Feature Incident Response
The SEC's Four-Day Clock: How to Make a Cyber Incident Materiality Call Under Item 1.05
The four-day filing clock under SEC Item 1.05 starts at materiality determination — not discovery. Here's how companies structure that determination, what enforcement looks like two years in, and how to avoid the two failure modes that are generating penalties.
Table of Contents
TL;DR
- The four-day clock under SEC Item 1.05 starts when you determine an incident is material — not when you discover it
- Over-filing under 1.05 for non-material incidents is a documented problem; the SEC’s May 2024 guidance redirected voluntary disclosures to Item 8.01
- Companies filing 8-Ks 6–14 business days after their documented materiality determination have faced penalties from roughly $1.0M to $2.3M per company
- The defensible process has four components: pre-defined materiality criteria, mapped decision authority, a documentation template, and a pre-drafted 8-K skeleton
When Change Healthcare Met the Four-Day Clock
On February 21, 2024, UnitedHealth Group discovered that threat actors had accessed Change Healthcare’s systems. The ALPHV/BlackCat ransomware group had compromised infrastructure that processes approximately one-third of US healthcare transactions. By April 22, two months later, UnitedHealth made its first public disclosure of the material financial impact: $872 million in Q1 2024 costs alone. The final tab for the year came in at $1.35 to $1.6 billion. The breach ultimately affected an estimated 190 million people — the largest healthcare data exposure in US history.
UnitedHealth isn’t a public enforcement action under the SEC’s cybersecurity disclosure rule. But compliance teams studying the case have asked the right question: at what point in that timeline would Item 1.05’s four-day clock have started?
That question — when does “determination” happen — is the central compliance problem that the rule created.
What the Rule Actually Says
Item 1.05 of Form 8-K became effective for most accelerated filers in December 2023. The obligation: disclose material cybersecurity incidents within four business days of determining that the incident is material.
Not four days from discovery. Four days from determination.
The word choice is deliberate. The SEC recognized that incident investigations take time and that forcing disclosure before a company understands what happened would produce inaccurate filings. So the clock starts at a specific documented moment — a company’s affirmative conclusion that an incident meets the materiality threshold.
Two additional obligations flow from this:
- Annual 10-K disclosure: Publicly traded companies must disclose cybersecurity risk management processes, governance structures, and board oversight in annual reports
- Amendment obligation: If material new facts emerge after an initial 1.05 filing, the company must amend — the initial disclosure doesn’t close the obligation
The Materiality Test in Practice
The SEC applies a dual test: qualitative and quantitative. Would a reasonable investor consider this incident important in making an investment decision?
Four factors anchor the analysis:
| Factor | What You’re Evaluating |
|---|---|
| Financial impact | Remediation costs, lost revenue, ransom payments, regulatory fines, litigation exposure |
| Operational disruption | Which systems went down, for how long, which business processes were affected |
| Data scope | Volume and type of records exposed — PII, financial data, trade secrets |
| Reputational risk | Likelihood of customer attrition, counterparty concern, or media coverage |
No single factor is automatically determinative. A breach affecting 50,000 customer records might be immaterial to a company with 50 million accounts. The key considerations for Form 8-K materiality determinations go beyond financial impact alone — operational significance and data sensitivity often drive the conclusion in practice.
Critical constraint: the determination must be documented. An undocumented materiality conclusion is procedurally indistinguishable from no conclusion at all.
The Over-Reporting Problem the SEC Had to Fix
Between December 2023 and early 2025, 54 public companies filed 80 Form 8-K disclosures related to cybersecurity incidents. The breakdown matters: a significant portion were voluntary disclosures, not required ones — companies were filing under 1.05 for incidents that either hadn’t been determined material or that the company was still investigating.
The SEC’s Division of Corporation Finance addressed this directly in May 2024 guidance. Item 1.05, the guidance clarified, is exclusively for incidents a company has affirmatively determined to be material. For voluntary, non-material disclosures — where a company chooses to inform investors about a contained incident — Item 8.01 exists precisely for that purpose.
After the guidance, companies shifted: voluntary disclosures increasingly moved to 8.01, while 1.05 filings tracked closer to actual material incident conclusions.
How the Four-Day Clock Runs
A defensible materiality determination process runs in sequence:
Step 1 — Detection and logging. CISO logs the incident, initiates investigation, begins severity classification. The clock is not running.
Step 2 — Technical investigation. Team assesses scope, containment status, affected data. This is the legitimate pre-determination window. Document progress at each step.
Step 3 — Preliminary briefing. CISO presents known facts to legal counsel and CFO: what happened, what’s confirmed, what’s still unknown, estimated financial and operational impact. This brief should itself be documented.
Step 4 — Materiality evaluation. Legal counsel, CFO, and relevant executives assess findings against the four factors. Board or audit committee involvement depends on governance structure and bylaws.
Step 5 — Documented conclusion. Three possible outcomes: Material (four-day clock starts), Not material (file under 8.01 if voluntary disclosure is warranted, or don’t file), or Ongoing assessment pending additional facts (legitimate — but document why, and set a deadline for resolution).
Step 6 — Disclosure drafting. If material: four-day clock is running. The SEC has confirmed that preliminary disclosures acknowledging ongoing investigations are acceptable — the 8-K doesn’t need to be complete. But it does need to be filed.
The “ongoing assessment” conclusion is legitimate in early stages of a complex incident. It cannot become a mechanism for avoiding a determination indefinitely. The SEC will ask: what new information did you receive, and when, that changed your assessment?
The National Security Exception
Form 8-K Item 1.05(c) includes a narrow delay provision. Where disclosure would pose a substantial risk to national security or public safety, the company can delay filing if the Department of Justice certifies the delay to the SEC. DOJ issued guidelines on how to request this exception in January 2024.
