Original Research | | 14 min read
Corporate Cyber Disclosure Index: What 400 Public Companies Reveal
Key Takeaways
Cyber governance is widely disclosed. Cyber measurement is not.
93.1% disclosed
367 of 394 extracted Item 1C disclosures described qualifying board oversight.
Only 7.6% disclosed
Thirty filings described cyber metrics, indicators, measurable targets, or quantitative thresholds used or reported.
12.2 to 1
Board oversight appeared more than twelve times as often as metrics or thresholds in the sampled public record.
13 distinct cases
The linked census found 14 Item 1.05 filings covering 13 incidents through August 2026.
Public companies are very good at naming who oversees cyber risk. They are far less likely to disclose how that risk is measured.
GS Consulting analyzed a reproducible probability sample of 400 Nasdaq, NYSE, or CBOE listed domestic companies with a 2025 Form 10-K. We extracted substantive Item 1C cybersecurity disclosures from 394 filings. Qualifying board oversight appeared in 93.1 percent. Cyber metrics or thresholds appeared in only 7.6 percent.
That is a 12.2-to-1 disclosure gap. It does not prove that companies lack security metrics. It shows that the public record says far more about governance structure than about the measures used to recognize change, test assumptions, and support escalation.
This study extends the operating questions in our SOC automation guide and SOC Automation research hub. GS Consulting helps organizations connect cyber visibility, incident decisions, executive reporting, and measurable response through cyber situational awareness services.
Can your cyber evidence support the next executive decision?
GS Consulting helps security leaders assess visibility, metrics, escalation paths, incident workflows, and the evidence that connects them.
Request a Cyber Risk Fit CheckThe Corporate Cyber Disclosure Index: The Short Answer
The SEC disclosure framework has made cyber governance visible at scale. Most sampled filings named board oversight, management accountability, and a third party risk process. The same filings were much less likely to describe measurement, escalation, prior incidents, or a concrete change tied to the reporting period.
The useful conclusion is not that governance language is empty. Board and management accountability matter. The conclusion is that responsibility becomes more useful when leaders can see the thresholds, operating signals, and escalation evidence behind it.
The SEC cybersecurity disclosure rules require annual information about risk management, strategy, governance, board oversight, and management's role. They also require disclosure of material cybersecurity incidents on Item 1.05 of Form 8-K. This index measures what qualifying evidence appeared in the resulting public filing sections. It does not grade compliance.
What 394 Annual Cyber Disclosures Show
| Disclosure element | Qualifying filings | Estimated share | 95% confidence interval |
|---|---|---|---|
| Board oversight | 367 of 394 | 93.1% | 90.2%–95.2% |
| Management accountability | 348 of 394 | 88.3% | 84.8%–91.1% |
| Third party risk process | 345 of 394 | 87.6% | 83.9%–90.5% |
| Enterprise risk integration | 243 of 394 | 61.7% | 56.8%–66.3% |
| Independent assessment | 215 of 394 | 54.6% | 49.6%–59.4% |
| Exercises and continuity | 180 of 394 | 45.7% | 40.8%–50.6% |
| Materiality and escalation | 128 of 394 | 32.5% | 28.1%–37.3% |
| Prior incidents | 110 of 394 | 27.9% | 23.7%–32.5% |
| Metrics and thresholds | 30 of 394 | 7.6% | 5.4%–10.7% |
| Changes tied to reporting period | 2 of 394 | 0.5% | 0.1%–1.8% |
These are estimates of disclosure prevalence among the study population. They do not estimate whether a practice exists or works effectively.
Why the Governance and Measurement Gap Matters
A named owner explains responsibility. A metric explains what the owner watches. A threshold explains when the organization changes posture. An escalation process explains how a security condition becomes a business decision.
When those links are weak, dashboards can become activity reports. Boards see counts without decision context. Security teams track alerts that do not connect to risk. Incident leaders debate materiality after the facts arrive. Vendors report service volume without showing whether exposure changed.
The index cannot tell us whether those weaknesses exist inside any sampled company. It does show that the public disclosure layer rarely makes the measurement system visible. That creates five useful questions for directors and executives:
- What changed? Which measures show that exposure, control performance, resilience, or response readiness moved?
- What threshold matters? Which conditions trigger investigation, escalation, executive review, or a materiality process?
