The SEC's Cyber Disclosure Rule Has Entered Its Enforcement Era
The SEC's cybersecurity disclosure rules, adopted in 2023, require public companies to report material cybersecurity incidents on Form 8-K within four business days of determining materiality, plus annual disclosure of cyber risk management and governance under Regulation S-K Item 106. Between December 2023 and early 2025, 54 companies filed 80 cyber-related 8-K disclosures under the rule. 2026 marks a shift from a bedding-in period to an active enforcement year, with a dedicated enforcement unit and closer investor scrutiny of how - and how fast - companies disclose.
A rule under political pressure, but still live
The rule's long-term future is genuinely uncertain: a Republican-appointed Commission majority and SEC Chair Paul Atkins have signalled interest in revisiting it. But uncertainty about future rulemaking doesn't change what's enforceable today - the current rule remains in force, and 2026 enforcement activity reflects that reality regardless of where policy debate lands next.
What this means for publicly listed fintech and insurance firms
- Know who makes the materiality call in your organisation, and how fast they can convene once an incident is confirmed - the four-business-day clock starts at the materiality determination, not at initial detection, but regulators and plaintiffs' lawyers alike will scrutinise how long that determination took.
- Annual Item 106 disclosures about governance and risk management are now a standing obligation, not a one-time exercise - treat them as living documentation that needs to reflect your actual current program.
- Board-level cyber governance is now effectively a disclosure topic. If your board can't describe its own oversight process in plain terms, that's a gap worth closing before it becomes an 8-K problem.
Have a security question of your own?
Talk to a Security Expert →