As the threat of cyber-attacks grows, so does the need for protection. The U.S. Securities and Exchange Commission (SEC) has begun to do just that as they roll out
new rules to protect investors from the material threat of
cybersecurity incidents. The rules will require companies registered with the SEC to disclose material cybersecurity incidents and report on their
cybersecurity practices to create a standardized approach to how organizations provide reporting.
The SEC Ruling
The rules mandate that registrants disclose any material cybersecurity incidents to investors. Whether a company’s information systems go down due to an internal systems failure, or they have a compromise due to a cybersecurity incident, they must provide a disclosure to the SEC on Form 8-K under the newly added Item 1.05. The disclosures must include critical details about the incident’s nature, scope, and timing, and its potential impact on the affected organization. As organizations further investigate the incident and more details become available, they are required to file disclosure amendments to provide updated information to investors. Additionally, the ruling requires organizations to document annual updates on their
cybersecurity risk management, strategy, and governance.
The SEC cybersecurity reporting guidelines require companies to file Form 8-K within four business days of determining that a cybersecurity incident is material, meaning that it could impact the outcome of investments. Even though the ruling has been in effect for 6 months, criticism surrounding the tight deadline is still rolling in.
Scrutiny Over Turnaround Time
The tight turnaround for reporting has received some scrutiny from critics. Some call attention to the lengthy process of determining the scope and impact of a cybersecurity incident, saying that four days is not long enough to determine the immediate impact and potential long-term effects. Others have security concerns, saying that reporting on an incident so soon after impact could expose weak spots to more bad actors. However, the SEC combats this concern with an exception to the reporting deadline, allowing delays for reporting if the U.S. Attorney General believes that immediate disclosure could threaten national security or public safety.
Even with the exception, companies have already failed to comply with the new rules. Some companies are missing the mark on compliance by failing to disclose all the reasonably likely material impacts of the incident, meaning the quantitative financial impact and the qualitative organizational impacts. In one case, this took the form of a company disclosing the estimated impact on annual earnings but failing to report on the qualitative impact to strategic initiatives. In another instance, a major financial institution did follow the reporting guidelines but was still fined because they failed to provide necessary safeguards to protect their customers’ security after the incident.
Facilitating Compliance
Companies will need to take steps to effectively meet the new requirements by facilitating strong communication between their IT/security, finance, and legal teams. This collaboration will be vital for assessing the impact of a cyber incident, determining the necessity of disclosure, and deciding the content of such disclosures. The goal is to ensure that all relevant departments work together to provide accurate and timely information to investors.
This communication between departments will also help companies facilitate compliance with the second aspect of the new SEC ruling, which requires organizations to provide annual updates on their cybersecurity risk management,
strategy, and governance. Investors and the SEC alike are expecting organizations to have defined risk management procedures, detailed criteria for determining the impact of an incident, and dedicated cybersecurity teams. This requirement is intended to give investors a clearer understanding of a company’s overall cybersecurity posture.
Ultimately, the SEC’s new reporting guidelines represent a significant push towards encouraging companies to prioritize cybersecurity. By requiring more transparency, the ruling aims to benefit investors by ensuring that crucial information about cybersecurity risks and incidents is consistently disclosed. For organizations, the new ruling means that it is time to get serious about assessing cybersecurity practices to prepare to meet the requirements. Before reporting to investors, find out where your environment stands with a
Cyber Gut Check from
ProCern, because the first step in facilitating compliance is understanding the state of your current environment.