SEC Cyber Disclosure Rules and Boardroom Surveillance

The SEC's 2023 cybersecurity rules require disclosure of material incidents on Form 8-K and of risk management practices under Regulation S-K Item 106. A covert device capturing material non-public information is squarely inside that frame.

Framework: United StatesLast reviewed: 2026-09-03

The 2023 rules in brief

Since December 2023, SEC registrants must disclose material cybersecurity incidents on Form 8-K Item 1.05 within four business days of determining the incident is material, and must describe their cybersecurity risk management, strategy, and governance annually under Regulation S-K Item 106 in the Form 10-K — including management's role and the board's oversight of cybersecurity risk.

The rules define a cybersecurity incident broadly: an unauthorized occurrence on or conducted through a registrant's information systems that jeopardizes the confidentiality, integrity, or availability of information systems or the information residing there.

Is a listening device a cybersecurity incident?

Modern covert devices are network devices. GSM and Wi-Fi transmitters, compromised conference hardware, and rogue access points sit on or against the registrant's information systems and exfiltrate information electronically. A device found in a boardroom where earnings, guidance, or deal discussions occur is an unauthorized occurrence jeopardizing confidentiality — the materiality analysis follows from what the device could have captured and for how long.

That last clause is where unprepared companies struggle. Without a documented sweep history, there is no defensible bound on the exposure window, which pushes the materiality assessment toward disclosure and makes the narrative worse. A dated record of clean inspections is what lets counsel bound the window credibly.

What Item 106 lets you say — if it's true

Item 106 asks registrants to describe processes for assessing, identifying, and managing material risks from cybersecurity threats. Companies whose risk program genuinely includes the physical vector — periodic technical surveillance countermeasures inspections of board and executive spaces, trigger-event sweeps around material transactions — can describe a more complete program than peers whose narrative stops at the network perimeter.

The practical steps are modest: add technical surveillance to the enterprise risk assessment, put sweep cadence and trigger events in writing, route findings through the incident response and disclosure committee process, and keep the records that make the program demonstrable.

Primary sources

This guidance is general information, not legal advice. Regulatory obligations depend on your entity classification, jurisdiction and facts — confirm specifics with your counsel or compliance function.

Scope an assessment

A short conversation establishes scope and a fixed price. Assessments run across the US, UK and Europe.

Speak to a specialist