Original Research | | 14 min read

Corporate Cyber Disclosure Index: What 400 Public Companies Reveal


Cybersecurity data display representing public company risk oversight, measurement, and incident disclosure
Photo by Adi Goldstein on Unsplash

Key Takeaways

Cyber governance is widely disclosed. Cyber measurement is not.

Board oversight

93.1% disclosed

367 of 394 extracted Item 1C disclosures described qualifying board oversight.

Metrics and thresholds

Only 7.6% disclosed

Thirty filings described cyber metrics, indicators, measurable targets, or quantitative thresholds used or reported.

Disclosure gap

12.2 to 1

Board oversight appeared more than twelve times as often as metrics or thresholds in the sampled public record.

Material incidents

13 distinct cases

The linked census found 14 Item 1.05 filings covering 13 incidents through August 2026.

Public companies are very good at naming who oversees cyber risk. They are far less likely to disclose how that risk is measured.

GS Consulting analyzed a reproducible probability sample of 400 Nasdaq, NYSE, or CBOE listed domestic companies with a 2025 Form 10-K. We extracted substantive Item 1C cybersecurity disclosures from 394 filings. Qualifying board oversight appeared in 93.1 percent. Cyber metrics or thresholds appeared in only 7.6 percent.

That is a 12.2-to-1 disclosure gap. It does not prove that companies lack security metrics. It shows that the public record says far more about governance structure than about the measures used to recognize change, test assumptions, and support escalation.

This study extends the operating questions in our SOC automation guide and SOC Automation research hub. GS Consulting helps organizations connect cyber visibility, incident decisions, executive reporting, and measurable response through cyber situational awareness services.

Can your cyber evidence support the next executive decision?

GS Consulting helps security leaders assess visibility, metrics, escalation paths, incident workflows, and the evidence that connects them.

Request a Cyber Risk Fit Check
Board oversight appeared in 93.1 percent of sampled disclosures, materiality and escalation in 32.5 percent, and cyber metrics or thresholds in 7.6 percent
Figure 1. Public cyber disclosure is much stronger on oversight than on measurement. Open the figure for a full size view.

The Corporate Cyber Disclosure Index: The Short Answer

The SEC disclosure framework has made cyber governance visible at scale. Most sampled filings named board oversight, management accountability, and a third party risk process. The same filings were much less likely to describe measurement, escalation, prior incidents, or a concrete change tied to the reporting period.

The useful conclusion is not that governance language is empty. Board and management accountability matter. The conclusion is that responsibility becomes more useful when leaders can see the thresholds, operating signals, and escalation evidence behind it.

The SEC cybersecurity disclosure rules require annual information about risk management, strategy, governance, board oversight, and management's role. They also require disclosure of material cybersecurity incidents on Item 1.05 of Form 8-K. This index measures what qualifying evidence appeared in the resulting public filing sections. It does not grade compliance.

What 394 Annual Cyber Disclosures Show

Disclosure elementQualifying filingsEstimated share95% confidence interval
Board oversight367 of 39493.1%90.2%–95.2%
Management accountability348 of 39488.3%84.8%–91.1%
Third party risk process345 of 39487.6%83.9%–90.5%
Enterprise risk integration243 of 39461.7%56.8%–66.3%
Independent assessment215 of 39454.6%49.6%–59.4%
Exercises and continuity180 of 39445.7%40.8%–50.6%
Materiality and escalation128 of 39432.5%28.1%–37.3%
Prior incidents110 of 39427.9%23.7%–32.5%
Metrics and thresholds30 of 3947.6%5.4%–10.7%
Changes tied to reporting period2 of 3940.5%0.1%–1.8%

These are estimates of disclosure prevalence among the study population. They do not estimate whether a practice exists or works effectively.

Ten annual corporate cybersecurity disclosure elements ranked by estimated prevalence, from board oversight at 93.1 percent to reporting period changes at 0.5 percent
Figure 2. Governance roles and third party risk processes dominate the sampled Item 1C disclosures. Open the figure for a full size view.

Why the Governance and Measurement Gap Matters

A named owner explains responsibility. A metric explains what the owner watches. A threshold explains when the organization changes posture. An escalation process explains how a security condition becomes a business decision.

