Join our Newsletter — 33% off our NHI Course

Regulation S-K Item 106

Regulation S-K Item 106 requires annual disclosure of a company’s cybersecurity risk management, strategy, and governance. Registrants must explain how they assess, identify, and manage material cyber risks, along with the board’s oversight role and management’s expertise. The rule turns cybersecurity into a recurring governance disclosure, not just an incident response issue.

What Regulation S-K Item 106 Covers in Practice

Item 106 is a disclosure rule, but its practical effect is broader: it forces companies to explain how cyber risk is governed, who owns oversight, and how management turns cyber topics into board-level reporting. The disclosure is meant to surface process, accountability, and decision-making, not just technical controls.

That matters because investors and regulators are not looking for marketing language. They are looking for a credible description of the organisation’s cyber risk posture, including how the company defines material cyber risk, how often the board is informed, and what management uses to assess whether its programme is working.

What Companies Typically Need to Disclose

The rule usually pulls together three disclosure themes: the processes used to assess and manage cyber risk, the governance structure for oversight, and the role of management expertise. A strong disclosure explains whether cyber risk is integrated into enterprise risk management, how incidents and near-misses are escalated, and whether the board or a committee has formal oversight responsibility.

Item 106 also makes management capability part of the story. Registrants may need to describe whether leaders with cyber responsibility have relevant experience, how they stay informed, and how cyber considerations are incorporated into strategic decisions such as vendor reliance, data architecture, product releases, and business continuity planning.

Why the Disclosure Matters for Governance and Assurance

Item 106 shifts cybersecurity from an isolated technical concern into a recurring governance obligation. That creates pressure for consistency between what a company says publicly and how it actually operates internally, especially where controls, ownership, and escalation paths are fragmented.

When the disclosure is strong, it can improve discipline across the organisation. When it is vague, generic, or disconnected from real oversight, it can signal weak governance even if the security programme itself is more mature than the filing suggests. For readers comparing disclosures, the quality of the narrative often matters as much as the existence of a statement.

How Item 106 Connects to Security Programs

Item 106 does not prescribe a single security framework, but it aligns naturally with governance, risk, and control mapping. A company that can explain its cyber risk process clearly is usually able to tie board oversight to operational controls, risk registers, incident response, third-party risk, and remediation tracking. That is why the disclosure often reflects the maturity of the broader security program.

For governance language and control mapping, many teams use the NIST Cybersecurity Framework 2.0 as a practical structure for organising cyber risk, while the NIST SP 800-53 Rev 5 Security and Privacy Controls is useful when disclosures need to reflect concrete control families such as access control, audit, and configuration management. For NHI-heavy environments, the governance narrative may also need to reflect secret management and privilege control described in OWASP Non-Human Identity Top 10.

Risk and Threat Considerations

Item 106 creates disclosure risk when the organisation cannot substantiate what it says about oversight, expertise, or cyber risk management. The main exposure is not only regulatory scrutiny, but also the possibility that public disclosures overstate maturity, understate dependencies, or omit material weaknesses in how cyber risk is governed.

Failure mechanism: The filing becomes vulnerable when governance is informal, evidence is scattered, or management cannot tie board reporting to actual risk decisions and control outcomes. Weak disclosure discipline can also hide chronic issues such as poor third-party visibility, incomplete incident escalation, or overstated assurance.

Impact: Investors may receive a misleading picture of cyber preparedness, and the company may face credibility damage, enforcement attention, or intensified follow-up after an incident or material control failure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV — Governance Item 106 centers governance, oversight, and cyber risk management disclosure.
ID — Identify The rule asks how the company identifies and manages material cyber risk.
RS — Respond Disclosures often describe incident escalation and response readiness as part of cyber risk management.
Recommendation — Align board oversight, risk ownership, and cyber reporting to the CSF governance function. Map material cyber risks, assets, and dependencies before drafting the disclosure. Describe escalation paths and response responsibilities that support the public governance statement.
CIS Controls v8 8 — Audit Log Management Audit evidence often underpins credible statements about cyber oversight and monitoring.
17 — Incident Response Management Item 106 disclosures commonly reference how the company manages and escalates cyber incidents.
Recommendation — Use logged evidence of monitoring and escalation to support the governance narrative. Tie incident response ownership and testing to the disclosure of cyber risk management.

Practitioner Guidance

Why practitioners should care: Item 106 is a governance quality test as much as a disclosure obligation. The safest filing is usually the one that cleanly reflects how cyber risk is really handled inside the company, because inconsistencies between narrative and practice are what tend to create trouble later.

Common misunderstanding: Teams sometimes treat the disclosure as a legal drafting exercise rather than an operating-model statement. In practice, the filing should mirror actual board reporting, management accountability, and the real cadence of cyber risk review.