What S&P 200 CISOs Are Actually Telling the SEC About Cybersecurity

A fresh read of 2024–2025 10-K Section 1.C filings shows NIST CSF dominance, audit committee capture, and a suspicious abundance of 'no material impact' disclosures.

ThreatVectr Newsdesk· 3 min read
What S&P 200 CISOs Are Actually Telling the SEC About Cybersecurity
Share

The SEC's 2023 mandate requiring public companies to disclose cybersecurity risk management, governance, and incidents in their annual 10-K filings was supposed to create transparency. Two filing cycles in, the picture is clarifying — and parts of it are worth scrutinizing.

A researcher analyzed Section 1.C disclosures across the top 200 S&P companies, comparing 2024 and 2025 filings. The short version: the CISO title dominates, the Audit Committee owns board-level oversight, and NIST CSF is the framework everyone reaches for. None of that is surprising. Some of what sits underneath it is.

Who holds the role and who they answer to

The CISO is the named cybersecurity lead at over 70% of these companies, ticking up from 137 to 142 firms year-over-year. Average experience clocks in at roughly 23 years. The CIO remains the most common reporting line, hovering around 48–49 companies in both years.

That CIO-as-boss arrangement has real structural problems. It creates conflicts of interest when security priorities bump against operational velocity — and it quietly signals where cybersecurity sits in the enterprise hierarchy. No strong alternative has emerged. CEO, CFO, and CTO each claim a slice, but the numbers are diffuse. More striking: for over 50 companies, the reporting line simply wasn't legible from the filing at all.

Audit Committee as de facto cyber committee

The Audit Committee handles board-level cybersecurity oversight at roughly 60% of companies. Broaden that to include Audit & Risk, Audit & Finance, and similar variants, and the figure jumps to about 70%. That concentration held steady across both years.

This is a governance pattern worth watching. Audit committees carry heavy financial reporting obligations; tacking cyber risk oversight onto that agenda risks giving neither adequate attention.

Frameworks: NIST CSF, then ISO, then a gap

NIST CSF is the clear winner, cited by 118 companies in 2025 filings, up from 113 in 2024. ISO 27001 is a distant second, growing from 49 to 55 mentions. SOC reporting standards appeared in only 17 filings — a curiously low number given how central SOC 2 is to vendor trust programs at large enterprises.

The 'no material impact' problem

Practically every filing includes a variation of the same sentence: the company faces continuous, sophisticated cyberattacks, but none have had a material adverse effect on operations or financial condition. Every single one.

Set that against the backdrop of Volt Typhoon and Salt Typhoon compromises hitting critical infrastructure and telecoms repeatedly, and the uniformity becomes harder to accept at face value. Cyber liability insurance disclosures are nearly as universal, typically paired with a quiet note that coverage may not be sufficient.

Whether these disclosures reflect genuine outcomes or reflect how narrowly companies are defining materiality is a question the researcher flags for further work. It's a good one.

AI gets a mention, mostly as boilerplate

Over 50 companies cited AI — framing it as both a detection tool and an amplifier of attacker capability. Seven specifically called out AI-related intellectual property disclosure risk. The language is largely generic, which tracks: a 10-K is a governance document, not a technical architecture review.

The filings confirm what most IAM and security practitioners already sense. Governance structures are stabilizing around familiar patterns. Whether those patterns are adequate is a different question entirely.

© 2026 Threat Vectr