Back to Blog
Insights
cybersecurity risk analysis

U.S. Investors: SEC Filings Based Cybersecurity Risk Analysis With AI

September 4, 202611 min read

U.S. Investors: SEC Filings Based Cybersecurity Risk Analysis With AI

Analyst comparing cybersecurity filing disclosures

For investment analysts, cybersecurity risk analysis means extracting and translating a company's SEC cybersecurity disclosures, specifically Item 1.05 and Item 1C/Item 106, into quantified, scenario-adjusted investment risk signals. Start by pulling recent Form 8-K Item 1.05 filings and the latest Item 1C language for each ticker in your coverage. The SEC's 4-business-day disclosure window means fresh incident filings carry time-sensitive information, and a tool with AI capabilities can help you triage that flow before you dig into the underlying language yourself.


TL;DR:

  • Material disclosures often show a reactive pattern, with increased mitigation language following incidents, indicating weaker underlying cyber programs.
  • Extracted impact details, governance structures, and third-party mentions help model scenario-specific risks and avoid overlooking unquantified tail risks.
  • Amended filings frequently reveal significant new information, especially when initial disclosures lack concrete impact quantification or detail.
  • Structured, AI-assisted review workflows enable faster detection of relevant disclosures, comparison with prior statements, and identification of potential red flags.
  • Disclosures lacking specific impact or relying on boilerplate language should be viewed with caution, as they may mask weak cyber risk management or misleading transparency.

Table of Contents

What Does the SEC Require Companies to Disclose About Cybersecurity?

Two disclosure lanes matter here, and they serve different purposes. Form 8-K Item 1.05 covers the event lane: a company must disclose a cybersecurity incident it determines to be material within four business days of that determination, not four days from discovery. Regulation S-K Item 106, which shows up as Item 1C in the annual 10-K, covers the program lane: how a company assesses, manages, and governs cyber risk on an ongoing basis.

The SEC's compliance guide lays out what each lane requires:

  • Item 1.05 fields: nature and scope of the incident, timing, and material impact or reasonably likely material impact on financial condition or results of operations.
  • Item 1C fields: risk assessment processes, board oversight structure, management's role and relevant expertise, and how the company handles third-party and vendor risk under Item 106.
  • Delay provision: the Attorney General can authorize a limited delay when immediate disclosure would create a substantial national security or public safety risk, per the Federal Register adopting release.
  • Inline XBRL: both disclosures require structured tagging, which affects how quickly you can pull comparable data across your coverage universe.

Practically, you check the 8-K for anything recent and acute. You check Item 1C for the standing program. Amendments to either filing, especially Item 1.05 amendments that add detail the original filing omitted, deserve extra scrutiny.

How Do You Decide if a Cyber Disclosure Is Material to Your Model?

The SEC applies a reasonable-investor standard: information is material if there's a substantial likelihood a reasonable investor would consider it important to the total mix of information available. That's the same materiality test used across securities law, and it's the filter you should run every cybersecurity disclosure through before you touch your model.

In practice, that means separating disclosures that actually move the needle from disclosures that just check a box. A sentence acknowledging "cybersecurity risks exist" tells you nothing new. A sentence quantifying remediation spend, customer attrition, or a specific litigation exposure tells you something you didn't know yesterday.

Split what you're reading into two buckets:

  • Quantitative signals: disclosed remediation or forensic costs, customer or revenue loss tied to an incident, insurance recovery adjustments, and litigation reserves or contingencies.
  • Qualitative signals: whether governance language names a specific board committee versus a vague "the board oversees risk," whether management expertise is described concretely (a named CISO with a security background) versus generically, and whether the tone reads proactive or purely defensive.

Statistic to watch: research on breached firms found that companies increase their disclosure of mitigation strategies after ransomware incidents, as detailed in a ransomware investigation case study based on 45 firms and over 6,000 cyber-related statements from 2018 to 2023. That pattern is your cue: a sudden jump in mitigation language often follows an incident rather than preceding one, which tells you the disclosure is reactive, not predictive.

Map what you find into scenario triggers. If a company discloses a material incident affecting a specific product line, model a revenue haircut scaled to that line's contribution. If Item 1C names a third-party vendor dependency without describing contingency plans, flag that as an unpriced tail risk rather than ignoring it because it isn't quantified yet.

Extraction Checklist: What to Pull From Every Filing

Building a repeatable process across your coverage list beats re-reading every filing from scratch each quarter. Here's the sequence that works:

  1. Check for Item 1.05 filings in the trailing 12 months and note the filing date relative to the incident date if disclosed.
  2. Parse Item 1C in the most recent 10-K for risk management process, board oversight structure, and management expertise language.
  3. Capture impact language verbatim, especially anything tying the incident to revenue, cost, or litigation exposure.
  4. Note governance statements, including whether a specific committee (audit, risk, or a dedicated cyber committee) is named.
  5. Flag vendor and supply-chain mentions, since third-party risk is explicitly part of Item 106 guidance.
  6. Record amendment history, since amended 8-Ks often add the substantive detail the original filing lacked.

A consistent extraction schema keeps this comparable across tickers. Useful fields include: filing_type, filing_date, impact_text, quantified_costs, vendors_mentioned, board_oversight_notes, management_expertise_notes, and amendment_timestamps. Standardizing these fields across your coverage list cuts down on the time you spend re-orienting yourself with each new filing.

Pro Tip: Sort your review queue by amended Item 1.05 filings first. An amendment usually means the company had to walk back or expand on an earlier statement, and that gap between the original and amended language is often more informative than either filing alone.

