BLOG

What Cyber Disclosure Obligations Mean for Your Board Right Now

Board cyber disclosure obligations: directors reviewing SEC, OSFI, and Canadian privacy breach-notification requirements at the board table.

By David Chernitzky, CEO, Armour Cybersecurity  ·  Serving organizations across North America  ·  Last updated August 2026

Quick Answer
Several regulatory frameworks now create explicit obligations around board-level cyber oversight and breach disclosure. The SEC requires public companies to disclose how their board oversees cyber risk and to report material incidents within four business days. Canadian financial and privacy regulations add escalating obligations of their own when a material incident occurs.The through-line is that materiality and disclosure are now board-level governance decisions, often made under time pressure and incomplete information. Boards that have not formalized their cyber governance and disclosure framework face decisions they are not prepared to make.

Key Takeaways

  • The SEC’s cybersecurity disclosure rules require public companies to disclose the board’s role in cyber risk oversight, including committee structure and reporting cadence, and management’s role and expertise in managing the risk. The SEC considered requiring disclosure of board cybersecurity expertise and deliberately dropped it from the final rule.
  • OSFI’s B-13 Technology and Cyber Risk Management guideline sets explicit expectations for the boards of federally regulated financial institutions, including board approval of cyber risk appetite and independent oversight of the technology and cyber risk function.
  • Quebec’s Law 25 requires organizations to notify the Commission d’acces a l’information and affected individuals when a confidentiality incident presents a risk of serious injury. The obligation is to act promptly, with diligence, and to keep a register of incidents; there is no fixed statutory number of hours.
  • Materiality, deciding whether a cyber incident is significant enough to require disclosure, is a board-level governance decision, not a technical one. Boards without a materiality framework are unprepared for the decision they will face under regulatory time pressure.
  • Active board engagement before an incident, an approved materiality framework, a tested disclosure playbook, and independent counsel, is the difference between a board that governs the disclosure process and one that reacts to it.

Board cyber disclosure obligations now sit at the center of cyber governance: multiple regulators expect the board itself, not just management, to own the decision about what gets disclosed and when. That expectation turns disclosure from a legal-team task into a governance discipline, and it is closely tied to the broader work of board cyber governance that boards are now held to.

By the Numbers4 business days. The SEC window to disclose a material cybersecurity incident on Form 8-K (Item 1.05) once it is determined material. Source: SEC final rule, 2023.24 hours. OSFI’s window for a federally regulated financial institution to report a material technology or cyber incident, shorter than the SEC’s. Source: OSFI incident reporting expectations.241 days. The average time to identify and contain a breach in 2025, which is why materiality decisions are so often made with the facts still incomplete. Source: IBM Cost of a Data Breach Report 2025.

Why Disclosure Has Become a Board-Level Issue

Cyber disclosure obligations historically sat with management: the legal team, the privacy officer, and the security function handled breach notification, and the board was informed after the fact. That posture is no longer adequate. Regulators in both the United States and Canada have moved to create explicit board-level accountability for cyber risk oversight, and short notification timelines create governance decisions that must be made at the board level, often under time pressure and incomplete information.

The shift reflects a broader view that cybersecurity has become material to investors, customers, and the public in a way that warrants the same governance formality as financial risk. A board that governs financial risk rigorously but treats cyber as a management matter is no longer consistent with the standard regulators and shareholders apply. The practical consequence: boards need to understand their specific disclosure obligations, have a framework for making materiality decisions, and be able to demonstrate they were actively engaged before an incident forced them to act.

The SEC Cybersecurity Disclosure Rules

The US Securities and Exchange Commission adopted its cybersecurity disclosure rules in 2023, with material-incident reporting compliance beginning in December 2023. The rules create two categories of obligation for public companies. The first is annual disclosure, in the proxy statement or annual report, of how the board oversees cybersecurity risk: which committee holds oversight responsibility, the reporting cadence, and how management keeps the board informed about material cyber risks and incidents, together with management’s own role and relevant expertise. The second is incident disclosure: a current report on Form 8-K (Item 1.05) within four business days of determining that a cybersecurity incident is material.

