ServicesVantageIndustriesCase StudiesInsightsAboutContactSchedule a Consultation
Home / Insights / SEC

The SEC's Cyber Disclosure Rules, Explained for Private Companies

You are not a registrant. Your customers, acquirers, and lenders may be, and their obligations are becoming yours by contract.

When the SEC adopted its cybersecurity disclosure rules in July 2023, most private-company executives filed it under “public company problem.” That was reasonable for about a year. It is less reasonable now, because the rules have changed what public companies expect from the private companies they buy from, lend to, and acquire.

Here is what the rules say, in plain terms, and why they reach past the registrants they apply to.

What the rules require

The SEC’s final rule (adopted July 26, 2023) does two things:

Incident disclosure. A registrant that experiences a cybersecurity incident it determines to be material must disclose it on Form 8-K (Item 1.05) within four business days of that materiality determination. The disclosure covers the nature, scope, and timing of the incident and its material impact or reasonably likely impact. The four-day clock starts at the materiality determination, not at discovery, but the SEC expects that determination to be made “without unreasonable delay.”

Annual disclosure. Registrants describe, in their annual report (Regulation S-K Item 106), their processes for assessing, identifying, and managing material cybersecurity risks; whether those risks have materially affected the business; and the board’s oversight of cyber risk and management’s role and expertise in managing it.

The annual requirements took effect for fiscal years ending on or after December 15, 2023, and the incident disclosure requirement began December 18, 2023, with smaller reporting companies given an additional 180 days. (Source: SEC Press Release 2023-139 and the final rule, Release No. 33-11216.)

Why this reaches private companies

Your customers are counting your incidents as theirs. If a public company relies on your product or service and you have an incident, that incident may be material to them. Their four-business-day clock can start based on information you give them. That is why customer contracts now routinely include incident notification clauses with tight deadlines (24 to 72 hours is common), rights to information during the investigation, and audit rights afterward. Those clauses are the SEC rule, translated into your MSA.

Your acquirer has to describe your risk. If a public company buys you, your security posture becomes part of their Item 106 disclosure and your incidents become potential 8-K events. Diligence teams now ask for the evidence that would let their client make those disclosures confidently: incident history, response plans, board reporting, risk assessment. A private company that cannot produce them is a harder acquisition, and sometimes a cheaper one.

Your PE sponsor is preparing for an exit. Funds that expect to sell a portfolio company to a public acquirer, or to take it public, are asking their platforms to operate as if the rules already apply. That means a board-level cyber risk process and a materiality framework for incidents, built before the buyer asks.

Your lenders and insurers are reading the same playbook. Cyber insurance applications and credit agreements increasingly ask about board oversight of cyber risk and incident response readiness, using language lifted directly from Item 106.

What “ready” looks like for a private company

You do not need to file anything. You need to be able to answer, quickly and with evidence, the questions the rules cause other people to ask you.

  1. A materiality framework. A short written approach for deciding, in the middle of an incident, whether it is significant enough to escalate, to notify customers, and to report to the board. The SEC’s standard is the securities-law definition of materiality; yours can be simpler, but it should exist before you need it.
  2. Contract-aware incident response. Your incident plan should include a list of who you owe notification to and how fast. Most plans I review have a technical runbook and no notification matrix. The notification matrix is what keeps you out of a breach-of-contract claim.
  3. Board reporting on a schedule. A quarterly (or at least twice-yearly) cyber risk briefing to the board or the sponsor, minuted. This is the single most reused piece of evidence in diligence, insurance, and customer reviews.
  4. A named accountable executive. Item 106 asks about management’s expertise. Buyers and customers ask the same thing of private companies. “Our IT provider handles it” is not an answer; a named executive with relevant experience, in-house or on a vCISO retainer, is.
  5. A defensible risk assessment. Current, written, and tied to what the company actually does, so that when a questionnaire asks “describe your processes for assessing cybersecurity risk,” you can attach it instead of writing it that afternoon.

What this is not

The rules do not require private companies to disclose incidents publicly, and nothing here is legal advice about your specific obligations. Whether you owe notification to a customer, a regulator, or affected individuals is a question for counsel, and the answer depends on your contracts and the data involved. What the rules have done is raise the standard for what your counterparties expect, and that expectation is enforceable through the agreements you sign.

Where to start

If you have a public-company customer, pull your top three contracts and read the incident notification clause. Then open your incident response plan and see whether it mentions those deadlines. The gap between the two is the first project. Our Virtual CISO engagements typically close that gap in the first quarter; if you are preparing for a sale, the M&A advisory work builds the evidence package a buyer will want to see.

Questions about how this applies to your company are welcome: schedule a consultation.

More insights

This site