When those links are weak, dashboards can become activity reports. Boards see counts without decision context. Security teams track alerts that do not connect to risk. Incident leaders debate materiality after the facts arrive. Vendors report service volume without showing whether exposure changed.

The index cannot tell us whether those weaknesses exist inside any sampled company. It does show that the public disclosure layer rarely makes the measurement system visible. That creates five useful questions for directors and executives:

  • What changed? Which measures show that exposure, control performance, resilience, or response readiness moved?
  • What threshold matters? Which conditions trigger investigation, escalation, executive review, or a materiality process?
  • Who owns the decision? Which role can accept risk, order containment, fund remediation, or approve external communication?
  • What evidence survives? Can the organization reconstruct the source facts, analysis, decision, action, and result?
  • What closes the loop? Do exercises, incidents, assessments, and third party findings change controls and operating priorities?

What 13 Material Incident Disclosures Show

The same company population produced 14 Item 1.05 filings covering 13 distinct incidents from January through August 2026. One incident had both an initial filing and an amendment. The table below uses the latest filing for each incident.

Information addressed in latest filingDistinct incidentsShare
Operational impact addressed13 of 13100.0%
Data impact addressed12 of 1392.3%
Containment or recovery addressed11 of 1384.6%
Financial impact addressed11 of 1384.6%
Third party involvement10 of 1376.9%
Stakeholder impact addressed7 of 1353.8%

The incident corpus is small, so these are descriptive counts rather than population estimates. The categories record whether a filing addressed the information. For example, financial impact includes language saying no material financial effect is expected. It does not mean a loss occurred.

Six information categories addressed in the latest filings for 13 distinct material cybersecurity incidents
Figure 3. Material incident filings commonly address operations, data, recovery, financial effects, and third party involvement.

What the filing dates can and cannot tell us

Only five distinct incidents supplied dates the parser could use for both discovery and materiality determination. Their median elapsed time was three calendar days, with a range of two to 21 days. Seven supplied both a materiality date and filing date. Their median was four calendar days.

Those values are descriptive. The SEC filing clock generally begins when the company determines that an incident is material, not automatically when the incident is discovered. Calendar day calculations in this research are not a determination that a company did or did not meet a business day deadline.

Unauthorized AI Has Entered the Material Cyber Record

CB Financial Services disclosed that its bank subsidiary became aware of nonpublic customer information handled through an unauthorized AI based software application. The filing said the incident did not disrupt customer access, payment systems, operations, or core IT infrastructure. The company determined the event was material because of the volume and sensitivity of the information.

One filing cannot establish how common this is. It does establish something important: shadow AI is no longer only an acceptable use problem. It can become a data handling, incident response, regulatory communication, and public disclosure problem.

Organizations adopting AI should connect tool approval, data classification, identity, monitoring, incident intake, legal review, and executive escalation before sensitive information reaches an unapproved application. Our secure AI automation services and AI incident response workflow guide show how to build those boundaries into the operating process.

Five Actions for Boards, CISOs, and Security Leaders

  1. Connect every governance role to measures. For each board committee, executive owner, and security leader, name the measures they receive, the decision each measure supports, and the threshold that changes action.
  2. Rehearse the materiality path. Map incident facts, legal and business inputs, decision authority, documentation, amendment handling, and communication. Test the path with incomplete and changing information.
  3. Measure third party exposure as an operating dependency. Track critical services, access, data, concentration, notification terms, detection coverage, and recovery options. A vendor inventory alone is not an operating picture.
  4. Turn assessments and exercises into tracked change. Link findings to owners, due dates, evidence, retest, residual risk, and executive visibility. Count verified closure, not just completed activity.
  5. Bring unauthorized AI into cyber operations. Give employees approved alternatives, monitor the right signals, define incident criteria, protect investigation data, and preserve the evidence needed for response and disclosure review.

This is where SOC automation and cyber threat detection should help. The goal is not a larger dashboard. The goal is faster, source linked evidence that supports triage, escalation, containment, recovery, and executive decisions. Our private AI cyber analysis automation case study shows how one controlled workflow connected analysis, structured records, human review, and operational delivery.

How GS Consulting Conducted the Research

The annual population includes 3,988 domestic companies associated with Nasdaq, NYSE, or CBOE in the SEC company ticker and exchange file that filed an unamended Form 10-K during calendar 2025. When a company filed more than one unamended Form 10-K, the latest filing defined the record.

