Governance Toolkit by Jacob James Kahn

Governance Toolkit / AI and technology oversight

AI and technology oversight · Editable Word document · Free

Reading Item 1C: A Director's Guide to Cybersecurity Disclosures (Word)

A plain-language guide to the cybersecurity section of the annual report and a checklist for reading your own company's disclosure.

Version 1.0 · Last updated

What it is

Since fiscal years ending on or after December 15, 2023, a U.S. public company's annual report on Form 10-K includes Item 1C, Cybersecurity. Item 1C carries the disclosure required by Regulation S-K Item 106. This guide summarizes what the item asks a company to describe and gives directors a checklist for comparing their own company's disclosure with what the board actually receives. It is a reading aid, not legal analysis; the company's counsel and disclosure committee own the disclosure itself.

Who it's for

Audit and risk committee members, general counsels and corporate secretaries of U.S. public companies.

When to use it

Use it when reviewing the draft annual report, after a change in how the board oversees cybersecurity, or when joining a public company board.

How to use it

  1. Read your company's most recent Item 1C alongside this guide.
  2. Work through the checklist and note where the disclosure and the board's own experience differ.
  3. Raise any differences with management and counsel before the next annual report is drafted.

Preview of contents

Get the template

Download the templateWord (.docx), 30 KB

Review with counsel before adoption. Templates are general resources, not legal advice.

Related