The SEC cybersecurity rules changed the CISO job in a specific way: they turned a security incident into a securities-disclosure event, and they made how the board oversees cyber risk a matter of public record. Most CISOs can recite the four-business-day headline and stop there. The parts that actually matter for you are subtler: who owns the materiality judgment, how the disclosure decision is supposed to work so that it does not land on you alone, and where your personal exposure really sits. I sit on the hiring side of security-leadership searches, and fluency here now separates candidates in board-facing rounds and protects you once you are in the seat. This guide is that fluency, and the protections to negotiate before you sign.
What the SEC cyber rules actually require
There are two distinct obligations, and conflating them is the most common mistake. The first is incident disclosure: a public company must report a material cybersecurity incident on a Form 8-K, generally within four business days of determining the incident is material, describing its nature, scope, and timing, and its material impact or reasonably likely material impact. The second is governance disclosure: in the annual 10-K, the company must describe its processes for assessing, identifying, and managing material cyber risks, and describe the board’s oversight of those risks and management’s role. One is fast and event-driven; the other is annual and structural. As a CISO you feed both, but you own neither the filing nor the legal judgment behind it.
The materiality judgment: the thing you must not own alone
Here is the single most important point for your own protection. Materiality is a company determination, not the CISO’s call. The standard is a securities-law standard, whether a reasonable investor would consider the information important, and the determination is meant to be made through a disclosure process that pulls in legal, finance, senior executives, and often the board. Your role is to surface the incident fast and give accurate, honest technical facts about scope and impact so that the people who own the legal judgment can make it. It is emphatically not your role to decide materiality alone in a Slack message at 2am.
Why this matters so much: if a company’s process, or its paperwork, quietly positions the CISO as the person who decides whether an incident is material, it has transferred a legal decision, and the liability attached to it, onto you. In interviews and in your first 90 days, the sophisticated move is to ask exactly how the materiality determination is made and to insist that you are an input to a cross-functional disclosure process, not the sole decider. The board presentation guide covers how to have that governance conversation with directors in a way that builds trust rather than sounding defensive.
The four-day clock, correctly understood
The four-business-day window is widely misquoted. It does not begin when the breach occurs, or even when you discover it. It begins when the company determines the incident is material. But companies cannot game that by simply refusing to decide: the expectation is that the materiality determination is made without unreasonable delay after discovery. There is a narrow national-security exception, available only when the US Attorney General makes a specific determination, and it is not a routine tool. For the CISO, the operational takeaway is concrete: your detection, scoping, and escalation machinery has to be fast and clean enough to feed a materiality decision promptly, because a slow or chaotic incident response now creates disclosure risk on top of security risk.
Where your personal exposure actually sits
The rules place obligations on the company, but CISOs carry real personal exposure adjacent to them, and the SolarWinds enforcement action made that concrete. The exposure is not usually about the incident itself; it is about statements. Alleged misrepresentations of a company’s security posture, in public filings, on the website, in a security whitepaper, or even in internal documents that later surface, are where the personal risk concentrates. The practical defenses are three:
- Do not sign off on materiality alone, for the reasons above.
- Keep your risk representations honest and documented. Do not let marketing or sales describe the security program in terms you know are not true, and keep a record of the risks you flagged and to whom. Your honest, contemporaneous risk statements are your protection; inflated ones are your liability.
- Get your governance protections in writing before you sign. This is a compensation and terms issue as much as a legal one.
What to negotiate before you take the seat
Treat SEC exposure as a term of the deal, not an afterthought. Before signing a public-company CISO offer, get answers in writing on:
- D&O coverage. Confirm you are covered as an officer under the company’s directors-and-officers policy, whether or not your title is technically C-level, and that coverage survives your departure for actions taken during your tenure.
- Indemnification. A board-approved indemnification agreement for actions taken in good faith within your role, not a verbal assurance.
- Where materiality is decided. Get the disclosure-process governance documented, so it is clear you are an input to a committee, not the sole decision-maker.
- Reporting and escalation authority. Confirm you can escalate an incident to legal and the board directly, and that no one can suppress a disclosure-relevant fact you have surfaced.
A company that gets uncomfortable when you raise these is telling you something important about how it will treat you when an incident actually happens. This is exactly the accountability-without-authority pattern the offer red flags guide is built to detect, and the compensation guide covers how to negotiate D&O and indemnification alongside the rest of the package.
The bottom line
The SEC rules did not make the CISO the disclosure decision-maker; they made the CISO the person whose honest, fast, well-documented input the disclosure process depends on, and whose public statements about security carry personal risk. Fluency means knowing the two obligations apart, understanding that materiality is a cross-functional company judgment you must not own alone, and treating D&O, indemnification, and a documented disclosure process as things you negotiate before you sign. Get those right and the rules are a governance framework you can operate inside confidently. Get them wrong and you have accepted the accountability for a decision you were never actually given the authority to make.