- Who owns the decision? Which role can accept risk, order containment, fund remediation, or approve external communication?
- What evidence survives? Can the organization reconstruct the source facts, analysis, decision, action, and result?
- What closes the loop? Do exercises, incidents, assessments, and third party findings change controls and operating priorities?
What 13 Material Incident Disclosures Show
The same company population produced 14 Item 1.05 filings covering 13 distinct incidents from January through August 2026. One incident had both an initial filing and an amendment. The table below uses the latest filing for each incident.
| Information addressed in latest filing | Distinct incidents | Share |
|---|---|---|
| Operational impact addressed | 13 of 13 | 100.0% |
| Data impact addressed | 12 of 13 | 92.3% |
| Containment or recovery addressed | 11 of 13 | 84.6% |
| Financial impact addressed | 11 of 13 | 84.6% |
| Third party involvement | 10 of 13 | 76.9% |
| Stakeholder impact addressed | 7 of 13 | 53.8% |
The incident corpus is small, so these are descriptive counts rather than population estimates. The categories record whether a filing addressed the information. For example, financial impact includes language saying no material financial effect is expected. It does not mean a loss occurred.
What the filing dates can and cannot tell us
Only five distinct incidents supplied dates the parser could use for both discovery and materiality determination. Their median elapsed time was three calendar days, with a range of two to 21 days. Seven supplied both a materiality date and filing date. Their median was four calendar days.
Those values are descriptive. The SEC filing clock generally begins when the company determines that an incident is material, not automatically when the incident is discovered. Calendar day calculations in this research are not a determination that a company did or did not meet a business day deadline.
Unauthorized AI Has Entered the Material Cyber Record
CB Financial Services disclosed that its bank subsidiary became aware of nonpublic customer information handled through an unauthorized AI based software application. The filing said the incident did not disrupt customer access, payment systems, operations, or core IT infrastructure. The company determined the event was material because of the volume and sensitivity of the information.
One filing cannot establish how common this is. It does establish something important: shadow AI is no longer only an acceptable use problem. It can become a data handling, incident response, regulatory communication, and public disclosure problem.
Organizations adopting AI should connect tool approval, data classification, identity, monitoring, incident intake, legal review, and executive escalation before sensitive information reaches an unapproved application. Our secure AI automation services and AI incident response workflow guide show how to build those boundaries into the operating process.
Five Actions for Boards, CISOs, and Security Leaders
- Connect every governance role to measures. For each board committee, executive owner, and security leader, name the measures they receive, the decision each measure supports, and the threshold that changes action.
- Rehearse the materiality path. Map incident facts, legal and business inputs, decision authority, documentation, amendment handling, and communication. Test the path with incomplete and changing information.
- Measure third party exposure as an operating dependency. Track critical services, access, data, concentration, notification terms, detection coverage, and recovery options. A vendor inventory alone is not an operating picture.
- Turn assessments and exercises into tracked change. Link findings to owners, due dates, evidence, retest, residual risk, and executive visibility. Count verified closure, not just completed activity.
- Bring unauthorized AI into cyber operations. Give employees approved alternatives, monitor the right signals, define incident criteria, protect investigation data, and preserve the evidence needed for response and disclosure review.
This is where SOC automation and cyber threat detection should help. The goal is not a larger dashboard. The goal is faster, source linked evidence that supports triage, escalation, containment, recovery, and executive decisions. Our private AI cyber analysis automation case study shows how one controlled workflow connected analysis, structured records, human review, and operational delivery.
How GS Consulting Conducted the Research
The annual population includes 3,988 domestic companies associated with Nasdaq, NYSE, or CBOE in the SEC company ticker and exchange file that filed an unamended Form 10-K during calendar 2025. When a company filed more than one unamended Form 10-K, the latest filing defined the record.
GS Consulting selected 400 companies through a simple random sample without replacement implemented as a deterministic hash ranking of CIK values. The fixed seed was gs-corporate-cyber-v1. Across broad SIC sectors, the largest absolute difference between sample and population shares was 1.2 percentage points.
The collector used SEC quarterly EDGAR master indexes, the SEC company ticker and exchange file, SEC Submissions API records, and primary filing documents in the SEC archive. It extracted Item 1C from annual filings and Item 1.05 from incident filings. Extraction failures remained visible rather than being silently removed.