AT&T invoked this exception twice in 2024. It’s a real mechanism — but one calibrated for incidents involving active law enforcement investigations or genuine national security concerns. It isn’t a general extension for incidents where the company is uncertain about scope or waiting for legal review of disclosure language.
What Enforcement Looks Like Now
The SolarWinds case — the SEC’s most ambitious use of cybersecurity disclosure theory — ended in November 2025 when the SEC voluntarily dismissed all remaining claims against SolarWinds and CISO Timothy Brown, with prejudice. The federal judge had thrown out most charges in July 2024.
The SolarWinds dismissal does not mean the rule has no enforcement backbone. The SEC has brought charges against multiple companies that filed Item 1.05 forms 6 to 14 business days after their documented materiality determination date. Penalties have ranged from approximately $1.0 million to $2.3 million per company, plus disgorgement of certain trading gains.
That pattern reveals the SEC’s current enforcement theory: not complex governance failures (which SolarWinds demonstrated are hard to litigate), but a specific, measurable gap between a documented determination date and an actual filing date. If your board minutes or incident log shows a materiality conclusion on Day 1 and your 8-K went in on Day 9, the math is straightforward.
The Two Failure Modes
Over-reporting under 1.05: Filing mandatory-channel disclosures for incidents that haven’t been affirmatively determined material. This creates an inflated record, signals unclear internal processes, and conflates investigative filings with concluded materiality determinations. The fix: use 8.01 for voluntary, non-material disclosures.
Late filing after documented determination: This is the more dangerous error. Once there’s a documented conclusion that an incident is material, the clock is running. Waiting for additional investigation results, full board sign-off, or polished disclosure language doesn’t pause it. Four business days from the determination date — that’s the limit.
Building the Process Before the Next Incident
An incident response notification clock framework only works if the materiality determination step is already built in. The components worth pre-establishing:
Materiality criteria in writing. Define, in advance, what financial impact levels, operational disruption thresholds, or data exposure scopes would trigger a material conclusion. This isn’t binding — novel incidents will always require judgment — but pre-defined criteria make the process faster and the documentation more credible.
Decision authority mapped. Who makes the call? CISO + CFO + General Counsel is a defensible structure. Board or audit committee notification should be built into the escalation path, with timeframes defined.
Documentation templates ready. A structured memo capturing incident facts, each factor evaluated, the conclusion, and the date. This document is your central evidence in any enforcement review. It should be part of your incident response post-event record before you need it.
Disclosure drafts ready. Prepare a skeleton Item 1.05 disclosure in advance — incident type, company description, investigation status language. When the four-day clock starts, formatting the filing from scratch costs time you don’t have.
Private Companies Aren’t Off the Hook
Public companies have Item 1.05. Private companies and fintechs face a different notification architecture: state breach notification laws (all 50 states have them, with deadlines from 30 to 90 days), the federal banking regulator 36-hour computer security incident notification requirement (OCC, FDIC, Federal Reserve), and potentially GLBA Safeguards Rule obligations.
The materiality concept doesn’t map directly to most state statutes, which trigger on affected records thresholds rather than investor relevance. But the underlying discipline — documented incident facts, structured decision process, clock management — applies equally. The NYDFS Healthplex enforcement action resulted in a $2 million consent order for a 72-hour notification window missed by four months. The documentation problem was the same one that generates Item 1.05 late-filing penalties: no defined process for identifying when the notification clock starts.
So What?
The four-day clock is less complicated than it looks if you have a process. The danger is approaching a real incident with no pre-established materiality criteria, no documented determination workflow, and a disclosure template that hasn’t been drafted yet.
The NYU Compliance and Enforcement review of the first year of Item 1.05 found that the regulation’s main compliance challenge wasn’t the four-day window itself — it was the lack of established process for getting from discovery to determination in a disciplined, documented way. That gap is still the gap most incident response plans have.
Build the materiality determination process into your incident response playbook now. Define the criteria. Map the decision authority. Prepare the documentation template and the disclosure draft. The clock doesn’t wait for your legal team to finish their review.
The Incident Response & Breach Notification Kit includes incident response playbooks, breach notification templates for all 50 states, an incident classification and severity matrix, and a post-incident review framework — including the documentation structure for managing notification clocks across federal and state regulatory requirements.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
When exactly does the four-day clock start under SEC Item 1.05?
What's the difference between Item 1.05 and Item 8.01 disclosure?
What does 'material' mean in the cybersecurity context?
Can the attorney general extend our filing deadline for a national security reason?
What has SEC enforcement actually looked like for late Item 1.05 filings?
Should our CISO or legal counsel make the materiality determination?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
After the Incident: Turn Lessons Learned Into Control Changes That Stay Closed
Strengthen an incident response plan by converting lessons learned into owned control changes, effectiveness tests, and defensible closure evidence.
Jul 25, 2026
Incident Response
Incident Response Decision Log: Document Why a Notification Clock Did—or Did Not—Start
When a cyber event hits, every regulator wants the same thing: proof you made a good-faith materiality determination without unreasonable delay. Here's the decision log structure that creates that proof—whether the clock started or not.
Jul 24, 2026
Incident Response
Four Months Late: What the NYDFS Healthplex $2M Penalty Says About When the Notification Clock Actually Starts
NYDFS fined Healthplex $2 million in August 2025 for notifying 4+ months after a breach. The failure wasn't forensics — it was a misunderstanding of when the 72-hour clock starts. The same mistake trips up banks under the FDIC's 36-hour rule.
Jul 23, 2026