In December 2023, the SEC finalized a rule requiring public companies to disclose material cybersecurity incidents within four business days of determining that the incident is material. The rule took effect for large accelerated filers in December 2024. The mechanism it created has almost nothing to do with disclosure and everything to do with demand for cybersecurity software.
The rule operates through 8-K filings — the same mechanism companies use to disclose earnings, executive departures, and other material events. A cybersecurity 8-K must describe the nature, scope, and timing of the incident, as well as the material impact or reasonably likely material impact on the company's financial condition and results of operations. The disclosure is filed with the SEC. It is read by investors, analysts, short sellers, plaintiff's attorneys, and regulators. The incentives around it are asymmetric and severe. Filing the 8-K on time means public acknowledgment of a cybersecurity failure. Filing late or incompletely means SEC enforcement action. Not filing at all, if the incident is later determined to have been material, means securities fraud liability for the officers who certified the disclosure controls.
Companies respond to asymmetric legal risk by buying insurance against it. The insurance in this case is cybersecurity software that reduces the probability and severity of the incident, and cybersecurity incident response retainers that ensure the company can determine materiality within the four-day window. The combination creates a permanent demand floor for cybersecurity products — a floor that is independent of the company's security posture, the threat environment, or the ROI of the software. The company buys the software because not buying it creates a disclosure risk that the CFO and general counsel are unwilling to accept.
The evidence that the rule is driving demand is visible in the earnings of the cybersecurity sector. Palo Alto Networks reported platform revenue growth of 24% in its most recent fiscal quarter. CrowdStrike's annual recurring revenue crossed $5 billion, growing 24% year-over-year, with the company explicitly citing "regulatory tailwinds" as a demand driver on its Q2 2026 earnings call. Zscaler reported billings growth of 30%. The cybersecurity sector is growing faster than enterprise software overall, and the growth is broad-based across endpoint security, network security, identity, and incident response — the full stack that a company needs to detect, contain, and disclose an incident within four business days.
The regulatory logic extends beyond the SEC. The EU's Digital Operational Resilience Act, which took effect in January 2025, imposes similar incident reporting requirements on financial institutions in the European Union. The UK's proposed Cyber Security and Resilience Bill, expected to pass in late 2026, would extend mandatory incident reporting to critical infrastructure operators. The regulatory pattern is expanding, but its practical effect is not settled: Axios found that only 16.9% of reviewed cyber 8-K filings described a specific material business impact, and enforcement priorities can change with SEC leadership. Regulation may harden compliance demand without guaranteeing informative disclosure or permanent software growth.
The contrarian angle is that the regulatory demand floor makes cybersecurity a structurally more durable category than almost any other category of enterprise software. Companies cut sales software in a downturn. They cut marketing software. They cut HR software. They do not cut the software that keeps them out of an SEC enforcement action. The cybersecurity budget line is becoming a compliance budget line, and compliance budgets do not get cut. They get audited.
The implication for cybersecurity valuations: the sector's premium multiples — Palo Alto Networks at 12x forward revenue, CrowdStrike at 15x — are not pricing growth. They are pricing the certainty of growth. The customers cannot leave. The budgets cannot be cut. The regulatory tailwind does not depend on the macroeconomic cycle or the threat environment or the efficacy of the software. It depends on an SEC rule that is not going away. The market has priced this correctly. The only question is whether the rest of enterprise software will get the same structural support — and the answer, for now, is no.