Back to Blog

What the SEC Requires for Cyber Disclosure in M&A: Item 1.05, Reg S-K Item 106, and the Deal Team's Playbook

Three SEC rules — Item 1.05 8-K, Reg S-K Item 106, and Item 2.01 8-K — set the cyber disclosure duty around any M&A deal that touches a public acquirer or soon-to-be-public target. When the 4-business-day clock starts, what the diligence package must contain to support a defensible filing, and the three enforcement cases every deal team should know cold.

Quick Answer

Three SEC rules — Item 1.05 8-K, Reg S-K Item 106, and Item 2.01 8-K — set the cyber disclosure duty around any M&A deal that touches a public acquirer or soon-to-be-public target. When the 4-business-day clock starts, what the diligence package must contain to support a defensible filing, and the three enforcement cases every deal team should know cold.

The SEC's cybersecurity disclosure regime is three rules, not one. Every M&A deal that touches a public acquirer or a soon-to-be-public target triggers at least one of them. The disclosure question surfaces twice in the life of a deal: first, when a material cyber incident is discovered during diligence, and again after close, when the acquirer files its next 10-K and has to account for what it now owns. Deal teams that route cyber diligence as an operational exercise and hand SEC disclosure to outside counsel as a separate workstream usually find out at the wrong moment that the two were the same workstream.

The Bain Capital / PowerSchool ruling in March 2026 sharpened the stakes. A federal court in the Southern District of California allowed five claims against Bain to proceed on the theory that pre-close operational control over PowerSchool's cybersecurity created a separate liability track for the acquirer, independent of the target's own disclosure duty. Everything downstream of that ruling, from how the diligence memo gets written to what covenants live in the term sheet to what the audit committee actually reviews, has to account for it.

4 days
Item 1.05 8-K materiality clock
17 CFR §240.13a-11 (Dec 2023)
$350M
Verizon price cut on Yahoo after mid-deal breach disclosure
2017 amended stock purchase agreement
$35M
Yahoo/Altaba SEC penalty for the same breach
SEC Rel. 33-10485 (Apr 2018)

The three rules that create the M&A cyber disclosure duty

All the mechanics that follow reduce to how these three rules interact when a public company is either the acquirer, the target, or the successor entity after close.

Rule
What it requires
M&A trigger
Item 1.05, Form 8-K
Disclosure of a material cybersecurity incident within 4 business days of determining materiality. Must describe the nature, scope, and timing of the incident and the material impact or reasonably likely material impact on the registrant.
Fires when the acquirer discovers a material incident at the target that has not been disclosed, when the target itself is public and an incident surfaces mid-deal, or when the combined-entity impact of a target's known incident meets materiality post-close.
Regulation S-K Item 106
Annual 10-K disclosure of the registrant's cybersecurity risk-management processes, strategy, and governance, including board oversight, management's role, and disclosure of previously material incidents that have not yet been reported on Item 1.05.
For the acquirer's first 10-K after close, the combined-entity risk-management program, board oversight structure, and any prior incidents at the target that are now material to the combined entity all become disclosable.
Item 2.01, Form 8-K + Regulation S-X Rule 3-05
Disclosure of the completed acquisition itself, including financial statements of the acquired business. Rule 3-05 governs which target periods must be reported. Material subsequent events, including cyber incidents, surface here if not already filed on Item 1.05.
Fires at close of any material acquisition. Cyber disclosures don't live in Item 2.01 itself, but the parallel diligence and audit-committee work to support Rule 3-05 financials is where undisclosed incidents most often get discovered on the acquirer's timeline.
What 'material' means in Item 1.05

The SEC deliberately did not define materiality quantitatively. The determination follows the TSC Industries v. Northway (1976) standard: information is material if there is a substantial likelihood that a reasonable investor would consider it important. The SEC's adopting release specifically rejected commenter requests for a numeric threshold. In practice, the enforcement bar has been set by SolarWinds and Yahoo. A breach affecting hundreds of millions of accounts or the integrity of a core product line is material almost by inspection. The harder cases are targets with mid-sized incidents (5,000 to 50,000 records, or a limited-blast-radius intrusion) where the materiality memo has to do actual work.

When the disclosure clock starts during deal negotiations

The 4-business-day Item 1.05 clock starts on the day the registrant determines the incident is material. The clock does not start on the day of the incident or the day of discovery. This distinction matters enormously in M&A. The SEC has been explicit that a company cannot delay materiality determination to avoid disclosure, but it also cannot rush it before it has the facts.

  • Public target discovers an incident mid-deal: The target is a public company. An incident is discovered during exclusivity. The target's board makes the materiality determination, not the acquirer, not the deal team. Once determined material, the target has 4 business days to file. This will almost always require the deal to be publicly acknowledged in the 8-K narrative, ending confidential negotiation. The deal team's leverage on this timing is zero; the target's counsel controls it.
  • Public acquirer discovers an undisclosed incident at a private target: The private target has no direct SEC obligation. The acquirer does. If the incident is material to the acquirer's investment thesis or to the combined entity's projected posture, the acquirer's Item 1.05 clock starts when the acquirer's board determines materiality. The 4-day window is on the acquirer, even though the incident occurred pre-signing at an entity the acquirer does not yet own.
  • Both entities are public, deal has been announced: Both companies have independent disclosure duties. If the incident affects the target, the target files. If the disclosure materially changes the acquirer's investment case (for example, the CCOD moves by 15% or more of consideration), the acquirer may need to file separately or amend prior deal disclosures. This is where sequencing between the two GCs has to be coordinated hour-by-hour.
  • Post-signing, pre-close discovery: The signing has been publicly announced. The deal has not closed. An incident surfaces at the target. The target files if it is public. The acquirer's obligation depends on whether the incident is material to the acquirer's already-disclosed deal terms; MAC clauses, price adjustment triggers, and financing covenants become the operative documents alongside the 8-K analysis.

Post-close: when the acquirer inherits the disclosure obligation

The day after close, the acquirer owns the target's cyber history. Reg S-K Item 106 requires the acquirer's next 10-K to describe the combined entity's risk management, governance, and any material prior incidents. The SEC's 2023 adopting release specifically addresses this: a prior incident at an acquired entity that is material to the combined registrant on a going-forward basis is disclosable, even if it occurred before the acquirer owned the entity.

The 'no-look-back' myth

Some deal teams operate on a working assumption that pre-close incidents at a private target die at signing, that the acquirer inherits only the entity's forward-looking risk and not its historical disclosure exposure. That is wrong. The SEC's Reg S-K Item 106(b)(1)(iv) requires disclosure of prior material incidents at the registrant, and the enforcement pattern (Yahoo 2018, SolarWinds 2023, R.R. Donnelley 2024) has consistently treated the successor entity as inheriting the underlying disclosure obligation. And the private-status shield is narrower than it looks even during independence: the March 2026 Bain Capital / PowerSchool ruling allowed five separate claims against a PE acquirer to proceed on the theory that pre-close operational control over the target's cybersecurity creates its own liability track, independent of any disclosure duty. Two separate doctrines, one shared diligence record.

What the diligence deliverable must contain to support a defensible filing

The gap between "we bought cyber diligence" and "we have a diligence package our GC can rely on for a 4-day Item 1.05 disclosure decision" is where deals get into trouble. A qualitative red/yellow/green heat map does not support a materiality memo. The package the audit committee needs contains six specific artifacts, all sourced during diligence.

