Governance Toolkit / AI and technology oversight
AI and technology oversight · Editable Word document · FreeReading Item 1C: A Director's Guide to Cybersecurity Disclosures (Word)
A plain-language guide to the cybersecurity section of the annual report and a checklist for reading your own company's disclosure.
Version 1.0 · Last updated
What it is
Since fiscal years ending on or after December 15, 2023, a U.S. public company's annual report on Form 10-K includes Item 1C, Cybersecurity. Item 1C carries the disclosure required by Regulation S-K Item 106. This guide summarizes what the item asks a company to describe and gives directors a checklist for comparing their own company's disclosure with what the board actually receives. It is a reading aid, not legal analysis; the company's counsel and disclosure committee own the disclosure itself.
Who it's for
Audit and risk committee members, general counsels and corporate secretaries of U.S. public companies.
When to use it
Use it when reviewing the draft annual report, after a change in how the board oversees cybersecurity, or when joining a public company board.
How to use it
- Read your company's most recent Item 1C alongside this guide.
- Work through the checklist and note where the disclosure and the board's own experience differ.
- Raise any differences with management and counsel before the next annual report is drafted.
Preview of contents
- 1. What Item 1C asks a company to describe
- 2. What Item 1C does not cover
- 3. Why it matters to directors
- 4. Checklist: reading your company's Item 1C
- 5. Questions to ask management and counsel
Get the template
Download the templateWord (.docx), 30 KB
Check your inbox for the download link.
Review with counsel before adoption. Templates are general resources, not legal advice.