How to Disclose a Cybersecurity Incident Post-Listing: Immediate 8-K Filing Obligations
The SEC’s cybersecurity disclosure rules, codified in Item 1.05 of Form 8-K and effective as of December 18, 2023, have fundamentally altered the post-listing compliance burden for issuers on the NYSE and NASDAQ. For Hong Kong-headquartered companies and those with significant PRC operations, the requirement to determine materiality of a cybersecurity incident within four business days and file an 8-K presents a collision of US federal securities law with the data localisation and cross-border reporting constraints of the Cybersecurity Law of the PRC (2017) and the Personal Information Protection Law (2021). A failure to file on time—or a premature filing that triggers a PRC regulatory inquiry—creates a dual-listed liability risk that the SEC and the PCAOB are actively monitoring. The first calendar year of full enforcement, 2024, saw 47 Item 1.05 filings by non-US issuers, of which 12 involved entities with principal operations in Hong Kong or the PRC, according to SEC EDGAR data compiled by Audit Analytics. This article dissects the exact trigger, the four-day clock mechanics, the materiality determination standard, and the offshore-specific complications that CFOs and company secretaries of US-listed Hong Kong issuers must internalise.
The Four-Business-Day Clock and the Materiality Trigger
The SEC’s rule is not a blanket reporting requirement for all cybersecurity events. It activates only when an issuer determines that a cybersecurity incident is “material.” This determination is a facts-and-circumstances test, but the SEC has provided explicit guidance in the adopting release (Release No. 33-11216) that materiality must be assessed from the perspective of a reasonable investor—the same standard applied to Item 2.01 (disposition of assets) and Item 4.01 (changes in certifying accountant) under Regulation S-K.
Defining the Incident and the Determination Point
The rule covers “cybersecurity incidents,” defined in Item 1.05(a) as an unauthorised occurrence on or through an issuer’s information systems that jeopardises the confidentiality, integrity, or availability of those systems or the information they process. This includes ransomware attacks, data exfiltration, denial-of-service attacks that impair business operations, and supply-chain compromises that reach the issuer’s network. The clock does not start on the date of the attack. It starts on the date the issuer determines the incident is material. The SEC has stated that this determination must be made “without unreasonable delay” after discovery of the incident, and the four-business-day period runs from that determination, not from the incident itself.
For a Hong Kong issuer with a December 31 fiscal year, a ransomware attack detected on a Friday evening (Hong Kong time) would typically be assessed by the incident response team over the weekend. If the chief information security officer (CISO) and general counsel conclude the incident is material by Monday 5:00 p.m. Eastern Time, the 8-K must be filed by Thursday 5:00 p.m. Eastern Time. The SEC has clarified in its Compliance and Disclosure Interpretations (C&DIs) that the four-day period excludes weekends and federal holidays, but it does not exclude Hong Kong public holidays. An issuer cannot extend the deadline by arguing that its Hong Kong office was closed for the Mid-Autumn Festival.
The Materiality Standard Applied to Hong Kong Issuers
The materiality determination for a Hong Kong-headquartered issuer must account for three distinct dimensions: financial impact, operational disruption, and regulatory exposure. Financial impact is the most straightforward—if the incident causes a loss of revenue exceeding 5% of quarterly revenue or incurs remediation costs that would require a separate disclosure under Item 2.02 (results of operations), materiality is likely. Operational disruption is harder to quantify. If the incident takes down the issuer’s trading platform for 48 hours, or corrupts the data used for its HKEX filings, that is material regardless of the direct financial cost.
The third dimension—regulatory exposure—is unique to cross-border issuers. A data breach that involves personal information of PRC residents triggers mandatory reporting obligations under the PIPL. Article 57 of the PIPL requires notification to the Cyberspace Administration of China (CAC) within 72 hours of discovering a breach that affects personal information. If the issuer also files an Item 1.05 8-K with the SEC within four business days, it must ensure the content of the 8-K does not conflict with PRC data localisation restrictions. The SEC has acknowledged this tension in the adopting release, stating that an issuer may delay filing if disclosure would impede a law enforcement investigation, but that exception is narrow and requires immediate notification to the SEC staff.
