Reuters [1] and Venturebeat [2] have reports. Here is a key passage:
The federal securities laws, in part, are designed to elicit disclosure of timely, comprehensive, and accurate information about risks and events that a reasonable investor would consider important to an investment decision.
I'm not an investor, but I read that to indicate that if the attack has an impact on the business that would affect a reasonable investor's decision with regards to whether to buy, sell or hold stock in the company, it needs to be disclosed
[1] http://www.reuters.com/article/2011/10/13/us-sec-cyberattack...
[2] http://venturebeat.com/2011/10/13/sec-tells-public-companies...