Cybersecurity Incidents: What is Item 1.05 on Form 8-K?
On this page:
What Is Item 1.05?
Item 1.05, "Material Cybersecurity Incidents," is the section of Form 8-K a company checks once it has determined that a cybersecurity incident is material. It requires a description of the material aspects of the incident's nature, scope, and timing, plus the material impact — or reasonably likely material impact — on the company's financial condition and results of operations.
The item was added by the SEC's Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure rule, adopted July 26, 2023. Larger registrants had to begin complying by December 18, 2023; smaller reporting companies got an additional 180 days, until June 15, 2024.
Who Needs to Disclose Cybersecurity Incidents?
Any domestic company with a reporting obligation under Section 12 or Section 15(d) of the Exchange Act must furnish an Item 1.05 8-K once it determines a cybersecurity incident is material. That covers operating companies across every SIC code, REITs, and other Exchange Act reporting companies regardless of size. Foreign private issuers instead furnish comparable disclosure on Form 6-K when they choose to, or are otherwise required to, make it public.
What's Included in a Cybersecurity Incident Disclosure?
Item 1.05 filings are short — often one or two pages — but dense with comparable fields:
- Nature of the incident: what happened — unauthorized access, ransomware, data exfiltration, a third-party or vendor compromise
- Scope: what systems or data were involved — proprietary data, personal information, protected health information, financial systems
- Timing: three distinct dates worth tracking separately — when the incident was identified, when materiality was determined, and when the 8-K was filed
- Impact assessment: a direct statement on whether the incident is reasonably likely to have a material impact on financial condition or results of operations
- Response actions: containment steps taken and forensic investigators engaged, described at a business level rather than in technical detail
- Amendment clause: filings routinely note that information not yet available will be added by a later Form 8-K/A, so a single incident can generate a small cluster of related filings over weeks or months rather than just one
Materiality tracks what was actually exposed, not just that a compromise occurred. An incident limited to internal employee email accounts rarely clears the bar on its own; one exposing customer data, payment information, protected health information, or trade secrets and IP is far more likely to. Amgen's July 2026 filing is a good example: it cleared the bar because the exposed files included patient protected health information and proprietary data, not simply because unauthorized cloud access had occurred.
What's the Difference Between Item 1.05 and Item 8.01?
Item 1.05 is mandatory once materiality is determined. Item 8.01, "Other Events," is a catch-all a company can use to voluntarily disclose an incident it has assessed as not (yet) material — no four-day clock, no mandatory trigger. Upbound Group's 2026 8-K shows this directly: it disclosed cybersecurity incidents under Item 8.01, stating the incidents were "not material" based on current facts, while committing to reassess under Item 1.05 if that changed. Companies sometimes prefer this route when they want to get ahead of a story — an incident is already public or rumored — before a formal materiality assessment is complete.
Screening for Item 1.05 alone will also miss the reverse case: an initial disclosure that gets revised as facts develop. River Financial Corp's original Item 1.05 8-K, filed June 25, 2026, was followed by three separate Form 8-K/A amendments over the following five weeks — the amendment clause described above, playing out in a real filing history rather than a single document.
Incident updates can also surface under Item 7.01 (Regulation FD Disclosure), separate from both 1.05 and 8.01. Stryker Corporation's March 2026 incident shows the full sequence: the company first disclosed a cybersecurity incident under Item 8.01 on March 11, stating it had "not yet determined whether the incident is reasonably likely to have a material impact"; a Reg FD update on the operational disruption followed the next day under Item 7.01. No Item 1.05 filing followed either one. Item-filtered queries alone won't surface a sequence like this — full-text search across all filing types catches it.
When Does the Four-Business-Day Disclosure Clock Start?
Most 8-K items are triggered by an event that's unambiguous the moment it happens — an earnings release, a merger. Item 1.05 is different by design: a cybersecurity incident is often discovered long before its scope or impact is understood. A four-business-day clock starts when the company determines the incident is material, a separately timestamped step the company must complete "without unreasonable delay" after discovery. A single incident can therefore show a discovery date, a materiality-determination date, and a filing date that are days or weeks apart.
A narrow exception exists: if the U.S. Attorney General determines disclosure would pose a substantial risk to national security or public safety, the SEC can permit a delay. This is used rarely.
Item 1.05 is also easy to confuse with Item 1C, "Cybersecurity" — the Part I section the same 2023 rule added to Form 10-K, requiring the disclosures specified in Regulation S-K Item 106. Item 1C is annual: a company's cybersecurity risk-management program, strategy, and board oversight. Item 1.05 is one-time: a specific material incident.
Resources
-
SEC: Form 8-K — general instructions, including Item 1.05
-
sec-api.io: Data Browser — every Item 1.05 8-K, live — the query behind the examples above, ready to run
-
sec-api.io: Data Browser — full-text search for "cybersecurity incident" — catches disclosures under any item
-
sec-api.io: Query API — filter 8-Ks by items:"1.05" to pull every material cybersecurity incident on file
-
sec-api.io: Full-Text Search API — search incident language (a vendor name, "ransomware”) across all 8-Ks
-
sec-api.io: Stream API — get pushed a new Item 1.05 filing within ~300ms of it hitting EDGAR
-
sec-api.io: Form 8-K Files dataset — bulk download of every 8-K filed with the SEC since inception