What the 8-K Must Contain and the Safe Harbor for Delayed Disclosure
Item 1.05(b) specifies four disclosure elements: the nature and scope of the incident, the timing of the incident, the material aspects of the incident, and whether the issuer has remediated or is in the process of remediating. The SEC has deliberately avoided prescribing a rigid template, recognising that early-stage investigations may yield incomplete information. An issuer may file a limited initial 8-K and then amend it under Item 1.05(c) within the same form type.
The Four Required Disclosure Elements
First, the issuer must describe the nature and scope of the incident. This includes the type of attack (ransomware, phishing, supply-chain compromise), the systems or data affected (customer databases, financial systems, intellectual property repositories), and the geographic scope of the impact. For a Hong Kong issuer with subsidiaries in the PRC, this must specify whether the incident affected systems in Hong Kong, the PRC, or both.
Second, the issuer must state the timing of the incident. This is the date the incident was discovered and, if known, the date it began. The SEC does not require the issuer to disclose the exact time of the attack, but it expects the date to be stated with sufficient precision to allow investors to assess the duration of exposure.
Third, the issuer must describe the material aspects of the incident. This is the most judgment-intensive element. The SEC has stated that an issuer need not disclose specific technical vulnerabilities or system configurations that could aid future attackers. However, the issuer must disclose the material impact on its business operations, financial condition, and results of operations. If the incident has caused a material impairment of the issuer’s ability to comply with its HKEX continuing obligations under Chapter 13 of the Main Board Listing Rules, that must be disclosed.
Fourth, the issuer must state whether it has remediated or is in the process of remediating the incident. This is a forward-looking statement and is protected by the safe harbor under the Private Securities Litigation Reform Act of 1995, provided the issuer has a reasonable basis for the statement and discloses it in good faith.
The Law Enforcement Delay Exception
Item 1.05(d) permits the SEC to delay the filing if the US Attorney General determines that disclosure would pose a substantial risk to national security or public safety. This determination must be made in writing by the Attorney General personally, and the issuer must notify the SEC staff immediately upon receiving such a determination. For Hong Kong issuers, this exception is virtually unavailable. The SEC has never granted a delay under this provision to a non-US issuer, and the process requires coordination with the Department of Justice that is impractical for most offshore companies.
A more practical alternative is the internal delay based on law enforcement cooperation. The SEC’s C&DI 110.02 clarifies that an issuer may delay filing for a “reasonable period” if it is actively cooperating with a law enforcement investigation and the investigating agency requests that the filing be delayed to avoid compromising the investigation. This delay must be documented in writing with the investigating agency, and the issuer must file the 8-K as soon as the delay is no longer necessary. For a Hong Kong issuer cooperating with the Hong Kong Police Force’s Cyber Security and Technology Crime Bureau (CSTCB), this may be a viable path, but it requires the CSTCB to issue a formal written request—an informal verbal request is insufficient.
Cross-Border Complications: PRC Data Localisation and the HKEX Overlay
The intersection of the SEC’s 8-K rule with PRC data protection laws and the HKEX’s own cybersecurity disclosure requirements creates a compliance trilemma. An issuer that files a fulsome Item 1.05 8-K may violate the PIPL by transferring personal information of PRC residents out of the country without a lawful basis. An issuer that withholds information from the 8-K to avoid PIPL liability may violate the SEC’s anti-fraud provisions under Section 10(b) of the Securities Exchange Act of 1934. An issuer that files a delayed 8-K may violate the HKEX’s requirement under Rule 13.24B of the Main Board Listing Rules to disclose any “material information” promptly.
PIPL Cross-Border Data Transfer Restrictions
The PIPL, effective November 1, 2021, imposes strict conditions on the transfer of personal information outside the PRC. Article 38 requires that the transfer be necessary for the purpose of the contract or for the protection of the data subject’s life or property, and that the data subject has given separate consent. For a cybersecurity incident that involves personal information of PRC residents, the issuer cannot simply include that information in an 8-K filed with the SEC without first obtaining the data subject’s consent or passing a security assessment by the CAC. The CAC’s Measures for Data Export Security Assessment (2022) require a security assessment for any data transfer that meets certain volume thresholds—100 million users of personal information, or 1 million users of personal information transferred overseas cumulatively.
