Auditen
Home / Frameworks / SEC Cyber Disclosure / Annual disclosure: risk management, strategy and governance
SEC Cyber Disclosure · Reg S-K Item 106

Annual disclosure: risk management, strategy and governance

Reg S-K Item 106 requires public companies to describe their processes for assessing, identifying, and managing material risks from cybersecurity threats. It also mandates disclosure of the company's governance structure, specifically how the board oversees cyber risk and management’s role in implementing these strategies.

What it means

This requirement focuses on "how" a company handles cybersecurity rather than listing specific technical vulnerabilities. The SEC wants to see that there is a systematic approach to identifying risks and a clear chain of command for managing them. It moves cybersecurity from a purely technical IT concern to a corporate governance obligation.

In practice, this means the organization must articulate its risk management lifecycle—how it detects threats, evaluates their potential impact on the business (materiality), and mitigates those risks. This process should be integrated into the company's broader enterprise risk management (ERM) strategy.

Regarding governance, the disclosure must clarify who is in charge. It requires a description of whether the board has a dedicated cyber committee or if oversight happens through existing committees, as well as how the Board stays informed about current threats and the effectiveness of the security program.

How to meet it

Evidence an auditor asks for

  • Board and committee meeting minutes demonstrating that cybersecurity risk was discussed and reviewed.
  • Written charters or job descriptions that explicitly assign cybersecurity oversight responsibilities to specific board members or executives.
  • Copies of the enterprise risk register showing identified cyber risks, their impact scores, and mitigation plans.
  • Internal memos or slide decks used for management-to-board reporting on the state of the cybersecurity program.

Common pitfalls

  • Using boilerplate language: Providing generic statements about "taking security seriously" instead of describing specific processes and governance structures.
  • Confusing Item 106 with Item 1.05: Mistaking this annual disclosure of *governance and strategy* for the requirement to report individual material *incidents*.
  • Governance gap: Describing a sophisticated oversight process in the public filing that is not supported by actual board meeting minutes or documented reporting lines.