Author
Abstract
The Securities and Exchange Commission (SEC) issued its final rule on Cybersecurity Risk Management, Strategy, Governance, and Incident Response on July 26, 2023. This mandates that SEC‐regulated companies disclose both significant cybersecurity incidents and their cyber risk management processes. These public disclosures will be made via existing SEC reporting channels. They are intended to provide investors with enhanced transparency into the cyber risks and mitigation strategies employed by SEC‐regulated corporations. This landmark decision marks the culmination of an 18‐month intensive rulemaking process that commenced in March 2022. The process was anything but smooth. The interval from the SEC's original announcement to the finalization of the rules was marked by fervent debate, heated public discourse, and diverging viewpoints. Adapting to the new regulations will vary among companies. Established firms with robust practices will find the transition smoother, primarily focusing on initial disclosures for the year's 10‐k report. In contrast, companies with less structured cyber risk approaches and reliant on reactive measures, will grapple with substantial challenges. Central to this transition is the collaboration between boards and executives in defining “material” cyber incidents. While no fixed formula exists to gauge impact, it is crucial for leadership to holistically understand and swiftly assess potential repercussions—spanning operational costs, legal ramifications, brand implications, and revenue loss—during emergent cyber situations.
Suggested Citation
Brian Walker, 2023.
"New SEC Cybersecurity Disclosure Protocols: Enhanced Transparency, Short Deadlines,"
Journal of Critical Infrastructure Policy, John Wiley & Sons, vol. 4(1), pages 61-66, March.
Handle:
RePEc:wly:crtinf:v:4:y:2023:i:1:p:61-66
DOI: 10.18278/jcip.4.1.7
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:wly:crtinf:v:4:y:2023:i:1:p:61-66. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Wiley Content Delivery (email available below). General contact details of provider: https://doi.org/10.1002/(ISSN)2693-3101 .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.