#1 Trending Cybersecurity News & Magazine
Wednesday, September 20, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Ministry of Public Works and Housing Cyber Attack

    OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

    Araújo e Policastro Advogados Breach

    Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

    TransUnion cyber attack

    USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

    Dymocks Cyber Attack

    Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

    Retool Data Breach

    Retool Data Breach Linked to Google Authenticator Vulnerability

    Cybercrime competitions

    Inside Cybercrime Tournaments: Players, Incentives, and Impact on Security

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Ministry of Public Works and Housing Cyber Attack

    OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

    Araújo e Policastro Advogados Breach

    Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

    TransUnion cyber attack

    USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

    Dymocks Cyber Attack

    Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

    Retool Data Breach

    Retool Data Breach Linked to Google Authenticator Vulnerability

    Cybercrime competitions

    Inside Cybercrime Tournaments: Players, Incentives, and Impact on Security

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Cyber Essentials Compliance

SEC Mandates US Public Firms to Disclose Cybersecurity Incidents in 4 Days

Public companies in the US have to promptly disclose any cybersecurity breaches that could impact their financial standing.

Chandu Gopalakrishnan by Chandu Gopalakrishnan
July 27, 2023
in Compliance, Cyber Essentials, Features, Firewall Daily, Governance
0
cybersecurity incident disclosure
601
SHARES
3.3k
VIEWS
Share on LinkedInShare on Twitter

Cybersecurity incident disclosure in the US just turned stricter. Public companies in the US now have four days to disclose cybersecurity breaches that could impact their financial standing.

In an effort to enhance transparency and protect investors, the Securities and Exchange Commission (SEC) voted along party lines, 3-2, to adopt new rules on Wednesday.

You might also like

OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

“I think companies and investors alike, however, would benefit if this disclosure were made in a more consistent, comparable, and decision-useful way,” SEC Chair Gary Gensler.

“Through helping to ensure that companies disclose material cybersecurity information, today’s rules will benefit investors, companies, and the markets connecting them.”

However, not all members of the commission were in favor of the new requirements, reported AP.

One of the dissenting Republican commissioners, Hester Peirce, argued that the SEC is overstepping its authority with these rules and expressed concerns that the detailed information provided by companies may inadvertently assist hackers.

Peirce also cautioned against potential micromanagement of company operations by the SEC in the future.

While certain critical infrastructure operators and healthcare providers are required by law to report breaches, no federal breach disclosure law existed before the adoption of these rules.

SEC’s interest in the matter stems from a major concern: breach information leads to a stock market activity called informed trading, currently a grey area in the eyes of law.

Stricter SEC cybersecurity incident disclosure norms

Under the newly adopted cybersecurity incident disclosure rules, registrants must disclose any cybersecurity incident that they determine to be material on the recently introduced Item 1.05 of Form 8-K.

This cybersecurity incident disclosure should encompass crucial details regarding the incident’s nature, scope, timing, and its material impact or potential material impact on the registrant.

Companies are generally expected to submit an Item 1.05 Form 8-K within four business days of confirming the incident’s materiality.

However, if immediate cybersecurity incident disclosure poses a substantial risk to national security or public safety, the disclosure can be delayed after written notification from the United States Attorney General to the Commission.

The rules introduce Regulation S-K Item 106, requiring registrants to describe their processes for assessing, identifying, and managing material risks arising from cybersecurity threats.

Additionally, companies must disclose the material effects or reasonably likely material effects of cybersecurity risks and past incidents.

Furthermore, the new rules call for detailed descriptions of the board of directors’ oversight of cybersecurity risks and management’s role and expertise in handling such risks. These disclosures will be included in a registrant’s annual report on Form 10-K.

Foreign private issuers will be held to comparable standards, required to disclose material cybersecurity incidents on Form 6-K and provide information on cybersecurity risk management, strategy, and governance on Form 20-F.

Deadline for the new SEC cybersecurity incident disclosure norms

The development of these rules was initiated in March 2022 when the SEC recognized the escalating risk of corporate network breaches due to increased digitization of operations and remote work.

The final rules are set to take effect 30 days after their publication in the Federal Register.

Companies will be required to comply with the Form 10-K and Form 20-F disclosure requirements for fiscal years ending on or after December 15, 2023.

As for Form 8-K and Form 6-K disclosures, companies will have 90 days from the date of publication in the Federal Register or until December 18, 2023, whichever is later.

