SEC Cybersecurity Disclosure Rules and AI-Discovered CVEs: What Public Companies Must Do
When a Glasswing CVE hits your systems, the four-day clock starts. Here is what your GC, CISO, and CFO need to know.

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
On December 18, 2023, the SEC's cybersecurity disclosure rules took effect, fundamentally changing how public companies handle cybersecurity incidents. The rules create two distinct obligations: a rapid incident disclosure requirement (Form 8-K Item 1.05, filed within four business days of a materiality determination) and an annual disclosure requirement covering cybersecurity risk management programs and governance (Regulation S-K Item 106). Project Glasswing, Anthropic's coordinated vulnerability disclosure program powered by Claude Mythos, has now generated more than 10,000 high- or critical-severity findings across 200-plus partner organizations. When a Glasswing CVD notification arrives describing a critical vulnerability in software embedded in a public company's core infrastructure, the general counsel, CISO, and CFO face a compressed decision window. This guide provides the complete framework for navigating that window.
The SEC Rules: What They Actually Require
The SEC's 2023 cybersecurity rules, codified at 17 CFR Parts 229 and 249, establish two distinct disclosure regimes for public companies. Item 1.05 of Form 8-K governs incident disclosure: when a company experiences a cybersecurity incident and determines it is material, the company must file an 8-K within four business days of that determination. The form requires disclosure of the nature, scope, and timing of the incident, and its material impact or reasonably likely material impact on the company.
Regulation S-K Item 106 governs annual disclosure: companies must describe their processes for assessing, identifying, and managing material risks from cybersecurity threats; their board oversight of cybersecurity risk; and whether any previously reported cybersecurity incidents have materially affected or are reasonably likely to materially affect the company.
Critically, Item 1.05 disclosure does not require disclosure of technical information that would impair remediation or assist threat actors. A company can satisfy the disclosure obligation while omitting the specific CVE identifier, the affected system architecture, or the patch timeline if disclosure of those details would provide material assistance to malicious actors.
Materiality Defined: The Test That Governs Everything
The SEC has not created a cybersecurity-specific definition of materiality. It applies the standard securities law test from Basic Inc. v. Levinson: information is material if there is a substantial likelihood that a reasonable investor would consider it important in making an investment decision, or if the information would have significantly altered the total mix of available information.
For cybersecurity incidents, the SEC's adopting release identifies several factors relevant to the materiality analysis: the scope of data compromised or potentially compromised; the disruption or degradation of business operations; the reputational harm; regulatory and litigation exposure; the company's ability to recover; and the financial impact, both direct costs and indirect effects on revenue.
The SEC explicitly rejected a bright-line financial threshold. A breach that exposes 50,000 customer records might be material for a healthcare company and immaterial for a large financial institution, depending on the regulatory context, the nature of the data, and the company's specific risk profile. Legal counsel and the CISO must conduct a facts-and-circumstances analysis each time.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
The CVD Notification Scenario: Where Glasswing Fits
Project Glasswing operates as a coordinated vulnerability disclosure program. When Claude Mythos identifies a vulnerability in a widely-deployed software component, Anthropic notifies the vendor through the CVD process. The vendor develops a patch. Both Anthropic and the vendor then notify affected organizations through standard CVD disclosure channels, typically with a fixed disclosure timeline (often 90 days) regardless of patch availability.
For a public company, receiving a Glasswing CVD notification has a different legal character than receiving a threat intelligence report or a CISA advisory. A CVD notification typically confirms that a specific, exploitable vulnerability exists in software the company uses, that the vulnerability has been independently discovered and analyzed, and that the analysis includes working proof-of-concept information held by the researcher.
This is relevant to materiality because CVD notifications narrow the uncertainty: the company knows a vulnerability exists, knows it is exploitable, and can assess whether its systems are affected. That assessment starts the materiality analysis clock, even if it does not start the four-day disclosure clock (which runs from the materiality determination, not from the vulnerability notification).
The wolfSSL CVE-2026-5194, with a CVSS score of 9.1, illustrates the stakes. wolfSSL is an embedded TLS library used across industrial controllers, medical devices, networking equipment, and payment processing terminals. A public company that operates any of those systems, receives a CVD notification about CVE-2026-5194, and then discovers active exploitation within its environment would face a compressed and high-stakes materiality determination process.
The Four-Day Clock: What Starts It and What Stops It
The four-day clock begins at the moment a company determines materiality, not when an incident first occurs, not when the company first learns of a vulnerability, and not when a CVD notification arrives. This sequencing matters because it creates a legally significant distinction between the notification event and the determination event.
The SEC has been clear that companies cannot manipulate this sequencing to delay disclosure. The Commission has stated it will examine whether a company's internal processes for making materiality determinations are designed in good faith or structured to create artificial delays. A policy that routes all cybersecurity materiality determinations through a six-week legal review process would likely invite SEC scrutiny.
Once the four-day clock starts, weekends and federal holidays do not stop it. Four business days means four days when the SEC is open for business. If a company makes its materiality determination on a Friday afternoon, the Form 8-K is due by the close of business on the following Thursday.