  • A quantified Cyber Cost of Deal with documented methodology: The Annual Loss Expectancy across the five diligence pillars (attack surface, third-party concentration, data sensitivity, insurability, remediation), computed with sourced probabilities (IBM CODB, Verizon DBIR, Ponemon) and named asset values. This is the number the materiality memo compares against the transaction consideration to argue material-or-not. A worked example shows the shape. Without it, the memo relies on adjectives, which the SEC has explicitly rejected as insufficient.
  • A 36-month incident history at the target, with regulatory notification log: Every reportable event in the trailing 36 months: date, nature, scope, customer notification, regulatory notification (HIPAA, GDPR, state AG, any FTC or SEC touchpoint), and resolution cost. Self-reported and third-party-detected incidents both included. Any 'we don't have that' answer from the target is itself a diligence finding; the SEC's Reg S-K disclosure requires the acquirer to know this.
  • A named list of critical vendors with change-of-control clauses and incident SLAs: Verizon 2025 DBIR reports third-party involvement in 30% of breaches. If the target's top-10 vendors include SLAs for incident notification that would flow through to the combined entity, those SLAs are part of the disclosure calculus. A vendor-side breach where the target is a downstream customer is inheritable exposure.
  • An assessment of the target's Reg S-K Item 106 compliance if the target is public: The target's own risk-management, governance, and board-oversight disclosures under Item 106 are a diligence input. Gaps here (a shallow governance section, missing risk-management process description, unrelated-party board oversight) are red flags that materially higher enforcement risk exists post-close.
  • Insurance policy analysis with named exclusions: The active cyber insurance policy, aggregate limit, retention, war/nation-state exclusion language, prior-acts coverage cutoff, and notification requirements. Coverage that lapses on change-of-control (some carriers) or that names the pre-close entity as insured (most) has to be repapered before close, or the combined entity is exposed on Day 1.
  • A written materiality memo template pre-approved by acquirer's SEC counsel: The 4-business-day Item 1.05 window does not give the deal team time to draft the memo structure from scratch when an incident surfaces. The template (with the TSC Industries standard applied, the CCOD-vs-consideration ratio, the comparison to enforcement precedent) should exist in the diligence data room before signing so it can be populated in hours, not days, if an incident is discovered.

Four cases every deal team should know cold

The enforcement pattern is short but instructive. All four cases involve M&A or successor-liability dynamics.

Case
What happened
What deal teams should learn
Yahoo / Altaba / Verizon (2016–2018)
Yahoo discovered in 2014 that state-sponsored actors had exfiltrated data on 500M+ user accounts. Yahoo did not disclose in its 10-K filings or in the M&A-related disclosures during the Verizon acquisition process. Discovery surfaced mid-deal in 2016. Verizon negotiated a $350M reduction in purchase price. The SEC settled with Yahoo/Altaba in April 2018 for $35M for failing to disclose the breach in its filings.
Materiality determination cannot be deferred by treating cyber as an operational issue. If the board knew and did not disclose, the SEC's enforcement position is that the disclosure obligation existed. In-diligence discovery must be repapered into the deal disclosures, not routed to a separate remediation workstream.
Marriott / Starwood (2018)
Marriott acquired Starwood in 2016. In 2018, Marriott disclosed that a breach at Starwood's reservation database, originating in 2014 pre-acquisition, had exposed data on ~500M guests. Marriott ultimately paid a £18.4M UK ICO penalty and settled a US class action for $52M. Marriott had not detected the intrusion during diligence.
Diligence must include actual technical assessment of the target's environment, not just document review. A years-long dormant intrusion is exactly what a properly scoped Tier-1 diligence pass exists to detect. Reg S-K Item 106 now requires the acquirer to describe how it evaluated the target's cyber posture pre-close. The answer 'we relied on the target's SOC 2 report' is a documented weakness.
SolarWinds / SEC (2023)
SEC filed a civil enforcement action in October 2023 against SolarWinds and its CISO, alleging fraud and internal controls failures related to statements about the company's cybersecurity practices pre- and post-Orion supply-chain incident (2020). The action was substantially dismissed in July 2024, but the SEC's stated position, that materially misleading cyber disclosures can be an enforcement target, stands.
Post-close, the acquirer's ongoing cybersecurity disclosures inherit the target's control weaknesses. If a control gap identified in diligence is not remediated and later contributes to an incident, the disclosure narrative describing the acquirer's cyber posture must account for the known-and-inherited gap. Aspirational disclosure is enforcement risk.
Bain Capital / PowerSchool (2024–2026)
Bain acquired PowerSchool for $5.6B in Oct 2024. A ShinyHackers intrusion had started in August 2024 (pre-close) via stolen vendor credentials. Bain's pre-close offer conditioned closing on cyber-staff layoffs; post-close it replaced the board and directed offshoring of cybersecurity functions. Breach surfaced Dec 2024 via ransom demand; disclosed Jan 2025. ~70M student and teacher records exposed. Consolidated class actions in SDCal named both PowerSchool and Bain. March 18, 2026: court allowed five claims against Bain to proceed (aiding and abetting, negligence, negligence per se, unjust enrichment, CA UCL). Court: 'control-in-fact ate control-on-paper.'
The disclosure duty and the acquirer's tort-liability duty are separate doctrines that feed off the same diligence record. Conditioning offers on cyber-cost cuts, exercising veto rights over the target's security budget, and directing post-close operational changes all become discoverable regardless of what the acquisition documents say about 'investor, not operator' status. The diligence memo has to serve both regimes; treating either as boilerplate now materially increases exposure to the other.