Smaller reporting companies will receive an additional 180 days before they must begin providing the Form 8-K disclosure.

Moreover, all registrants must comply with the structured data requirements by tagging the required disclosures in Inline XBRL, starting one year after their initial compliance with the relevant disclosure requirement.

“In many ways, the SEC’s rule will regulate what companies should have been implementing in the first place; good cyber hygiene,” said Amit Yoran, Chairman and CEO at cybersecurity company Tenable.

“Requiring companies to provide annual updates of their cybersecurity risk management strategy and governance and report material breaches within four business days will keep customers and investors better informed as to who they trust with their business.”

In the initial announcement, SEC clarified that companies cannot avoid or delay real‑time disclosure of material cybersecurity incidents citing ongoing internal and external investigations.

“We expect this aspect of the proposed rulemaking – which prioritizes investors’ interest in real-time disclosure over the impact of such disclosures on ongoing investigations – to be a focal point of comments,” wrote Timothy Gregg, Chair of Public Company Advisory Group at US-based law firm Maynard Nexsen.

Cybersecurity incident disclosure and informed trading

According to the SEC, the rules are designed to ensure timely reporting and will require companies to reveal breach incidents within four days of their discovery.

However, the disclosure window can be extended in cases where immediate reporting poses a serious threat to national security or public safety.

Additionally, the new regulations demand public companies to annually disclose information pertaining to their cybersecurity risk management protocols and the expertise of executives in the cybersecurity field.

This measure aims to provide investors with valuable insights into companies’ preparedness against cyber threats.

In a 2018 article published in the Harvard Business Law Review, Columbia Law professors Eric Talley and Joshua Mitts identified trading patterns suggestive of informed trading prior to the disclosure of cybersecurity breaches.

They argued that trading of this type raises complex and, in context, unique concerns over price discovery, liquidity, and efficient allocation of resources.

“Profits from such trading may increase hackers’ incentives to exploit security vulnerabilities, leading to impersonation, identity theft, and greater dissemination of stolen personal information,” Joshua Mitts wrote later.

“These represent real economic costs not present in garden variety information-trading contexts. Consequently, informed cyber-trading plausibly justifies enhanced legal scrutiny of those who profit from the activity.”

The treatment of informed trading on cybersecurity breaches is complicated under existing law.

It is unlawful for an agent or fiduciary to trade on a firm’s material non-public information, for third parties to steal such information, or for a person to spread false information about a cybersecurity risk in order to manipulate stock prices.

However, if third parties were simply to use computer queries to access, discover, trade upon, and then expose bona fide cybersecurity vulnerabilities, they might face little liability under current law.

It is thus critical to have effective ongoing disclosure of cybersecurity vulnerabilities, as the SEC proposes, noted Mitts.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Previous Post

Cyclops Ransomware Group to Shut Down Old Panel, Set to Rebrand as ‘Knight’

Next Post

Cyber Attack on Kenya: Anonymous Sudan Hackers Target Digital Infrastructure

Chandu Gopalakrishnan

Chandu Gopalakrishnan

Executive Editor, The Cyber Express

Related Posts

Ministry of Public Works and Housing Cyber Attack
Firewall Daily

OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

by Vishwa Pandagle
September 18, 2023
Araújo e Policastro Advogados Breach
Firewall Daily

Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

by Ashish Khaitan
September 18, 2023
TransUnion cyber attack
Data Breach News

USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

by Vishwa Pandagle
September 18, 2023
Dymocks Cyber Attack
Firewall Daily

Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

by Editorial
September 18, 2023
Retool Data Breach
Data Breach News

Retool Data Breach Linked to Google Authenticator Vulnerability

by Ashish Khaitan
September 18, 2023
Next Post
cyber attack on kenya

Cyber Attack on Kenya: Anonymous Sudan Hackers Target Digital Infrastructure

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

3AM Ransomware
Cybersecurity News

3AM Ransomware – A Potential Backup for LockBit Ransomware?

September 19, 2023
Cybersecurity in the Middle East
Cybersecurity News

Evolution of Cybersecurity in the Middle East

September 19, 2023
Ministry of Public Works and Housing Cyber Attack
Firewall Daily

OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

September 18, 2023
Araújo e Policastro Advogados Breach
Firewall Daily

Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

September 18, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance