Securities Regulation Daily Wrap Up, CYBERSECURITY—Financial trade groups ask SEC to rescind rule on 4-day cyber breach disclosure, (May 28, 2025)
Organizations Mentioned:American Bankers Association | Bank Policy Institute | Independent Community Bankers of America | Institute of International Bankers | Securities Industry & Financial Markets Association | U.S. Attorney General

The trade associations say a specific rule requiring disclosure of cybersecurity incidents is harmful to companies and does not help investors.
Five major financial industry associations petitioned the SEC to eliminate a requirement for companies to disclose material cybersecurity incidents within four business days. According to the groups, Form 8-K Item 1.05 hurts registrants and does not give investors useful information. They also asked the SEC to rescind similar cyberincident disclosures by foreign private issuers in Form 6-K.
Under Item 1.05, registrants must assess whether a cybersecurity incident is material and, if so, file a Form 8-K generally within four business days.
The trade groups strongly criticized Item 1.05 as confusing and interfering with incident response, law enforcement investigations, and internal communications. They said it could also open companies to further cyberattacks and financial harm.
The petition was signed by Securities Industry and Financial Markets Association (SIFMA), American Bankers Association, Bank Policy Institute, Independent Community Bankers of America, and Institute of International Bankers.
Item 1.05 disclosure. In 2023, the SEC added specific cybersecurity disclosures to Forms 6-K and 8-K as part of a new cybersecurity ruleset (Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, 88 Fed. Reg. 51896, Release No. 33-11216 (July 26, 2023)). The amendments became effective September 5, 2023.
According to a fact sheet, registrants must determine whether an incident is material “without unreasonable delay” following discovery. If the incident is determined material, then the registrant must file an Item 1.05 Form 8-K, generally within four business days. A registrant may delay filing upon certain notification by the U.S. Attorney General.
The SEC also added Reg S-K Item 106, requiring registrants to disclose processes and oversight to manage cybersecurity threats. The groups said they have concerns about Item 106 but are not asking the SEC to rescind it.
Harms. The trade groups said Item 1.05 is causing various harms.
Registrants have been forced to publicly disclose incidents, even when an issue is ongoing and has not yet been remediated. This could expose registrants to further cyberattacks;
The SEC’s requirement directly conflicts with confidential reporting requirements, compromising coordinated regulatory efforts to enhance national cybersecurity;
The delay mechanism interferes with incident response and law enforcement investigations;
The rule has created market confusion as to mandatory versus voluntary disclosures;
The disclosure requirement has been weaponized as an extortion method by ransomware criminals. For example, in November 2023, the ransomware group AlphV took the unprecedented step of reporting to the SEC that its victim, MeridianLink, had not publicly disclosed a cybersecurity breach carried out by AlphV;
Insurance and liability implications of premature disclosures can exacerbate financial and operational harm to registrants;
Forced public disclosure could chill candid internal communications and routine information sharing.
Investor impact. The groups said Item 1.05 disclosures of cyber incidents are “unhelpful” to investors and have “failed to provide the market with meaningful or actionable information upon which to make investment decisions.”
“Critically, without Item 1.05, investor interests will still be protected, and we believe they would be better served, through the pre-existing disclosure framework for reporting material information—which may include material cybersecurity incidents—while better mitigating the concerns raised above,” the groups stated.
Although Item 1.05 only requires disclosures of “material” incidents, the groups said some companies were disclosing incidents before making this determination “out of an abundance of caution.” This was potentially “flooding” investors with immaterial information. While the number of immaterial disclosures declined after a clarifying statement by Erik Gerding, then-Director of the Division of Corporation Finance, the group said this caused confusion for investors.
The groups noted that registrants would still be able to voluntarily disclose cybersecurity incidents under Item 8.01.
SEC commissioner views. The rule was adopted in a 3-2 party line vote, with then-Chair Gary Gensler and Commissioners Caroline Crenshaw and Jaime Lizárraga voting to adopt.
In voting for the rule, Crenshaw said that cybersecurity breaches reported by public companies increased by nearly 600 percent in the last decade, and the costs, borne by issuers and their investors, are estimated to be in the trillions of dollars per year in the U.S. alone.
Commissioners Mark Uyeda and Hester Peirce criticized the rule as an overreach of the SEC’s authority. In Uyeda’s view, the rule unduly elevates cybersecurity risks over others faced by companies.
MainStory: TopStory CyberPrivacyFeed DataBreach DataSecurity FedTracker Securities FinancialIntermediaries PublicCompanyReportingDisclosure