The private-target twist

The SEC's rules apply to public registrants. A private target has no direct Item 1.05 or Reg S-K Item 106 obligation. That does not make the disclosure question go away in the deal.

What survives to the public acquirer

The acquirer's Reg S-K Item 106 duty on its next 10-K applies to the combined entity. Prior material incidents at the private target become disclosable if they are material to the combined registrant. The private-status shield covered the target during its independent life; it does not cover the incident forever. The 2023 SEC adopting release makes this explicit: the successor entity's disclosures include the acquired business's history to the extent material.

What surfaces at IPO or exit

Private targets pursuing an IPO or an exit to a public strategic acquirer will surface prior incidents in the S-1 or in the acquirer's diligence. The private-company period is a runway, not a permanent immunity. Companies that treat pre-IPO diligence as the moment to first assemble a comprehensive incident history typically discover during the S-1 process that the timeline is too compressed and the disclosure ends up broader than a properly maintained record would have required.

What good looks like: the disclosure package the audit committee should demand

By the time the deal reaches the acquirer's audit committee, the cyber diligence workstream should have delivered a package that lets the committee answer three specific questions without further discovery:

  • Is there a material cyber incident at the target that has not been disclosed?: Answered by the 36-month incident history, the regulatory notification log, and the technical assessment findings. The affirmative or negative answer, with the evidence and the materiality analysis behind it, in one paragraph.
  • What is the quantified cyber exposure the combined entity inherits?: Answered by the CCOD number, the confidence interval, the top-three drivers of the number, and the sensitivity of the number to the two or three assumptions most likely to be wrong. Not a heat map. A dollar figure with methodology.
  • What is the disclosure posture on Day 1 post-close?: Answered by the pre-approved materiality memo template, the identified prior incidents that will need Reg S-K Item 106 treatment on the next 10-K, and the specific language changes to the acquirer's existing cyber-governance disclosure that the combined entity will require. This is a legal deliverable, not a security deliverable, but the security team has to give the legal team what they need to write it.

If any of these three questions cannot be answered on the day of the IC meeting, the diligence is not complete, regardless of how many artifacts have been produced. The audit committee's job is to certify the disclosure controls; the diligence package's job is to make that certification defensible.

Where the QCD methodology plugs into SEC disclosure

vCISO Lite's Quantitative Cyber Diligence (QCD) methodology was built around the five-pillar framework that maps directly onto what the SEC's disclosure rules require the acquirer to know. Each pillar produces a dollar-denominated finding that supports a materiality memo, and the assembled CCOD number is the exact input the audit committee needs to make a defensible Item 1.05 determination when an incident surfaces. The methodology also produces the artifacts (vendor register with SLAs, 36-month incident history, insurance analysis, governance assessment) that populate Reg S-K Item 106 for the combined entity's first post-close 10-K.

The point is not that QCD is the only way to do this. The point is that any diligence methodology has to produce these artifacts, in this format, on this timeline, or the SEC disclosure obligations cannot be met without a scramble. Deal teams that route cyber diligence to a vendor optimized for a written report (the 40-page PDF with the heat maps) should assume the disclosure question will re-emerge at IC and again post-close, and budget the additional discovery cost.

If you're scoping cyber diligence for an active deal or reviewing the disclosure posture on a recent close, visit vcisolite.com to learn more and get started.

Where this matters next

Share this article:

Ready to build your security program?

See how easy it can be.