The DOJ exception is narrow: the SEC can delay an 8-K requirement if the Attorney General notifies the SEC in writing that immediate disclosure would present a substantial risk to national security or public safety. This exception was included at DOJ's request and is intended for situations where disclosure would expose an ongoing law enforcement operation. It is not a general carve-out for sensitive disclosures.
Who Needs to Be in the Room
The materiality determination for a cybersecurity incident cannot be made by the security team alone. The decision requires input from legal, finance, and executive leadership because materiality is inherently a business and legal judgment, not a technical one.
The CISO's role is to provide the technical facts: Is the vulnerability present in the company's systems? Is there evidence of exploitation? What data was accessible? What systems were affected? What is the remediation timeline? The CISO translates technical reality into a set of facts that non-technical decision-makers can evaluate.
The general counsel's role is to apply the materiality standard to those facts and assess collateral legal exposure: regulatory obligations, contractual notification requirements, potential litigation, and the adequacy of the proposed 8-K disclosure.
The CFO's role is to assess financial materiality: What are the direct costs of remediation? What is the potential revenue impact? What is the insurance situation? Are there contractual penalties for breach?
The board's role is governance oversight. Item 106 requires companies to describe how the board oversees cybersecurity risk. When a material incident occurs, boards should expect to be briefed before or contemporaneously with the 8-K filing, not after.
The Materiality Assessment Checklist
When a CVD notification arrives, the immediate response should trigger a structured materiality assessment. This checklist represents the minimum analysis required before the company can make a good-faith determination that an incident is or is not material.
First, confirm affected status: Is the named software component present in the company's systems? If so, what versions? Are those versions affected by the named vulnerability? This technical triage can typically be completed within hours using software asset management data and SBOM (software bill of materials) records.
Second, assess exploitation status: Is there evidence the vulnerability has been exploited against the company's specific systems? Glasswing CVD notifications typically include indicators of compromise and exploitation signatures. Check SIEM logs, EDR telemetry, and network flow data against those indicators.
Third, evaluate data exposure: If exploitation occurred, what data was accessible to the threat actor? Customer PII, financial records, health information, trade secrets, and regulated data each carry distinct notification obligations beyond the SEC rules.
Fourth, assess operational impact: Has the incident caused or is it likely to cause disruption to business operations? Quantify downtime, revenue impact, and recovery timeline.
Fifth, evaluate remediation availability: Is a patch available? Can it be applied immediately? If not, what compensating controls are available?
Sixth, consider investor perspective: Would a reasonable investor finding this information decide differently about the company's stock? If the answer is plausibly yes, materiality is likely.
Form 8-K Item 1.05: What the Disclosure Must Say
Form 8-K Item 1.05 requires disclosure of the material aspects of the nature, scope, and timing of the cybersecurity incident, and its material impact or reasonably likely material impact on the company, including on its financial condition and results of operations.
A compliant disclosure addresses: when the incident was detected and when the company determined it was material; the nature of the incident (unauthorized access, data exfiltration, ransomware, exploitation of a vulnerability); the scope of affected systems and data; the status of remediation; and the expected financial or operational impact.
An example disclosure structure for a Glasswing CVD scenario might read: 'On [date], the Company received a coordinated vulnerability disclosure notification describing a critical vulnerability (CVSS 9.1) in [software component] used in [general system description]. Upon investigation, the Company determined that the vulnerability had been exploited by an unauthorized party who accessed [data category] for approximately [timeframe]. The Company has engaged [incident response firm] and implemented [remediation measures]. The Company has not yet determined the full financial impact of the incident but expects to incur material costs related to investigation, remediation, notification, and potential regulatory proceedings.'
The key is accuracy, not completeness. You are not required to disclose every technical detail, but what you do disclose must be accurate and not misleading. The SEC takes a dim view of disclosures that technically comply while materially understating the incident.
Annual Disclosure Obligations Under Regulation S-K Item 106
Beyond the incident-triggered Form 8-K, Regulation S-K Item 106 requires annual disclosure of the company's cybersecurity risk management program. This disclosure, which appears in the annual report (Form 10-K), must describe how the company assesses, identifies, and manages material risks from cybersecurity threats; whether and how the company engages third parties in assessing and managing those risks; how cybersecurity risks are integrated into the company's overall risk management framework; and whether any previously reported cybersecurity incidents have had or are reasonably likely to have a material impact.
Item 106(b) specifically requires disclosure of board oversight of cybersecurity risk: which board committee or full board oversees cybersecurity risk, and how the board or committee is informed about and monitors cybersecurity risks.
For companies that receive Glasswing CVD notifications, the annual disclosure presents an opportunity to describe the company's external threat intelligence program and how it integrates AI-powered vulnerability discovery into the risk management process. A company that can credibly describe an AI-augmented vulnerability management program that includes CVD notification intake, rapid materiality assessment capability, and documented remediation SLAs is presenting a stronger risk management narrative to investors than a company that does not.
What Happens If You Miss the Deadline
The SEC has both civil and criminal enforcement tools available for disclosure violations. Civil penalties for late Form 8-K filing can reach tens of thousands of dollars per day, though the SEC typically focuses its enforcement resources on cases involving deliberate delay or misleading disclosure rather than minor technical lateness.
