SEC Cybersecurity Disclosure Rule
Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule

SEC Cybersecurity Disclosure Rule 1.05-I1: Item 1.05 Instruction 1: determine materiality without unreasonable delay after discovery

Make the materiality determination for a cybersecurity incident without unreasonable delay after discovering it. Materiality follows the securities-law standard (a substantial likelihood that a reasonable shareholder would consider it important, or that it would significantly alter the total mix of information) and weighs quantitative and qualitative factors, such as harm to reputation, customer or vendor relationships or competitiveness, and the possibility of litigation or regulatory action. Because a cybersecurity incident includes a series of related unauthorized occurrences, related incidents that are each immaterial must be assessed collectively (C&DI 104B.09). An incident that has stopped must still be assessed (104B.05); insurance reimbursement of a ransom (104B.07) or a small payment (104B.08) does not by itself make it immaterial; consulting the Department of Justice or other agencies is not itself a materiality determination (104B.04).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Form 8-K Item 1.05: Material cybersecurity incidents – SEC Cybersecurity Disclosure Rule

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.