★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/SEC Proposes Regulations for Breach Reporting, Governance Disclosures
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
News·Cyber & Privacy Brief

SEC Proposes Regulations for Breach Reporting, Governance Disclosures

The SEC has proposed new cybersecurity risk management and disclosure regulations for public companies, including mandatory reporting of “material” cybersecurity incidents within four business days of discovery. Covered entities would also need to periodically disclose their policies for managing and identifying cybersecurity risk, what role management plays in cybersecurity, and the board of directors’ oversight role and cybersecurity expertise. Their disclosures to investors would explain the extent to which they prioritize cybersecurity in their business planning.

SEC chair Gary Gensler explained that one of their goals was for information about corporate risk to be standardized “in a consistent, comparable, and decision-useful manner,” including machine-readable mark-up. A group of senators – four Democratic, two Republican, and one independent – wrote to Gensler a month ago urging SEC to set new cybersecurity rules.

Sources:

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.