Leadership1 publisher3 min readPublished
SEC staff says Item 1.05 leaves a breached company free to brief its vendors
The Division of Corporation Finance has told companies that the belief that the cyber disclosure rule bars them from saying more than the 8-K is wrong. Silence toward customers and peers is now a board's call.
The Board Room · Leadership desk

What happened
- An SEC statement says nothing in Item 1.05 of Form 8-K prevents a company from privately discussing a material cybersecurity incident, or sharing more detail about it, than the filing contained.
- Division of Corporation Finance staff had been hearing the opposite from companies, which asserted the disclosure rules precluded them from telling commercial counterparties anything further.
- On Regulation FD, the statement sets out four routes to sharing: immaterial information, recipients outside the rule, a duty of trust or confidence, or an express confidentiality agreement.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- decision A playbook that routes every counterparty question to a no-comment citing SEC rules now needs an owner who decides case by case what gets shared and under what agreement.
- exposure A customer or supplier left uninformed through the next breach has a staff statement to cite when arguing the silence was elective and cost it remediation time.
- constraint The relief runs only to the Commission's rules, so contract notice terms, other regulators and discovery risk still bound what counsel will sign off on.
- precedent With the securities argument answered, a blanket no-comment posture becomes a judgement a board has to record a reason for.
An Item 1.05 filing is written about the company. The rule asks for the material aspects of the nature, scope and timing of an incident, and its material impact or reasonably likely material impact on the company, including financial condition and results of operations [4]. A supplier reading that learns whether its customer expects a bad quarter, and nothing about which credential to rotate. The statement names the parties who need the second thing: commercial counterparties such as vendors and customers, plus other companies that may be impacted by, or at risk from, the same incident or threat actor [6]. Sharing with them, it says, may assist remediation, mitigation or risk avoidance and may help those parties meet their own reporting obligations [7].
The objection counsel actually raises is Regulation FD, and the statement takes it in order. Regulation FD requires public disclosure of material nonpublic information that has been selectively disclosed to securities market professionals or shareholders [8]. Nothing in Item 1.05 alters that regulation or makes it apply differently to communications about a cyber incident [9]. From there the statement lists the ordinary routes through. The information being shared may be immaterial, or the recipients may not be persons Regulation FD covers, or an exclusion may apply: a recipient who owes a duty of trust or confidence to the issuer, such as an attorney, investment banker or accountant, or one who expressly agrees to maintain the information in confidence [10]. In operating terms, that last route is a confidentiality agreement signed before the technical call.
A general counsel's real worry is that a candid briefing to a vendor is discoverable and that somebody's notes become an exhibit. That worry is legitimate and this statement does not answer it, because it speaks only to the Commission's rules, which it says generally do not prohibit the sharing of such information [14]. A company can no longer describe its silence as something the SEC required. On the impression that the rules prohibit discussion beyond the filing, the statement says: "That is not the case." [3]
The misreading took hold quickly. The statement describes the Commission as having adopted the Item 1.05 rules the previous year and says Division of Corporation Finance staff have been hearing the assertions since then. That puts the spread of the belief inside roughly twelve months of adoption [13]. It also observes that Regulation FD was adopted over 20 years ago. If the scope and requirements of those rules are heeded, it says, they should not be an undue impediment to sharing [11].
The choice in front of a board this quarter is narrow and unglamorous. Who is authorised to brief a counterparty during an incident, at what level of detail, and is the confidentiality agreement drafted now or at hour six of the response? Boards that leave the question open will still answer it, by default, and the default is a spokesperson declining to comment to everyone including the customers carrying the same exposure. At the next incident, the customer who heard nothing and the peer hit by the same actor can both point to a staff statement saying nothing in Item 1.05 prohibited the conversation [5].
What to watch
- Any Commission-level restatement of the point; a statement from Division staff carries no binding force.
- The first post-incident suit in which a customer or supplier argues it was left uninformed and cites this statement.
- Whether incident response plans start naming who may authorise a counterparty briefing, with the confidentiality agreement pre-drafted.