Versioned, Codex authored deterministic concept patterns classified the complete extracted sections. A balanced comparison sample tested the initial rules against the published concept specification across all 16 categories. All 371 comparison rows were resolved before the release audit marked the package publication ready.
This is reproducible classification and specification checking, not independent human validation. There was no second reviewer, adjudication process, or inter-rater agreement estimate. Independent human review is the next validation step before making stronger construct validity claims.
Research Sources, Selected Filings, and Limits
- SEC, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rules
- CB Financial Services, May 11, 2026 Item 1.05 filing
- 8x8, June 23, 2026 Item 1.05 filing
- iRhythm Holdings, June 15, 2026 Item 1.05 filing
- Navient, July 2, 2026 Item 1.05 filing
- Amgen, July 31, 2026 Item 1.05 filing
Interpretation limits: “Not found” means the method did not find qualifying language in the public section. More detailed disclosure does not necessarily mean stronger security. Less detailed disclosure does not prove that a company lacks the practice. Similar language is not evidence of shared controls, advisers, or effectiveness.
The incident frame contains incidents companies determined were material and disclosed under Item 1.05. It is not a census of cyber incidents. Amendments can add facts unavailable in an initial filing and remain distinguishable in the research data.
GS Consulting Original Research. The GS Corporate Cyber Disclosure Index measures qualifying public filing language using the documented method. It is not a cybersecurity maturity score, control effectiveness assessment, legal opinion, SEC compliance determination, incident severity score, investment recommendation, or regulatory finding.
Corporate Cyber Disclosure Index FAQ
What is the GS Corporate Cyber Disclosure Index?
It is GS Consulting original research measuring qualifying cybersecurity language in public SEC filings. The first release analyzes a probability sample of 400 major exchange domestic companies with 2025 Form 10-K filings and a linked census of Item 1.05 filings through August 31, 2026.
Does more cybersecurity disclosure mean a company has stronger security?
No. The index measures public evidence in filing disclosures. Detailed disclosure does not prove that a control works, and limited disclosure does not prove that a company lacks the practice.
How many public company cybersecurity disclosures were analyzed?
The annual population contained 3,988 Nasdaq, NYSE, or CBOE listed domestic companies with a 2025 Form 10-K. The study selected 400 companies through a deterministic probability sample and extracted a substantive Item 1C section from 394 filings.
How often did companies disclose cybersecurity metrics or thresholds?
Thirty of 394 extracted Item 1C disclosures, or an estimated 7.6 percent, described the use or reporting of cybersecurity metrics, indicators, measurable targets, or quantitative thresholds. The 95 percent confidence interval is 5.4 to 10.7 percent.
How many material cybersecurity incidents were in the study?
The incident census found 14 Item 1.05 filings covering 13 distinct incidents from January 1 through August 31, 2026. One incident had an initial filing and an amendment, so the descriptive category results use the latest filing for each incident.
Did the study identify a material cyber disclosure involving AI?
Yes. CB Financial Services disclosed an incident involving nonpublic customer information handled through an unauthorized AI based software application. One case does not establish prevalence, but it places unauthorized enterprise AI use in the material cyber disclosure record.
Was the classification independently human reviewed?
No. Published labels came from versioned, Codex authored deterministic concept patterns applied to complete extracted sections. The process is reproducible classification and specification checking, not independent human validation, and the release makes no inter-rater agreement claim.
The Bottom Line
Corporate cyber governance is visible. The measurement system behind it usually is not.
Boards and executives should not respond by asking for more reporting volume. They should ask which measures change a decision, which thresholds trigger escalation, who owns the response, and what evidence proves the loop closed.
Continue Reading
- SOC Automation: What to Automate First and What to Keep Human
- AI Cybersecurity Incident Response Workflows
- Measuring the ROI of Analyst Workflow Automation
- Building Audit Trails for Automated Workflows
- Private AI Cyber Analysis Automation Case Study
- Cyber Situational Awareness and Incident Response Workflows
Turn cyber reporting into decision evidence.
GS Consulting can assess the measures, thresholds, escalation paths, workflows, and technical visibility behind your cyber governance model.
Request a Cyber Risk Fit Check