For a deeper walk-through of 8-K mechanics, FilingsIQ's guide to why companies file 8-K reports covers the procedural side, and the 10-K analysis guide walks through Item 1C alongside the rest of the annual report.

What Are the Warning Signs of Weak or Misleading Disclosure?

Some disclosures tell you what happened. Others tell you what a lawyer decided was safe to say. Learning to tell the difference is arguably the highest-value skill in this whole process.

Watch for these patterns:

  • Templated negative responses. Language identical or nearly identical to boilerplate used across dozens of other filers, with no company-specific detail.
  • Delayed or missing Item 1.05s when credible third-party reporting (news outlets, breach-tracking services) already describes an incident affecting the company.
  • Amendments that add real detail. If a follow-up filing suddenly quantifies impact the original filing didn't mention, that's a signal the first version understated materiality.
  • Mismatch between claimed maturity and history. A company describing a mature, board-supervised cyber program while also disclosing a material breach in the same fiscal year deserves a harder look.

Early filing analysis found that a substantial share of large filers used generic, templated language in their initial Item 106 disclosures, according to Dechert's review of the SEC's final rule and early filings. Combine that with the tendency toward reactive mitigation language noted earlier, and you get a pattern worth weighting heavily in position sizing: companies that ramp up cyber language only after trouble hits tend to have weaker underlying programs than their disclosures suggested a year earlier. For more detail on spotting these patterns, see FilingsIQ's guide to red flags in SEC filings.

Scaling the Process: Structured Data and AI-Assisted Review

Inline XBRL tagging on both Item 1.05 and Item 1C disclosures makes automated extraction and timeline tracking far more reliable than manually scanning PDFs. The SEC has said standardized, timely disclosure helps investors assess financial effects and reduces mispricing risk, which is exactly the gap structured tagging is meant to close.

A practical workflow looks like this:

  • Automated monitoring flags new or amended Item 1.05 and Item 1C filings across your coverage list.
  • An AI-generated summary surfaces the impact language, governance notes, and vendor mentions without requiring a full manual read on every ticker.
  • You extract those fields into your standing schema and verify the highest-impact claims manually before updating your model.
Workflow stageManual-only approachAI-assisted approach
Monitoring new filingsDaily manual EDGAR checksAutomated alerts on filing type
Summarizing Item 1C languageFull read of each 10-KAI summary flags key clauses
Red-flag detectionAnalyst judgment alonePattern-based flagging plus review

This workflow can be built into a per-ticker workspace, pairing AI summaries of Item 1.05 and Item 1C disclosures with automated red-flag detection, so structured tagging does the sorting and you spend your time on judgment calls, not page-turning.

A Practitioner's Look at the Analyst Workflow in Practice

The checklist matters less than the judgment calls sitting on top of it. Here's roughly how it plays out on a real coverage list: an Item 1.05 filing lands, and the first question isn't "how bad is this," it's "does the Item 1C from the last 10-K match this event, or contradict it?" If a company claimed a mature, board-supervised program six months ago and now discloses a material breach with vague scope language, that mismatch is the signal, not the breach itself.

A Practitioner's Look at the Analyst Workflow in Practice — overview diagram

From there, a downside scenario gets built around whatever quantified figures exist, remediation cost, customer impact, litigation exposure, and position sizing or engagement priorities shift accordingly. When disclosures are specific and consistent with prior program claims, that's usually sufficient to hold a position without escalation. When the language is generic and the history doesn't line up, that's when deeper diligence earns its cost.

The hardest part of this work isn't reading the filing. It's resisting the urge to treat silence as safety.

— Matthew

Get More From Every Filing With FilingsIQ

Some platforms are built for exactly the workflow this article describes: pulling Item 1.05 and Item 1C language out of dense filings and turning it into something you can act on in minutes instead of hours. Instead of manually re-reading each 10-K and 8-K for cyber risk language, AI-generated summaries can surface impact statements, governance notes, and vendor mentions automatically, alongside red-flag detection tuned to catch the boilerplate-versus-substance gap covered above.

Filingsiq

Each ticker gets its own workspace, so amendment history, prior disclosures, and your own notes stay attached to the company rather than scattered across spreadsheets. If you want to see the extraction and monitoring workflow applied to your own coverage list, start with FilingsIQ's platform or review how the product works before requesting a walkthrough. For a companion read on building disciplined filing habits, FilingsIQ's guide to SEC filing analysis best practices rounds out the workflow described here.

Sources

FAQ

What Is the Difference Between Item 1.05 and Item 1C Disclosures?

Item 1.05, filed on Form 8-K, discloses a specific material cybersecurity incident within four business days of the materiality determination. Item 1C, filed annually in the 10-K, describes the company's ongoing cyber risk management process and governance structure.

How Quickly Must a Company Disclose a Material Cyber Incident?

Companies must file within four business days of determining an incident is material, not four days from when the incident was discovered, per the SEC's final rule.

What Counts as a Material Cybersecurity Disclosure for Investors?

A disclosure is material if a reasonable investor would consider it important to the total mix of available information, the same standard applied across securities law.

How Can Analysts Spot Boilerplate Cybersecurity Disclosures?

Look for language that's identical to filings used across many other companies, absent quantified impacts, and inconsistent with the company's actual incident history; generic language was common among large filers in early Item 106 disclosures.

Can AI Tools Help Analyze Cybersecurity Disclosures Across a Portfolio?

Yes. Some AI platforms use technology to summarize Item 1.05 and Item 1C language and flag red flags automatically, cutting the time needed to identify decision-useful cyber risk signals across a coverage list.

Recommended

Ready to analyze filings faster?

Try FilingsIQ free and turn SEC filings into actionable research in minutes.