The lede: Since December 2023, SEC Item 1.05 has forced U.S. public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality — not four days after discovering an intrusion, four days after deciding it matters financially or operationally. That distinction quietly moved the incident-response buying decision out of the SOC and into the general counsel's office. A materiality call is a legal judgment that needs a defensible timeline, chain-of-custody forensics, and board-ready documentation an auditor and a plaintiffs' attorney will both accept. Detection tools that just say "we stopped it" don't produce that artifact. Vendors that can hand GC a court-ready incident narrative do. That's a budget line moving from IT security spend to legal/compliance spend, and it favors a specific kind of company.
The SEC Rule That Made General Counsel the New Cybersecurity Buyer
SEC Item 1.05's four-day materiality clock turned breach forensics into a legal-budget line item, and CrowdStrike and Palo Alto built the products general counsel actually buys.

A materiality determination isn't a security question — it's a legal one, and it needs a vendor who can produce a timeline a plaintiffs' lawyer can't shred.
Who cashes in:
- CrowdStrike CRWD — CrowdStrike built and markets "SEC Readiness Services" explicitly for this rule: Falcon-platform assessments plus board/C-suite exercises for practicing materiality determinations, sold directly to general counsel and audit committees, not IT. That's a purpose-built product line riding the regulation, not a repackaged pitch.
- Palo Alto Networks PANW — Unit 42's incident-response retainer is built around law-firm and cyber-insurer relationships (Palo Alto cites ties to 150+ global law firms and 70+ insurance carriers) plus expert-witness and litigation-support work. That's precisely the forensics-to-disclosure pipeline GC needs to sign off on an 8-K, and it's a retainer model — recurring revenue booked before any breach happens.
- SentinelOne S — smaller scale, but its forensics/attribution tooling and incident-response partnerships give it a foothold in the same disclosure-support niche as boards look for a second bidder against CrowdStrike's retainer pricing.
Who is exposed: Pure detection/prevention vendors whose product stops at "alert fired, threat blocked" without a forensics or reporting layer are structurally weaker sellers into this budget. Zscaler ZS is a proxy/SSE traffic-inspection platform — excellent at prevention, but it doesn't own the post-incident forensics or board-reporting narrative, so it's a bystander to this specific spending shift even as overall security budgets grow. Fortinet FTNT, heavily weighted toward network appliances (firewalls), faces the same gap: hardware-centric vendors have to partner or acquire their way into the forensics/disclosure layer rather than sell it natively.
The play: Watch for services-revenue mix, not just ARR growth — CrowdStrike and Palo Alto both break out professional-services/retainer bookings, and disclosure-readiness engagements should show up there. Also watch 8-K Item 1.05 filing volume itself (searchable on EDGAR full-text search) as the leading indicator of demand; each new filing is a live advertisement for whichever forensics vendor is named in the incident narrative.
Primary source: https://www.sec.gov/newsroom/press-releases/2023-139
Source: original report ↗
Free: catalyst alerts, straight to your inbox.
Get the White House orders, federal contracts, and FDA decisions that move money — with who cashes in — free. Unsubscribe in one click.
Free · weekly · unsubscribe anytime. Privacy.
Stay three moves ahead of every practice in your market.
Knowing it happened is table stakes. Money Racket Pro hands you the play — what each move means for your margins, your license, and your patients, and exactly what to do about it — in a two-minute brief, twice a week. The owners who read it never get blindsided.
Get the edge · $40/moJoin the owners who run ahead of the industry. Cancel anytime, one click.