We analyzed the Item 1C disclosures that 1,098 companies filed April 16, 2025, through April 16, 2026, comparing the information to those companies’ prior-year filings. We also reviewed 85 cybersecurity-related Form 8-K incident disclosures filed since Item 1C took effect. Five signals emerged for business and security leaders:
- Artificial intelligence has entered the disclosure mainstream faster than AI governance has.
- The disclosure baseline is largely built.
- The middle market is increasing its cybersecurity resource allocation.
- Cybersecurity leadership has moved decisively into the C-suite, and reporting structures are evolving in tandem.
- Incident disclosures are blurring the line between mandatory and voluntary.
Read our report to learn what these signals truly mean for business and board-level leadership, as well as for security and technology leaders. In addition, the report includes a detailed review of:
- Security program leadership and oversight
- Framework alignment
- Cybersecurity risk management
- External communication of cyber risk governance
- Cybersecurity incident disclosure practices