SEC Proposes Regulations for Breach Reporting, Governance Disclosures

The SEC has proposed new cybersecurity risk management and disclosure regulations for public companies, including mandatory reporting of “material” cybersecurity incidents within four business days of discovery. Covered entities would also need to periodically disclose their policies for managing and identifying cybersecurity risk, what role management plays in cybersecurity, and the board of directors’ oversight role and cybersecurity expertise. Their disclosures to investors would explain the extent to which they prioritize cybersecurity in their business planning.
SEC chair Gary Gensler explained that one of their goals was for information about corporate risk to be standardized “in a consistent, comparable, and decision-useful manner,” including machine-readable mark-up. A group of senators – four Democratic, two Republican, and one independent – wrote to Gensler a month ago urging SEC to set new cybersecurity rules.
Sources:
- Federal Computer Week: SEC Proposes Mandatory Breach Reporting for Publicly Traded Companies
- CyberScoop: SEC Weighs Reporting Requirements for Publicly Traded Companies
- Government Executive: The SEC Is Proposing Mandatory Cybersecurity Incident Reporting for Publicly Traded Companies