GS Consulting selected 400 companies through a simple random sample without replacement implemented as a deterministic hash ranking of CIK values. The fixed seed was gs-corporate-cyber-v1. Across broad SIC sectors, the largest absolute difference between sample and population shares was 1.2 percentage points.

The collector used SEC quarterly EDGAR master indexes, the SEC company ticker and exchange file, SEC Submissions API records, and primary filing documents in the SEC archive. It extracted Item 1C from annual filings and Item 1.05 from incident filings. Extraction failures remained visible rather than being silently removed.

Versioned, Codex authored deterministic concept patterns classified the complete extracted sections. A balanced comparison sample tested the initial rules against the published concept specification across all 16 categories. All 371 comparison rows were resolved before the release audit marked the package publication ready.

This is reproducible classification and specification checking, not independent human validation. There was no second reviewer, adjudication process, or inter-rater agreement estimate. Independent human review is the next validation step before making stronger construct validity claims.

Research Sources, Selected Filings, and Limits

Interpretation limits: “Not found” means the method did not find qualifying language in the public section. More detailed disclosure does not necessarily mean stronger security. Less detailed disclosure does not prove that a company lacks the practice. Similar language is not evidence of shared controls, advisers, or effectiveness.

The incident frame contains incidents companies determined were material and disclosed under Item 1.05. It is not a census of cyber incidents. Amendments can add facts unavailable in an initial filing and remain distinguishable in the research data.

GS Consulting Original Research. The GS Corporate Cyber Disclosure Index measures qualifying public filing language using the documented method. It is not a cybersecurity maturity score, control effectiveness assessment, legal opinion, SEC compliance determination, incident severity score, investment recommendation, or regulatory finding.

Corporate Cyber Disclosure Index FAQ

What is the GS Corporate Cyber Disclosure Index?

It is GS Consulting original research measuring qualifying cybersecurity language in public SEC filings. The first release analyzes a probability sample of 400 major exchange domestic companies with 2025 Form 10-K filings and a linked census of Item 1.05 filings through August 31, 2026.

Does more cybersecurity disclosure mean a company has stronger security?

No. The index measures public evidence in filing disclosures. Detailed disclosure does not prove that a control works, and limited disclosure does not prove that a company lacks the practice.

How many public company cybersecurity disclosures were analyzed?

The annual population contained 3,988 Nasdaq, NYSE, or CBOE listed domestic companies with a 2025 Form 10-K. The study selected 400 companies through a deterministic probability sample and extracted a substantive Item 1C section from 394 filings.

How often did companies disclose cybersecurity metrics or thresholds?

Thirty of 394 extracted Item 1C disclosures, or an estimated 7.6 percent, described the use or reporting of cybersecurity metrics, indicators, measurable targets, or quantitative thresholds. The 95 percent confidence interval is 5.4 to 10.7 percent.

How many material cybersecurity incidents were in the study?

The incident census found 14 Item 1.05 filings covering 13 distinct incidents from January 1 through August 31, 2026. One incident had an initial filing and an amendment, so the descriptive category results use the latest filing for each incident.

Did the study identify a material cyber disclosure involving AI?

Yes. CB Financial Services disclosed an incident involving nonpublic customer information handled through an unauthorized AI based software application. One case does not establish prevalence, but it places unauthorized enterprise AI use in the material cyber disclosure record.

Was the classification independently human reviewed?

No. Published labels came from versioned, Codex authored deterministic concept patterns applied to complete extracted sections. The process is reproducible classification and specification checking, not independent human validation, and the release makes no inter-rater agreement claim.

The Bottom Line

Corporate cyber governance is visible. The measurement system behind it usually is not.

Boards and executives should not respond by asking for more reporting volume. They should ask which measures change a decision, which thresholds trigger escalation, who owns the response, and what evidence proves the loop closed.

Continue Reading

Turn cyber reporting into decision evidence.

GS Consulting can assess the measures, thresholds, escalation paths, workflows, and technical visibility behind your cyber governance model.

Request a Cyber Risk Fit Check

© GS Consulting, LLC . All Rights Reserved | For more information, contact us at info@gsconsultingllc.com. Image credit: ©iStock.com/Vertigo3d. Privacy Policy | Terms of Use