BLUF: Board level cybersecurity reporting has become dramatically more structured over the past six years. Nearly every large public company now has a defined reporting cadence and a named accountable executive. What most of those structures still lack is a pre-agreed answer to a narrower question: what happens automatically the moment a metric crosses a line. SEC disclosure data from the past two years shows that even under a hard legal deadline, that answer gets worked out in the moment, under pressure, company by company. Boards run the same informal process internally, every reporting cycle, usually without noticing.
The Same Rule, Three Different Timelines
Since December 2023, the SEC has required public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality (Item 1.05). The clock is identical for every filer. What varies enormously is how long it takes a company to reach that determination in the first place.
UnitedHealth Group reached a materiality determination in one day following the Change Healthcare ransomware attack. Halliburton took two days after its 2024 ransomware incident. AT&T took 84 days following its 2024 Snowflake linked breach, invoking a rare national security delay along the way.
Same rule. Same four business day clock once the determination is made. An 84 day gap in how quickly three different companies decided the determination itself needed to happen.
That gap isn’t a metrics problem. None of these companies lacked visibility into what had happened. It’s a question of authority and process: who is empowered to call something material, how fast, and against what pre-agreed criteria, versus figuring it out live, with legal counsel and communications teams working the question in real time.
The same discretion shows up further downstream. After the SEC’s May 2024 clarification that Item 1.05 should be reserved for confirmed material incidents, tracking by Debevoise & Plimpton finds that as of May 2026, 29 companies had filed under the mandatory material incident item since that clarification, while 50 had filed under the softer, non-material Item 8.01. Even with explicit guidance narrowing when the material item applies, most companies still land in the ambiguous bucket.
That’s the system working the same way boards’ internal metrics programs work: a number crosses a line, and someone decides, in the moment, whether it counts.
Reporting Structure Has Genuinely Improved
To be fair to boards, actual reporting structure has matured substantially. Comparing Fortune 100 disclosures from 2019 to 2025, board level committee oversight of cybersecurity is now disclosed by 96 percent of companies, up from 81 percent. Explicit reporting frequency language appears in 99 percent of disclosures now, up from 44 percent. Nearly all Fortune 100 companies (100 percent) now describe how management reports cybersecurity matters to the board, up from 57 percent, and 89 percent identify a specific accountable executive, typically a CISO or CIO, up from just 27 percent six years earlier.
NACD’s own Director’s Handbook recommends standardizing cyber risk reporting on the same cadence, language, and structure used for other enterprise risks, and most large companies have visibly moved in that direction. Cybersecurity oversight has gone from an informal, ad hoc board topic to a formalized, named, cadenced one in a remarkably short window. That’s real progress, and it’s worth naming as such before pointing at what’s missing.
Structure Without a Working Relationship
What hasn’t moved as much is what sits behind the structure. NACD’s 2025 board practices survey found that 37 percent of public company directors, and 40 percent of private company directors, still consider improving the board’s relationship with its CISO an important or very important priority. That’s not a small minority, years after CISO reporting became close to universal on paper.
A dashboard with a named presenter doesn’t guarantee a working relationship between the person delivering the numbers and the people deciding what to do about them. Structure defines what gets reported. It says very little about what happens after the number lands.
What Actually Reduces Risk: Pre-Agreed Thresholds, Not Better Metrics
Most cybersecurity metrics conversations focus on which numbers to track: mean time to detect, patch cadence, phishing click rates, whichever KPI is in favor this year. That conversation matters less than it seems to. A well chosen metric with no pre-agreed action threshold behind it is just another data point in a deck. Someone still has to decide, live, whether this quarter’s number is a shrug or an emergency.
The variance in SEC materiality determination speed shows what that live decision looks like when the stakes are highest and legal deadlines are attached. UnitedHealth and Halliburton had processes that let them decide quickly. AT&T’s 84 day span points to a slower, more deliberative internal path (understandable given the case’s complexity and the invoked national security delay, but instructive regardless of the reason).
Johnson Controls’ March 2026 incident illustrates a second version of the same problem. The stock barely moved the day after disclosure: about a quarter point decline. Investors reading the initial 8-K had little signal that anything serious was underway. The real impact showed up a quarter later: Q1 2026 revenue missed consensus by roughly 4.4 percent and adjusted earnings per share came in about 8.5 percent below the prior year, both explicitly tied to the incident. The initial disclosure and the eventual financial reality were disconnected in time, not because anyone hid anything, but because nothing in the reporting structure was built to flag “this will show up in the numbers later” as distinct from “this is contained.”
Neither of these is a story about the wrong metric being chosen. They’re stories about organizations without a pre-committed answer to a specific question: at what point does this get escalated, to whom, with what authority to act, without waiting for the next scheduled board meeting or the next quarter’s numbers to force the issue.
What a Working Structure Adds
NACD’s own guidance points toward the right shape: standardized reporting aligned to the same enterprise risk management process used for other material risks, quantified in financial terms rather than purely technical language, and reviewed on a consistent cadence with year over year comparability. Most large companies have adopted this framing at the format level.
The piece worth adding on top of that structure is explicit and specific: a named role with pre-authorized power to act when a defined threshold is crossed, and a documented trigger, rather than a general instruction to flag anything concerning. Concerning is a judgment call made after the fact. A threshold is a decision made in advance, while everyone involved is still calm.
What This Means for Business Leaders
- Audit your current board reporting against what happens automatically when a metric crosses a defined line, not just which metrics show up in the deck
- Confirm the named accountable role, typically the CISO or equivalent, has pre-authorized authority to act at defined thresholds, not simply visibility into the numbers after the fact
- Document materiality and escalation triggers in advance, the way the SEC’s four business day clock forces a deadline, rather than deciding them live under pressure
- Revisit the board-CISO relationship directly rather than assuming a reporting cadence on paper has already resolved it
Reporting structure will likely keep maturing on its own, driven by disclosure rules, activist investors, and peer pressure inside industries where a competitor’s incident makes the next one look inevitable rather than surprising. Decision latency won’t fix itself the same way. It’s the one piece of this system still fully within a leadership team’s control, and the piece the last six years of progress have mostly left untouched.
References
- NACD, “Cybersecurity Oversight Disclosures: 10 Questions for Boards,” 2026 Director’s Handbook on Cyber-Risk Oversight. nacdonline.org
- NACD, “Building a Relationship Between the Board and CISO,” 2026 Director’s Handbook on Cyber-Risk Oversight. nacdonline.org
- NACD, “Principle Five: Guide Cybersecurity Risk Measurement and Reporting,” 2026 Director’s Handbook on Cyber-Risk Oversight. nacdonline.org
- Debevoise & Plimpton, “Cybersecurity Incident Disclosure: Form 8-K Tracker (Two-Year Update),” May 2026. debevoisedatablog.com
- Cherry Hill Advisory, “SEC Cybersecurity Disclosure Rule: Two Years of 8-K Filings (2026 Review),” June 3, 2026. cherryhilladvisory.com

