Desk live·
ForensicPost
Cloud/Method/File 26-0403

US Public Companies Must Disclose Material Cyber Incidents Within Four Days

US public companies must disclose material cyber incidents within four business days of determining materiality. The clock and the investigation run on incompatible timescales.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS public companies
ActorUnattributed
D. Kennedy10 min readConfidence: high2 sources reviewed

US public companies must disclose material cybersecurity incidents within four business days of determining that an incident is material. Insider incidents qualify. Boards are expected to oversee the risk, and the determination is an accountable judgement rather than a formality.

This desk reads a great many filings made under this rule, and the tension in them is consistent.

Materiality Precedes Understanding

Four business days from a materiality determination is a workable window for drafting. It is not a workable window for knowing what happened.

At the point a company concludes an incident is probably material, a typical investigation has established that unauthorised access occurred and roughly where. It has usually not established what was taken, over what period, or how many people are affected — the Conduent file in 26-0731 took fifteen months to settle its count.

Which Is Why Filings Read The Way They Do

The resulting language — "unauthorised access to certain systems", "the investigation is ongoing", "no material impact on operations to date" — is frequently criticised as evasive. Some of it is. Much of it is an accurate description of what is known on day four.

The genuine problem is that the determination itself can be deferred. The clock starts on a judgement the company makes, and a company that has not yet determined materiality has not yet started the four days.

What We Do With These Filings

We treat a filing as evidence of what the company was prepared to state on a date, not as a description of the incident. We record the date, the language, and later revisions — because the drift between an initial filing and a final count is frequently the most informative thing in a file.

How we reported this

This is a standards file. Compiled from published regulatory analysis, listed below. It is not legal advice and we are not characterising any specific company’s compliance. Corrections: corrections@forensicpost.com.

Sources
  1. SEC public companies enforcement: FY 2025 review and what to expect in 2026Cooley
  2. 2026 insider threat cyber security statisticsSwif
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary