The Securities and Exchange Commission published its first comprehensive data set on cybersecurity incident disclosures filed under Item 1.05 of Form 8-K, covering the twelve months following the July 2023 rule adoption. 184 public companies filed material breach disclosures during the period. The average time from incident detection to filing was 4.8 days, suggesting counsel review remains the primary bottleneck. Seventeen filers requested delay extensions citing national security or law enforcement coordination.
The new regime makes silence expensive. Companies that disclosed breaches within the four-business-day window saw an average 2.1% stock decline on filing day, recovering 1.4% within ten trading sessions. Late filers—those beyond the statutory window without extensions—experienced 4.7% average declines with no measurable recovery pattern through thirty days. The market now prices disclosure discipline as a proxy for incident-response maturity. Three issuers faced follow-on enforcement inquiries for filing delays the SEC deemed unjustified, though no penalties have been formalized.
The data carries two implications for allocators. First, the 184 filings represent only material incidents under management's judgment—a threshold that remains subjective and varies widely by sector. Financial services and healthcare accounted for 41% of filings despite representing 28% of Russell 3000 constituents, indicating either higher incident rates or lower materiality bars in regulated industries. Second, the compliance infrastructure cost is measurable. Mid-cap issuers in the dataset increased median cyber insurance premiums by 18% year-over-year, and 63% added dedicated incident-response retainers with outside counsel. The rule effectively creates a minimum operational capability floor for public markets.
Operators should track second-year filings for pattern shifts. The SEC indicated it will release quarterly snapshots going forward, with the next data cut due September 2025 covering Q2 filings. Watch for sector-specific guidance from the Division of Corporation Finance, expected by year-end, which may narrow or clarify the materiality standard. Any uptick in enforcement actions for late filings will compress the de facto compliance window below four days as general counsel prioritize speed over precision. Portfolio companies with board-level cyber committees filed 2.3 days faster on average than those without, a structural advantage worth noting in due diligence.
The 184-filing baseline now serves as the market's benchmark for normal breach volume. Any material deviation in quarterly data will signal either a threat environment shift or a change in disclosure interpretation by issuers and their advisors.