The 2023 rules in brief
Since December 2023, SEC registrants must disclose material cybersecurity incidents on Form 8-K Item 1.05 within four business days of determining the incident is material, and must describe their cybersecurity risk management, strategy, and governance annually under Regulation S-K Item 106 in the Form 10-K — including management's role and the board's oversight of cybersecurity risk.
The rules define a cybersecurity incident broadly: an unauthorized occurrence on or conducted through a registrant's information systems that jeopardizes the confidentiality, integrity, or availability of information systems or the information residing there.
Is a listening device a cybersecurity incident?
Modern covert devices are network devices. GSM and Wi-Fi transmitters, compromised conference hardware, and rogue access points sit on or against the registrant's information systems and exfiltrate information electronically. A device found in a boardroom where earnings, guidance, or deal discussions occur is an unauthorized occurrence jeopardizing confidentiality — the materiality analysis follows from what the device could have captured and for how long.
That last clause is where unprepared companies struggle. Without a documented sweep history, there is no defensible bound on the exposure window, which pushes the materiality assessment toward disclosure and makes the narrative worse. A dated record of clean inspections is what lets counsel bound the window credibly.
What Item 106 lets you say — if it's true
Item 106 asks registrants to describe processes for assessing, identifying, and managing material risks from cybersecurity threats. Companies whose risk program genuinely includes the physical vector — periodic technical surveillance countermeasures inspections of board and executive spaces, trigger-event sweeps around material transactions — can describe a more complete program than peers whose narrative stops at the network perimeter.
The practical steps are modest: add technical surveillance to the enterprise risk assessment, put sweep cadence and trigger events in writing, route findings through the incident response and disclosure committee process, and keep the records that make the program demonstrable.