Securities and Exchange Commission Adopts Cybersecurity Disclosure Rules for Public Companies

JurisdictionUnited States,Federal
CitationVol. 1 No. 6
Publication year2023
topicCorporate / Commercial,Securities Law,Technology

[Page 443]

David M. Lynn, Haimavathi V. Marlier, and Miriam H. Wugmeister *

In this article, the authors review amendments adopted by the Securities and Exchange Commission that will require companies to evaluate and adapt their disclosure controls and procedures, management processes, and governance structures around cybersecurity.

The U.S. Securities and Exchange Commission (SEC) has adopted amendments to its rules to require disclosures regarding cybersecurity risk management, strategy, governance, and incident reporting by public companies. 1

Under the rule and form amendments adopted by the SEC, public companies will be required to:

■ Disclose, within four business days after determining that an incident is material pursuant to new Item 1.05 of Form 8-K (subject to limited exceptions described below), any cybersecurity incident that a company experiences that is determined to be material, describing the material aspects of its:
■ Nature, scope, and timing; and
■ The impact or reasonably likely impact of the incident on the company, including on the company's financial condition and results of operations.
■ Describe, on a periodic basis pursuant to new Item 106 of Regulation S-K, the company's processes, if any, for the assessment, identification, and management of material risks from cybersecurity threats, as well as whether any risks from cybersecurity threats have materially affected or are reasonably likely to materially affect their business strategy, results of operations, or financial condition;

[Page 444]


■ Describe, on a periodic basis pursuant to new Item 106 of Regulation S-K, the board's oversight of risks from cybersecurity threats; and
■ Describe, on a periodic basis pursuant to new Item 106 of Regulation S-K, management's role in assessing and managing material risks from cybersecurity threats.

The SEC adopted similar disclosure requirements that will apply to foreign private issuers.

In adopting the final rules, the SEC made the following significant changes from the proposing release in response to comments:

■ Narrowed the scope of the disclosure required by pursuant to Item 1.05 of Form 8-K;
■ Added a limited delay for disclosures that would pose a substantial risk to national security or public safety;
■ Required certain updated incident disclosure in an amended Form 8-K, rather than in Forms 10-Q and 10-K;
■ Omitted a proposed requirement that contemplated periodic disclosure of aggregated immaterial cybersecurity incidents that were deemed to be material;
■ Streamlined the proposed disclosure elements related to risk management, strategy, and governance; and
■ Did not adopt a proposed requirement to disclose board cybersecurity expertise.

The final rules will be effective 30 days following publication of the Adopting Release in the Federal Register. The compliance time frame is as follows:

■ With respect to the periodic disclosures required by Item 106 of Regulation S-K, all issuers must provide such disclosures beginning with annual reports for fiscal years ending on or after December 15, 2023;
■ With respect to compliance with the current disclosure requirements for material cybersecurity incidents required by Item 1.05 of Form 8-K, all issuers (other than smaller reporting companies) must begin complying 90 days after publication of the Adopting Release in the Federal Register or December 18, 2023, whichever is later; and
■ Smaller reporting companies have an additional 180 days from the non-smaller reporting company compliance date,

[Page 445]

so those issuers must begin complying with Item 1.05 of Form 8-K 270 days after publication of the Adopting Release in the Federal Register or June 15, 2024, whichever is later.

Key Takeaways for Public Companies

The SEC's final rules requiring disclosures regarding cybersecurity risk management, strategy, governance, and incident reporting should prompt public companies to:

■ Ensure that incident response policies and procedures provide a clear path to escalate incidents to corporate leadership and/or a disclosure committee, and that disclosure controls and procedures are in place to discern the impact that an incident may have on the company;
■ Establish the framework for undertaking a materiality assessment without unreasonable delay after discovery of the incident so that decisions about whether an incident must be disclosed under SEC rules can be completed on a timely basis;
■ Modify or establish disclosure controls and procedures to facilitate the reporting of material cybersecurity incidents, including the nature, scope, and timing of the incident and the impact or reasonably likely impact of the incident on the company, including on the company's financial condition and results of operations, within the four-business-day deadline contemplated by new Item 1.05 of Form 8-K, as well as any information that was not determined or was unavailable at the time of the initial Form 8K filing; and
■ Prepare new disclosures for the company's annual report regarding the company's processes for the assessment, identification, and management of material risks from cybersecurity threats; whether any risks from cybersecurity threats have materially affected or are reasonably likely to materially affect their business strategy, results of operations, or financial condition; the board's oversight of risks from cybersecurity threats; and management's role in assessing and managing material risks from cybersecurity threats.

[Page 446]

Background

Since 2011, the SEC and its staff have been focused on disclosures that public companies make about cybersecurity risks.

On October 13, 2011, the SEC's Division of Corporation Finance issued disclosure guidance to assist public companies "in assessing what, if any, disclosures should be provided about cybersecurity matters in light of each registrant's specific facts and circumstances." 2 CF Disclosure Guidance Topic No. 2 reviewed the applicability of existing SEC disclosure requirements to cybersecurity concerns, noting that:

1. Businesses increasingly focus or rely on internet communications and remote data storage,
2. Risks and potential costs associated with cyber attacks and inadequate cybersecurity are increasing, and
3. As with other operational and financial risks and events, companies should, on an ongoing basis, review the adequacy of disclosure relating to cybersecurity risks and other cyber incidents.

On February 20, 2018, the SEC issued interpretive guidance, which noted that public companies should take all required actions "to inform investors about material cybersecurity risks and incidents in a timely fashion, including those companies that are subject to material cybersecurity risks but may not yet have been the target of a cyber-attack." 3 The SEC noted in this guidance the importance of disclosure controls and procedures "that provide an appropriate method of discerning the impact that such matters may have on the issuer and its business, financial condition, and results of operations, as well as a protocol to determine the potential materiality of such risks and incidents." In addition, the 2018 Interpretive Release noted that "directors, officers, and other corporate insiders must not trade a public company's securities while in possession of material nonpublic information, which may include knowledge regarding a significant cybersecurity incident experienced by the company." The SEC indicated that companies should have policies and procedures in...

Get this document and AI-powered insights with a free trial of vLex and Vincent AI

Get Started for Free

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex

Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant

  • Access comprehensive legal content with no limitations across vLex's unparalleled global legal database

  • Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength

  • Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities

  • Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting

vLex