Join our Newsletter — 33% off our NHI Course

Item 106

A required annual disclosure item in Form 10-K that asks public companies to explain how they assess, identify, and manage material cybersecurity risks. It pushes organisations to document governance, oversight, and risk management processes rather than relying on informal security practices or ad hoc reporting.

What Item 106 Requires and Why It Matters

Item 106 turns cybersecurity into a formal disclosure obligation. It asks companies to explain how they identify, assess, and manage material cyber risk, which makes the quality of internal governance and documentation part of the filing itself.

That is important because the item is not satisfied by broad assurances or informal security narratives. The disclosure has to reflect a real operating model, including who owns risk decisions, how escalation works, and how management understands the company’s exposure.

Disclosure Scope and the Management Story

Item 106 is less about listing every security tool and more about showing the structure behind cyber risk management. A strong disclosure usually connects the company’s risk assessment process, oversight model, and integration with enterprise risk management.

This means the filing should read like a coherent management story, not a marketing summary. Investors and regulators are looking for whether cyber risk is treated as a business risk with defined accountability, not as a standalone technical issue buried inside security operations.

What a Credible Item 106 Disclosure Typically Covers

A useful Item 106 discussion usually explains the company’s material cyber risks, the processes used to assess those risks, and how the board or relevant committee receives information. It also tends to show whether the organisation has repeatable governance rather than ad hoc reporting.

Where the disclosure is thin, it often omits the practical details that make oversight believable: risk prioritisation, reporting cadence, escalation thresholds, and the relationship between cyber findings and broader business decisions. Those elements help readers judge whether cyber governance is active or merely formal.

  • NIST Cybersecurity Framework 2.0 provides a governance-and-risk vocabulary that maps well to the kinds of processes Item 106 disclosures are expected to describe.
  • NIST SP 800-53 Rev 5 Security and Privacy Controls is useful when a company wants to anchor its narrative in concrete control families such as audit, access control, and risk assessment.
  • CIS Benchmarks can support the technical side of the story when the disclosure needs to reflect hardened environments and consistent baseline configuration.

How Item 106 Changes Cybersecurity Governance

Item 106 pushes cyber risk into the same accountability chain as other material business risks. That changes how security teams, legal teams, and executives collaborate because the filing has to be supportable by evidence, not just by intent.

It also raises the bar for cross-functional consistency. If the board narrative, internal risk register, incident readiness, and actual control posture do not match, the disclosure can become misleading even when no single technical control has failed.

Risk and Threat Considerations

Weak Item 106 disclosures create risk when the public narrative is broader or more confident than the organisation’s actual cyber governance. The exposure is not only reputational, because incomplete or inaccurate disclosure can also signal poor internal visibility, weak escalation, and gaps in risk ownership.

Failure mechanism: Management may fail to translate operational security data into a defensible material-risk narrative, leaving material exposures under-described, overstated, or inconsistently reported across the filing, board materials, and internal risk registers.

Impact: Investors, regulators, and counterparties may draw the wrong conclusion about the organisation’s cyber posture, and the company may face disclosure, governance, and trust consequences if the gap becomes visible after an incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Item 106 centers on explaining cyber risk management and oversight.
GV.OV-01 — Oversight of Cybersecurity Risk Item 106 asks how management and oversight bodies manage material cyber risk.
Recommendation — Align disclosure language to a documented cyber risk strategy and board reporting cadence. Tie the filing to formal oversight roles, escalation paths, and governance reporting.
NIST SP 800-53 Rev 5 RA-3 — Risk Assessment Item 106 disclosures describe how material cyber risks are identified and assessed.
AU-6 — Audit Review, Analysis, and Reporting The item depends on credible reporting and analysis of security events and risk signals.
Recommendation — Document how risk assessments feed the disclosure and update materiality judgments. Use audit and reporting evidence to support the cyber risk narrative in the filing.
ISO/IEC 27001:2022 A.5.4 — Management responsibilities Item 106 depends on clear accountability for cybersecurity governance and risk ownership.
Recommendation — Assign explicit responsibility for approving and maintaining the cyber risk disclosure.

Practitioner Guidance

Governance implication: Treat Item 106 as an evidence-backed disclosure process, not a drafting exercise. The underlying question is whether the organisation can trace its cyber risk statements to real oversight, real decision-making, and real reporting lines.

What to watch for: The clearest warning sign is when the filing uses polished language but cannot point to a consistent risk methodology, board reporting rhythm, or material-risk threshold. That usually means the disclosure is outpacing the governance model that should support it.