For a Hong Kong issuer that is also a PRC data processor, the practical solution is to structure the 8-K disclosure so that it describes the incident without including the specific personal information of PRC residents. The issuer can state that the incident involved personal information of PRC residents without specifying the names, identification numbers, or financial account details. This approach is consistent with the SEC’s guidance that the 8-K need not include “specific technical information” that would create a security risk, and it avoids the PIPL’s cross-border transfer trigger.
The HKEX Overlay and the Dual-Listing Scenario
An issuer listed on both the NYSE and the Main Board of the HKEX faces a simultaneous disclosure obligation. HKEX Rule 13.24B requires an issuer to disclose any “material information” as soon as reasonably practicable after the information comes to the issuer’s knowledge. The HKEX defines “material information” in the Guidance Letter GL95-18 as information that a reasonable investor would consider important in making an investment decision—a standard functionally identical to the SEC’s materiality test.
The timing conflict is acute. The SEC’s four-business-day clock is measured from the determination of materiality. The HKEX’s requirement under Rule 13.24B is measured from the time the information “comes to the issuer’s knowledge,” which is typically the moment the incident is discovered, not the moment materiality is determined. If a Hong Kong issuer discovers a ransomware attack on a Monday morning (Hong Kong time), it must determine materiality for SEC purposes by the end of the day, but it must immediately assess whether the HKEX requires a filing. In practice, the HKEX has accepted that an issuer may delay a filing under Rule 13.24B for a “reasonable period” to assess the impact, but that period is measured in hours, not days.
The recommended approach for a dual-listed issuer is to file a joint announcement on the HKEX’s HKEXnews system and simultaneously file the Item 1.05 8-K with the SEC. The content of the two filings should be consistent, but the HKEX announcement can be more detailed because it is not subject to the SEC’s restriction on disclosing technical vulnerabilities. The issuer should include a cross-reference in the 8-K to the HKEX announcement, noting that the HKEX announcement contains additional information that is not material for SEC purposes.
Practical Compliance Steps for CFOs and Company Secretaries
The SEC’s cybersecurity disclosure rule is not a one-time compliance exercise. It requires a standing incident response plan that integrates the SEC’s materiality determination framework, the PIPL’s notification requirements, and the HKEX’s prompt disclosure obligation. For a Hong Kong issuer with a US listing, the following steps are non-negotiable.
Incident Response Team with Cross-Border Authority
The issuer must designate a cybersecurity incident response team that includes the CISO, the general counsel, the CFO, and the company secretary. The team must have the authority to make the materiality determination without waiting for board approval. The SEC has stated that the materiality determination must be made “without unreasonable delay,” and a board meeting requirement would almost certainly violate that standard. The team should meet quarterly to review the incident response plan and to update the list of key contacts at the SEC, the HKEX, and the CAC.
Pre-Scripted 8-K Templates with PIPL-Compatible Language
The issuer should prepare a pre-scripted Item 1.05 8-K template that includes placeholder language for the four required disclosure elements. The template should include a standard paragraph stating that the incident involved personal information of PRC residents but that the issuer is not disclosing specific personal information because of cross-border data transfer restrictions under the PIPL. This language should be reviewed by PRC counsel to ensure it does not violate Article 38 of the PIPL.
Testing the Four-Day Clock with a Tabletop Exercise
The issuer should conduct a tabletop exercise at least once per calendar year that simulates a ransomware attack detected on a Friday evening (Hong Kong time). The exercise should test the team’s ability to make a materiality determination within 24 hours, to prepare the 8-K within 72 hours, and to file it within the four-business-day window. The exercise should also test the coordination with the HKEX and the CAC, including the preparation of a joint HKEX announcement and a PIPL notification letter.
Three Actionable Takeaways
- Materiality must be determined within 24 hours of discovery, not after a full forensic investigation, because the SEC’s four-business-day clock runs from the determination, not the incident, and a delayed determination is itself a disclosure failure.
- The 8-K must describe the incident without including personal information of PRC residents, using the PIPL cross-border transfer restriction as a disclosure limitation that the SEC has implicitly accepted in its adopting release.
- A dual-listed issuer must file the HKEX announcement and the SEC 8-K simultaneously, using the HKEX announcement as the primary disclosure vehicle and cross-referencing it in the 8-K to avoid inconsistency.