Breach disclosure: when an incident becomes a tradeable fact
A breach becomes tradeable at the moment it becomes a document. Everything before that is reporting, and reporting is not what a market settles on.
At a glance
- United States
- Form 8-K Item 1.05, within four business days of determining materiality
- EU personal data
- GDPR Article 33, within 72 hours of becoming aware
- EU critical entities
- NIS2 Article 23: 24-hour warning, 72-hour notification, one-month final report
- Annual, not incidental
- Regulation S-K Item 106, describing risk management and board oversight in the 10-K
What a disclosure obligation actually is
Since December 2023, a US-listed company that determines a cybersecurity incident is material must file a Form 8-K under Item 1.05 within four business days. The filing has to describe the material aspects of the incident's nature, scope and timing, and its material impact or reasonably likely material impact on the company's financial condition and results of operations. It is a securities-law obligation, not a security one: the point is that investors learn something that would change their view of the company.
The clock is the part most readers get wrong. It does not start when the intruder gets in, and it does not start when the company notices. It starts when the company determines that the incident is material - a determination the rules require to be made without unreasonable delay, but which is still a judgement made inside the company. That single design choice explains most of the distance between when an incident happens and when it appears in a filing.
Europe runs on a different logic and different clocks. The GDPR's Article 33 gives a controller 72 hours from becoming aware of a personal data breach to notify its supervisory authority. NIS2 layers a faster sequence on top for essential and important entities: an early warning within 24 hours, a fuller notification within 72, a final report within a month. These obligations are cumulative, not alternative - a NIS2 report does not discharge a GDPR duty, and vice versa.
Awareness starts the European clocks. A materiality determination starts the American one. That is why the same incident can be public in Brussels and unfiled in Washington.
Why this decides markets rather than describing them
A prediction market about an incident is almost always a market about a document. Whether a company confirms a breach by a date, whether a filing appears, whether a regulator is notified - each of those is an act with a timestamp and a public record, which is exactly what a resolution rule needs. The incident itself has no such timestamp: it has a discovery date, a disclosure date and an actual date, and the three can be months apart.
That gap is also where the mispricing lives. Coverage of a large incident arrives within hours and reads like a conclusion. The filing, if it comes at all, arrives days or weeks later and often says considerably less. Traders who price the coverage and settle on the document lose the difference, and the difference is systematic rather than occasional.
There is a second use, quieter and more durable. Since companies must describe their cyber risk management and board oversight annually under Item 106 of Regulation S-K, every large US issuer now publishes a structured description of how it handles exactly this. It is a slow document and nobody reads it for excitement, but for anyone estimating how likely a company is to disclose promptly, it is the closest thing to a stated policy.
- The event a market settles on is a filing, a notification or a statement - not the intrusion.
- Reporting leads disclosure by days to weeks, and sometimes disclosure never comes.
- A non-material incident may be disclosed voluntarily, but under a different item of the same form.
- US disclosure can be delayed if the Attorney General determines it poses a substantial risk to national security or public safety.
The four clocks, in the order they run
Laid out end to end, the obligations are not competing versions of one rule but a sequence with different triggers. The European clocks run from awareness and are measured in hours. The American clock runs from a materiality judgement and is measured in business days, which over a holiday weekend can be most of a week of calendar time.
The practical consequence for anyone pricing a question: the first official trace of a large incident at a company with European operations is usually a regulator notification, not a securities filing, and regulator notifications are frequently not public at all. The first trace the market can see is often the company's own statement, published because the story is already running.
This is also why 'has the company disclosed' is a far better question than 'has the company been breached'. The second is unfalsifiable on any useful timescale. The first has a register, a form number and a date.
1Incident occurs
No obligation attaches yet; the date is often established only in hindsight
2Awareness
Starts both European clocks
GDPR and NIS2 trigger here
324 hours
NIS2 early warning to the national CSIRT
472 hours
GDPR notification to the supervisory authority; NIS2 incident notification
5Materiality determination
A judgement made inside the company, required without unreasonable delay
Starts the US clock
6Four business days
Form 8-K Item 1.05 filed with the SEC
7One month
NIS2 final report; the 8-K may be amended as facts firm up
Behind the subscription
The rest of this entry is the part that changes a decision: what moves the price, which contract sets it, who ships it and where that can be cut off.
What decides whether a filing comes, and when
Six things determine whether an incident ever reaches a filing. Only one of them is how bad the incident was.
Where the settling document appears
Four registers, four different levels of public access - and one of them is where most European incidents go to stay invisible.
The gap between the event and the record
Three dates exist for every incident and markets confuse them constantly. Which one your rules name decides whether you are even in the right week.
How this shows up in prediction markets
The five question shapes this domain produces, and the wording that decides each of them.
Included with a subscription
Create an account to unlock the full entry — price drivers, trading venues, trade flows and the live markets attached to it.
Frequently asked questions
- How long does a company have to report a cyber breach?
- It depends on which rule applies. A US-listed company files a Form 8-K under Item 1.05 within four business days of determining the incident is material. In the EU, the GDPR gives 72 hours from awareness for a personal data breach, and NIS2 requires an early warning within 24 hours, a notification within 72 hours and a final report within a month for essential and important entities. These are separate duties that can all apply to the same incident.
- Does the four-business-day clock start when the breach is discovered?
- No, and this is the most consequential detail in the rule. It starts when the company determines the incident is material. That determination must be made without unreasonable delay, but it is still made inside the company, which is why the distance between discovery and filing varies so much between issuers.
- Why do some huge incidents never appear in a filing?
- Because the disclosure test is materiality in the securities sense - whether a reasonable investor would consider it important to an investment decision - and not severity or news coverage. An incident involving no personal data, no operational disruption and no measurable financial consequence can be enormous as a story and immaterial as a filing.
- Can a company legally delay disclosure?
- Yes, in a narrow case. Disclosure under Item 1.05 can be deferred where the US Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety, and notifies the SEC in writing. It is rare, time-limited, and it postpones the filing rather than removing the obligation.
- Are GDPR and NIS2 notifications public?
- Usually not per company. Authorities may publish aggregate statistics or, much later, enforcement decisions. That means an incident can be correctly and fully reported in Europe while leaving nothing a prediction market could cite as a resolution source - which is a reason to prefer questions that name an SEC filing or a company statement.
Primary sources
Related entries
Prediction markets carry real risk of loss. Nothing on Market Guy is financial advice — it is research tooling to help you think, not a signal to trade.