initial detection, but regulators and plaintiffs' lawyers alike will scrutinise how long that determination took.
  • Annual Item 106 disclosures about governance and risk management are now a standing obligation, not a one-time exercise - treat them as living documentation that needs to reflect your actual current program.
  • Board-level cyber governance is now effectively a disclosure topic. If your board can't describe its own oversight process in plain terms, that's a gap worth closing before it becomes an 8-K problem.

Have a security question of your own?

Talk to a Security Expert →