Resources — FAQ

SEC Cybersecurity Disclosure FAQ

Answers specific to SEC cybersecurity disclosure requirements (Item 1.05 of Form 8-K and related rules) and how Essert supports the materiality assessment and disclosure process.

What counts as a “material” cybersecurity incident?

Materiality is a judgment call the SEC leaves to each organization to define and apply consistently. Essert's workflow structures that judgment into a repeatable, documented process rather than a fixed formula — but the determination itself remains yours (with legal counsel) to make.

Does Essert file the disclosure with the SEC on our behalf?

No. Essert prepares the materiality assessment and supporting evidence; your legal and investor-relations teams handle the actual filing.

What's the disclosure deadline once an incident is determined material?

Current SEC rules require disclosure within four business days of a materiality determination, via Form 8-K Item 1.05 — Essert's timeline tracking starts the clock automatically from the point of determination and flags it to your team.

Can we run a practice materiality assessment before a real incident?

Yes — Essert supports tabletop exercises so your team can rehearse the workflow under low-stakes conditions.

Does this apply to private companies?

The SEC's Item 1.05 disclosure requirement applies to public companies; private companies may still adopt the same materiality-assessment discipline as governance best practice, but aren't subject to the disclosure deadline itself.

Still have questions?

We'll route it to the right person.

Contact Us