SEC Cyber-Materiality: Why a Defensible Dollar Beats Adjectives
What Item 1C and the four-day 8-K clock actually require, why "material" is a financial total-mix question, and where a method-stamped quantification helps counsel decide.
Since the SEC adopted its cybersecurity disclosure rules in 2023, the CFO and the CISO have been bound to the same problem whether or not they have met to discuss it. Two distinct obligations now sit on top of cyber risk. The first is annual and descriptive: Regulation S-K Item 106, surfaced as Item 1C in the Form 10-K, requires a registrant to describe its processes for assessing, identifying, and managing material risks from cybersecurity threats, plus the board's oversight and management's role. The second is event-driven: Form 8-K Item 1.05 requires disclosure of a cybersecurity incident the registrant has determined to be material. Both pivot on the same word, and that word is a financial term of art, not an engineering one.
Item 1C: describing your process has teeth
Item 1C is often underestimated because it asks you to describe rather than certify. But description has teeth. The rule wants to know how you decide what is material, who reviews it, how often, and how the board exercises oversight. A program that produces inconsistent, ad hoc, or purely narrative judgments about cyber risk reads very differently in a 10-K than one that runs a repeatable, documented process. The annual disclosure is, in effect, a public account of your risk-management machinery. If that machinery cannot articulate how a given risk would translate into financial consequence, the disclosure tends to default to generic language that says little and protects less.
The 8-K and the four-day clock
The 8-K obligation is where timing pressure concentrates. Once a registrant determines that an incident is material, it generally has four business days to file, describing the incident's nature, scope, and timing and its material impact or reasonably likely material impact on financial condition and results of operations. Critically, the four-day clock does not start at discovery; it starts at the materiality determination, which the rule requires be made without unreasonable delay after discovery. That structure means the determination itself is the load-bearing decision. Move too slowly and you risk an unreasonable-delay finding; move without a defensible basis and you expose the judgment to second-guessing with the benefit of hindsight.
What 'material' actually means
So what does material mean here? The SEC did not invent a cyber-specific threshold; it imported the long-standing securities-law standard from TSC Industries v. Northway and Basic v. Levinson. Information is material if there is a substantial likelihood that a reasonable investor would consider it important to an investment decision, or that it would significantly alter the total mix of information available. There is no statutory dollar line, no fixed percentage of revenue, no bright-line trigger. Materiality is a judgment about how a reasonable investor would weigh the information, and under guidance like SAB 99 it is explicitly both quantitative and qualitative. A small dollar figure can still be material for qualitative reasons, and a large one is not automatically dispositive.
This is precisely why qualitative-only language is fragile under the standard. Words like significant, serious, or limited are unanchored: they do not tell a reader, a regulator, or a court what magnitude was contemplated or how the conclusion was reached. The same adjective gets applied inconsistently across incidents and across the people making the call, which undermines the comparability the disclosure regime is built on. And because materiality is assessed against the total mix, a narrative that never quantifies the potential impact gives the determination no measurable reference point. When an incident is later litigated or examined, the absence of a basis is itself a vulnerability, regardless of whether the ultimate call was right.
Why a defensible dollar helps
A dollar quantification helps because it puts the determination on the same axis the standard actually uses. Investors weigh information against revenue, earnings, cash flow, liquidity, and the company's own guidance. A potential loss expressed as a range, against that financial backdrop, lets the decision-maker reason about whether it could significantly alter the total mix. It also creates consistency: the same method applied to two incidents produces comparable outputs, so the materiality line is drawn the same way each time rather than re-argued from adjectives. None of this makes the call mechanical, but it gives the human judgment something concrete to weigh.
The method behind a financial estimate needs to match the question. A pre-incident annual loss model and an estimate of the consequences of a specific incident are different analyses. An incident review needs the actual facts, affected systems, loss categories, time horizon and uncertainties available at that point. A probabilistic model can help expose assumptions, but an annual P95 is not an incident-impact estimate or a materiality threshold. Keep measured costs and modeled future impacts distinct.
The honest boundary
Here is the honest boundary, and it is not a disclaimer to skim past. Quantification does not make the materiality determination. Counsel, the disclosure committee, and ultimately the board or audit committee make it, weighing legal standards, qualitative factors, and context that no model captures. A quantified loss range is an input to that judgment, not a substitute for it. Nothing produced by a quantification engine is legal advice, an audit opinion, or an investment recommendation, and a number should never be presented to the board as a guarantee of outcome. What the quantification does is give the deciders a structured, documented basis to reason from and to record.
That documented basis is the quiet value most teams underweight. Whatever the determination, the SEC, the plaintiffs' bar, and your own auditors will eventually ask how it was reached. A contemporaneous record that shows the estimated financial exposure, the method used, the confidence attached, and the data it drew on is a fundamentally stronger artifact than a memo asserting an incident was or was not significant. It demonstrates the determination was made on a reasoned basis at the time, which is the posture you want if the call is ever revisited with hindsight. A number with no method behind it is arguably worse than no number at all, because it invites the question your file cannot answer.
A repeatable evidence and review process can also inform the annual account of risk governance. Preserve what was assessed, who reviewed it and which actions followed. A public hypothetical model does not demonstrate that a company’s process operated, and a financial calculation does not by itself satisfy a disclosure obligation.
Pitfalls worth naming
Several pitfalls deserve naming because they recur. Over-precision, where a model spits out a figure to the dollar and people start treating the false specificity as truth, is the most common; ranges and confidence bands are the antidote. Anchoring on the first number presented, double-counting overlapping loss categories, and conflating an estimate with a forecast are close behind. Scope is its own trap: related incidents may need to be assessed in the aggregate rather than dismissed individually, and forward-looking impact statements carry their own liability considerations that counsel, not the model, must manage. A quantification tool should make these tensions visible, not paper over them.
Where Valty fits
Valty supports a scoped review of evidence, financial assumptions and funding alternatives. Its public methodology demonstrates mean, median and P95 annual gross loss using a fictional scenario, not an estimate of a particular incident’s impact. The proof workflow shows how sources and limitations can accompany a reviewable output. Confirm the exact supported workflow during evaluation. Valty does not make a materiality determination, provide legal advice or replace the company’s disclosure process and counsel.
Inspect the fictional sample decision memo, or request a platform demo to explore the supported workflow with illustrative data. Company scope, evidence handling, access, onboarding and commercial terms are agreed separately before evaluation. Valty does not make the materiality call and does not replace counsel.