One point is widely misunderstood. The SEC’s original proposal would have required companies to disclose whether the board itself holds cybersecurity expertise, and the Commission deliberately dropped that requirement from the final rule, concluding that effective oversight does not depend on directors being technical experts and that the relevant expertise sits with management. So the annual disclosure describes the board’s oversight structure and management’s expertise, not a roster of technically expert directors. Both obligations still create direct board accountability: the board must be able to characterize its oversight structure accurately, and it must be able to make a materiality determination within a defined window, which requires both a governance framework and the information infrastructure to support it.

SEC cyber disclosure board timeline: a four-business-day clock from materiality determination to a Form 8-K filing, a board-level decision under time pressure.

OSFI B-13 and Canadian Federally Regulated Institutions

The Office of the Superintendent of Financial Institutions published its Technology and Cyber Risk Management guideline (B-13) with a compliance date of January 1, 2024. B-13 applies to all federally regulated financial institutions in Canada, including banks, trust and loan companies, insurers, and their branches. The guideline is organized into three domains: governance and risk management, technology operations and resilience, and cyber security. Third-party and outsourcing risk is addressed in a separate guideline, B-10, and is read alongside B-13 rather than being a fourth B-13 domain.

The governance and risk management domain creates the most direct board obligations. OSFI expects the board to approve the institution’s risk appetite for technology and cyber risk, to receive regular reporting on that risk from management, to provide independent oversight of how it is managed, and to ensure the institution has adequate resources and capabilities. Separately, OSFI expects federally regulated institutions to report a material technology or cyber incident to OSFI within 24 hours of becoming aware, making the governance response timeline even shorter than the SEC’s four-business-day window.

Canadian Privacy Legislation and Breach Notification

Canada’s federal private-sector privacy law, PIPEDA, remains in force. An earlier reform bill, C-27 (which would have enacted the Consumer Privacy Protection Act), died on the Order Paper when Parliament was prorogued in early 2025, and a successor, Bill C-36, was introduced in June 2026, but PIPEDA governs today. Under PIPEDA, organizations must notify the Office of the Privacy Commissioner and affected individuals when a breach of security safeguards creates a real risk of significant harm, and must do so as soon as feasible. Whether the harm threshold is met is a legal judgment the organization makes, typically with privacy counsel, and it carries board-level accountability when the breach is material.

Quebec’s Law 25 adds its own obligation, and it is often misstated. Law 25 requires organizations to notify the Commission d’acces a l’information and the affected individuals when a confidentiality incident presents a risk of serious injury, to do so promptly and with diligence, and to keep a register of confidentiality incidents. There is no fixed 72-hour deadline in Law 25; the 72-hour figure people cite comes from the European GDPR, not from Quebec law. What matters for governance is the same either way: a board that did not know about a material incident quickly, or whose governance record does not reflect active engagement with the disclosure decision, faces questions about the adequacy of its oversight.

Materiality: The Governance Decision Boards Must Be Ready to Make

The SEC rules require a materiality determination before the four-business-day incident clock starts. Materiality follows the general securities-law standard: information is material if there is a substantial likelihood a reasonable investor would consider it important in deciding whether to buy, sell, or hold. Applied to a cyber incident, the determination weighs the operational impact, the financial cost (remediation, business interruption, regulatory exposure), the nature of the data involved and the liability or reputational exposure it creates, and whether the incident affects the organization’s ability to conduct its business. Translating those factors into a defensible number is exactly the kind of cyber risk quantification work that belongs in front of the board before an incident, not during one.

Making the call accurately, under the pressure of an active incident, requires that the board set the framework in advance. What loss thresholds, operational impacts, and data categories trigger a presumption of materiality? Who decides, and by when? What information does the board need, and how does it get it during a live incident? Boards that work through this in advance, ideally with legal counsel and an independent cyber advisor, make the disclosure decision with confidence. Boards facing the question for the first time during an incident are at a serious disadvantage.

Where This Fits in Armour’s Services

Armour’s board advisory covers regulatory horizon scanning, disclosure preparedness, and materiality-framework development as part of the quarterly engagement. The advisor tracks upcoming regulatory changes relevant to the organization, prepares the board for the disclosure decisions it may face, and ensures the governance record reflects active, informed oversight, working alongside the advisory team that builds the underlying compliance posture.

