Dispatches · Regulation
SEC cyber disclosure rules: how to rehearse the materiality decision in a tabletop exercise
US public companies must disclose a material cybersecurity incident on Form 8-K Item 1.05, generally within four business days of determining that it is material. The clock starts at the determination, not at the incident, so the determination process is what to rehearse. Build one tabletop around that decision and record who made it, when, and on what information.
Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026
By Security Training assessors · 10 June 2026
3-1What do the SEC rules require?
The SEC adopted its cybersecurity disclosure rules on 26 July 2023. They add two obligations for US public companies.
- Form 8-K Item 1.05: disclose any cybersecurity incident the company determines to be material, describing its nature, scope and timing and its material impact or reasonably likely material impact. The filing is generally due four business days after the materiality determination.
- Regulation S-K Item 106: describe, in the annual report, the processes for assessing, identifying and managing material cybersecurity risk, the board's oversight of that risk, and management's role and expertise.
Disclosure may be delayed if the United States Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety. Foreign private issuers use Form 6-K for incidents and Form 20-F for the annual disclosures. Annual disclosures began with fiscal years ending on or after 15 December 2023; incident disclosure applied from 18 December 2023, with an additional 180 days for smaller reporting companies.
3-2Why is the materiality determination the step to exercise?
Because it is the step the rule times from. An organization can detect, contain and recover well and still file late if nobody knew they owned the determination, or if the people who hold the facts never reached the people who decide.
Materiality is a judgement. A tabletop cannot tell you the answer for a future incident. It can show whether the people who make the judgement know that they own it, receive the information they need, and reach a decision without losing days to scheduling.
NIST SP 800-61 Rev. 3, published in April 2025, sets incident response inside the cybersecurity risk management activities of CSF 2.0. The materiality decision is where the two meet: a technical fact becomes a governance decision with a legal deadline attached.
3-3Who should be in the room?
- The CISO or incident commander, who holds the technical facts.
- General counsel or the securities lawyer who advises on filings.
- The CFO or controller, who can estimate financial impact.
- Investor relations or communications, who will draft the external language.
- A business owner for the affected service.
- The executive who makes the final call, and a plan for how the board is told.
Item 106 asks companies to describe board oversight, so the exercise should also test how and when the board hears about the incident.
3-4A session plan for one tabletop
- Discovery. An inject reports unusual access to a system that holds customer or financial data. Players decide whether this is an incident and who is told.
- Scoping. Forensics reports that data was copied. Players decide what they know, what they do not, and who else must now be involved.
- Pressure. A journalist, a large customer and a supplier each ask questions. Players decide who answers and what they say.
- Determination. The facilitator asks the group to make, or formally defer, the materiality determination, and records the time and the reasons.
- Drafting. Players outline the Item 1.05 disclosure: nature, scope, timing and impact. This shows quickly which facts are missing.
- Delay. The facilitator asks whether the case for an Attorney General delay could apply, and who would raise it. If nobody in the room knows the route, that is itself a finding.
The six-step tabletop guide covers preparation, facilitation and the hotwash.
3-5What should the record show?
A decision log with times: when each piece of information arrived, when it reached the decision-makers, when the determination was made or deferred, and why. That log is the raw material for the after-action report and for the next Item 106 description of how the process works in practice.
Give each gap an owner and a date. Gaps to look for: an unclear owner for the determination, no agreed escalation path out of hours, and draft disclosure language that depends on facts the team could not have had.
3-6Where does a platform help?
A CISA Tabletop Exercise Package adapted to a data theft scenario covers this at no cost. Platforms help when you want the stakeholders simulated, the timeline recorded automatically, or the exercise repeated each quarter as people change. Crisis simulation platforms such as Reflex Security, iluminr, Immersive Labs and Hack The Box Crisis Control are compared in the rankings.
Sources
- SEC press release 2023-139: https://www.sec.gov/newsroom/press-releases/2023-139
- CISA Tabletop Exercise Packages: https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
- NIST SP 800-61 Rev. 3: https://csrc.nist.gov/pubs/sp/800/61/r3/final