The more significant exposure is not the SEC penalty itself but the securities litigation that follows. A company that files a late 8-K or that files a 8-K later found to be materially misleading faces significant exposure to class action securities fraud litigation under Section 10(b) of the Securities Exchange Act and Rule 10b-5. The SolarWinds litigation, in which the SEC charged both the company and its CISO individually, demonstrates that cybersecurity disclosure failures can generate personal liability for senior officers.
State regulators add another layer: many state attorneys general have cybersecurity disclosure and data breach notification laws that may impose shorter deadlines or different materiality thresholds than the SEC rules. A company operating in multiple states must manage compliance with both the federal SEC rules and applicable state law.
The practical message is simple: build the materiality assessment process before a CVD notification arrives, not after. Companies that have pre-established processes, documented decision frameworks, and clear escalation paths are better positioned to make timely, accurate disclosures than companies that build the process during the incident.
Full Materiality Assessment Framework and Disclosure Drafting Guide
The Mythos Brief provides the complete, practitioner-ready toolkit for SEC cybersecurity disclosure compliance in the AI vulnerability era. Subscribers receive step-by-step resources that compress the assessment and drafting process into a defensible, repeatable workflow.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The bottom line
The SEC's 2023 cybersecurity disclosure rules were designed for the era of AI-powered threat discovery. When a Glasswing CVE notification arrives, the materiality clock is running even before the four-day disclosure clock formally starts. Public companies that lack a pre-built materiality assessment process face compressing that decision under incident-response pressure, which is precisely the condition that produces disclosure errors. Build the process now, brief the board, and assign the decision-making authority before the next CVD notification lands. For the complete materiality assessment framework, disclosure templates, and board briefing toolkit, access the Mythos Brief at decryptiondigest.com/mythos-brief.
Frequently asked questions
Does receiving a Glasswing CVD notification trigger SEC disclosure?
Receiving a coordinated vulnerability disclosure notification does not by itself trigger the four-day Form 8-K clock. The clock starts only after your company determines that a cybersecurity incident is material. A CVD notification describing a vulnerability in software you use is a starting point for a materiality assessment, not a materiality determination. If your investigation concludes the vulnerability has been exploited against your systems and the incident is material, disclosure is required within four business days of that conclusion.
What is the four-day clock under SEC rules?
Under Item 1.05 of Form 8-K, a public company must file a report within four business days of determining that a cybersecurity incident is material. The clock begins at the moment the company makes a materiality determination, not at the moment of discovery, not at the moment a CVD notification is received, and not when the incident first occurred. The SEC has stated it will scrutinize whether companies delayed their materiality determinations to avoid or delay disclosure.
What does 'material' mean for a cybersecurity vulnerability?
The SEC applies the standard materiality test from Basic Inc. v. Levinson: information is material if there is a substantial likelihood that a reasonable investor would consider it important. For cybersecurity, this means assessing whether the incident is reasonably likely to have a material impact on financial condition, results of operations, or reputation. Factors include: the scope of data compromised, operational disruption, potential regulatory penalties, litigation exposure, and whether the vulnerability has been actively exploited. A high-CVSS vulnerability in a core system that processes customer payment data would warrant serious materiality analysis.
Do we need to disclose a patch before it is applied?
Yes, if the incident is material, the four-day disclosure obligation is not contingent on remediation. You must file the Form 8-K within four business days of the materiality determination even if the patch has not yet been applied. The SEC allows a limited exception when the Department of Justice determines that disclosure would pose a substantial risk to national security or public safety, but this is narrow and requires active DOJ coordination. You may omit technical specifics that would assist threat actors while still meeting the disclosure obligation.
What are the penalties for late disclosure?
The SEC can bring enforcement actions for failure to timely file Form 8-K, including civil monetary penalties. The SEC has demonstrated willingness to penalize companies for cybersecurity disclosure failures: in 2023, the SEC charged SolarWinds and its CISO with fraud and disclosure failures. Beyond SEC penalties, late disclosure can trigger securities class action litigation, state attorney general investigations, and reputational damage with investors. Directors and officers may face personal liability if they knew of materiality and delayed disclosure.
How should a public company structure its internal materiality assessment process to withstand SEC scrutiny?
The SEC will examine whether a materiality assessment process is designed in good faith or engineered to create artificial delays. A defensible process documents the start time of the assessment (when the incident or CVD notification was received), names the individuals responsible for each assessment step, sets internal SLAs for completing the technical triage and legal analysis within two to three business days of notification, and requires a documented decision with a rationale signed by the general counsel or a designated legal officer. Assessment meetings should be calendared immediately upon receiving a CVD notification rather than waiting for a scheduled security review cycle. The process should include a parallel track: legal is drafting the disclosure while technical is completing the exploitation assessment, so that if materiality is determined, the four-day clock does not restart the drafting process from zero. Tabletop exercises simulating a Glasswing CVE scenario, run at least annually with the GC, CISO, and CFO, demonstrate to regulators that the organization's process is pre-built and practiced rather than improvised.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
