From compliance to strategy: An analysis of SEC Item 1C disclosures

AI, governance and leadership emerge as key maturity signals

October 01, 2026

More than two years after going into effect, the Securities and Exchange Commission’s disclosure requirement on Form 10-K, Item 1C, has accomplished its primary goal: Every public company now has a baseline cybersecurity narrative on file. But the subsequent questions are: What do those disclosures actually reveal about how cybersecurity risk is governed, operationalized and communicated, and what is the next stage of maturity?

54%

of companies are led by a dedicated security leader.

91%

of companies designate a specific board committee responsible for cybersecurity oversight.

65%

of companies align with at least one recognized control framework.

+5.2 percentage points: Year-over-year increase in AI-related cybersecurity risk mentions; the largest YOY movement in the dataset

We analyzed the Item 1C disclosures that 1,098 companies filed April 16, 2025, through April 16, 2026, comparing the information to those companies’ prior-year filings. We also reviewed 85 cybersecurity-related Form 8-K incident disclosures filed since Item 1C took effect. Five signals emerged for business and security leaders:

  1. Artificial intelligence has entered the disclosure mainstream faster than AI governance has.
  2. The disclosure baseline is largely built.
  3. The middle market is increasing its cybersecurity resource allocation.
  4. Cybersecurity leadership has moved decisively into the C-suite, and reporting structures are evolving in tandem.
  5. Incident disclosures are blurring the line between mandatory and voluntary.

Read our report to learn what these signals truly mean for business and board-level leadership, as well as for security and technology leaders. In addition, the report includes a detailed review of:

  • Security program leadership and oversight
  • Framework alignment
  • Cybersecurity risk management
  • External communication of cyber risk governance
  • Cybersecurity incident disclosure practices

RSM contributors

  • David Carter
    Industrials Senior Analyst
  • Jacob Kastenschmidt
    Senior Associate

Download the report