New Cybersecurity Risk Management Rules Proposed by SEC
On February 9, 2022, The Securities and Exchange Commission voted to propose new rules for cybersecurity risk management for registered investment...
If you are a public company subject to the reporting requirements of the Securities Exchange Act of 1934., listen up. The Security and Exchange Commission (SEC) just released a new controversial disclosure requirements.
This blog will answer any questions you may have about the new disclosure requirements and lay out what enterprises need to do now to maintain compliance.
The SEC’s ruling for public companies subject to SEC reporting requirements(referred to as “registrants”) took effect September 5,. 2023. Some of the specific reporting requirements, such as including cybersecurity incidents in annual reports, take effect on specific dates ranging from December 15, 2023 to December 15, 2024. In short, public enterprises will be required to disclose material incidents within four days. In addition, they’ll be required to reveal how they detect and address incidents while describing board oversight.
Per the new rules, registrants will now be required to:
As with most new rules or laws, it depends on who you are. Reactions to the recent ruling have been all over the map. Perhaps one of the largest pushbacks is that four days is not enough time for many enterprises to confirm a breach, let alone understand its impact and coordinate notifications.
Others believe that any move the SEC makes to increase transparency and communication is a good one.
Perhaps the most significant point of contention and confusion around the new ruling is now to define what classifies as “material.”
The definition of “material” may largely depend on the industry. For example, the timelines could differ when comparing a breach in the supply chain versus intellectual property theft. This has yet to be more clearly defined by the SEC, but enterprises will likely require greater explanation as December 15th gets closer.
Are you a large enterprise with questions about how the new SEC ruling may affect your current cybersecurity practices? Make sure you have an IT professional in your corner. Contact PK Tech, and our team can help.
On February 9, 2022, The Securities and Exchange Commission voted to propose new rules for cybersecurity risk management for registered investment...
Arizona businesses should be aware of a recent act initiated in New York that looks to change the way companies approach security practices...
1 min read
Following increased enforcement in 2021, the SEC recently released its new cybersecurity rules on February 9, 2022 (reference). The rules are...