What Active Board Engagement on Disclosure Requires

Boards that are actively engaged with cyber disclosure obligations before an incident share several characteristics. They have a written materiality framework, approved by the board, defining the thresholds and criteria for disclosure decisions. They have an incident response and disclosure playbook, reviewed and approved by the board, defining roles, timelines, and communication protocols. They have exercised that playbook through a tabletop scenario that included a disclosure-decision component. They have legal counsel engaged from the outset with a clear mandate on regulatory notification and shareholder disclosure. And they have an independent advisor who can provide an outside perspective on the disclosure decision when management’s account of the incident is the primary information source.

The Bottom Line

Cyber disclosure is now board work, governed by the clock and judged after the fact on whether the board was ready. The boards that come through an incident with their oversight record intact are the ones that built the materiality framework, the playbook, and the independent challenge before they needed them. If your board wants to be ready for the disclosure decision before an incident forces it, Armour’s board advisory services are built for exactly that preparation.

Across the 260+ organizations Armour serves in 52+ industries, the boards that handle a disclosure decision well are almost always the ones that built the materiality framework on a quiet afternoon months earlier. The ones that struggle are making the call for the first time, in the first hours of a live incident, with a regulatory clock running and half the facts still missing.

Frequently Asked Questions

What are our board’s cyber disclosure obligations, in plain terms?

They depend on where you operate and how you are regulated, but three sources dominate. If you are an SEC-registered public company, you must disclose how the board oversees cyber risk annually and report material incidents on an 8-K within four business days. If you are a federally regulated financial institution in Canada, OSFI’s B-13 expects board approval of cyber risk appetite and independent oversight, plus 24-hour incident reporting to OSFI. And any organization handling personal data faces breach-notification duties under PIPEDA (real risk of significant harm) and, in Quebec, Law 25 (risk of serious injury). In each case the board is expected to be engaged, not just informed after the fact.

Does the SEC cyber disclosure rule apply to Canadian companies listed on US exchanges?

Yes. Foreign private issuers listed on US exchanges are subject to modified versions of the SEC requirements. The specific form and timing differ from domestic issuers, but the substantive obligation to disclose material cybersecurity incidents and describe the board’s oversight of cyber risk applies. Canadian companies cross-listed in the US need to evaluate their obligations under both the SEC rules and applicable Canadian securities law, a task for counsel with cross-border securities expertise.

What is a materiality framework, and how does the board approve one?

It is a documented set of criteria, thresholds, and decision processes the board uses to evaluate whether a cyber incident requires disclosure under applicable securities or privacy law. It defines the information categories that trigger heightened scrutiny (personal data, financial data, critical-system access), the financial and operational thresholds that presume materiality, the process for escalating the determination to the board within the required window, and who is responsible for each step. The board approves it as a governance document, typically through the audit or risk committee, the same way it approves other governance policies.

What happens if we disclose a cyber incident and it turns out to be less serious than we thought?

Regulators generally treat good-faith disclosure under uncertain information more favorably than delayed or non-disclosure. The SEC framework recognizes that materiality determinations are made with incomplete information and allows amended filings as facts develop. What matters for the governance record is whether the board made the determination in a timely, structured way using the information available, not whether the first characterization was perfectly accurate. Disclosing promptly and updating as the picture clarifies is a stronger position than delaying to fully understand the incident first.

How do we document the board’s role in cyber oversight for SEC annual disclosure?

Describe the committee responsible for cyber oversight, the frequency and format of management’s reporting to it, the criteria for escalating incidents to the full board, and management’s role and relevant expertise. Because the SEC dropped the board cyber-expertise requirement, describing individual directors’ expertise is optional, not mandatory. The disclosure is supported by the governance record: committee minutes reflecting cyber briefings, charter provisions defining the cyber mandate, and documentation of board actions on cyber risk. A board whose record does not yet support its intended disclosure needs to build the record first, which means establishing the oversight structure and running it for at least one reporting period.

What should the board do if an incident occurs before we have a materiality framework in place?

Engage legal counsel immediately, and the independent cyber advisor if one is in place. Counsel guides the materiality assessment against the general securities-law standard. Document every step of the board’s engagement: the information received, the analysis, and the basis for the decision. Notify regulators within the required timeframes even if the determination is preliminary, noting that the investigation is ongoing. Afterward, use the experience to develop and formally approve a materiality framework so the next incident benefits from a pre-established process.

Leave the first comment