According to a press release yesterday from the United States Securities and Exchange Commission (SEC), the agency has "adopted rules requiring registrants to disclose material cybersecurity incidents they experience and to disclose on an annual basis material information regarding their cybersecurity risk management, strategy, and governance. The Commission also adopted rules requiring foreign private issuers to make comparable disclosures."
"Whether a company loses a factory in a fire—or millions of files in a cybersecurity incident—it may be material to investors," said SEC Chair Gary Gensler. "Currently, many public companies provide cybersecurity disclosure to investors. I think companies and investors alike, however, would benefit if this disclosure were made in a more consistent, comparable, and decision-useful way. Through helping to ensure that companies disclose material cybersecurity information, today's rules will benefit investors, companies, and the markets connecting them.”
Most cybersecurity professionals were expecting the new regulations to go into affect in October of this year, so this news is an eye-opener for CISOs and other business leaders.
[RELATED: SEC to Put More Onus on Corporate Boards for Cybersecurity]
Jerry Perullo, Cybersecurity Advisor, Founder, and Professor, added this perspective on the news in a LinkedIn post:
"I'm pleased to see thoughtful consideration of the comments many of us submitted. Key takeaways and changes from the original proposal include:[RELATED: Less than 10% of Fortune 500 Ready for New SEC Cyber Regulations]
The new regulations were approved by a 3-2 vote.
A few days prior to the vote, Nakul Goenka, Founder of the Houston Legal Tech Association, wrote this post on LinkedIn breaking down the implications of the now-enacted regulations.
"There are five main disclosure requirements which the SEC is proposing:
1. Reporting of 'material' cybersecurity incidents.
2. Ongoing reporting of 'material' cybersecurity incidents.
3. Disclosures of cybersecurity policies, governance and management.
4. Disclosure if any Director has cybersecurity expertise.
5. Disclosure for foreign private issuers."
Check out the article for specifics to all five disclosure requirements.
Brian Walker, Founder and CEO of The CAP Group, had this to say in a LinkedIn post:
"Today's SEC vote requiring material breach disclosures appears to mostly affect CISOs and leadership teams more than board directors but disclosure rules have major implications for all stakeholders.
According to World Economic Forum's Global Security Outlook, 14 market days after a security breach goes public, average share price bottoms out and underperforms NASDAQ by -3.5% and even 6 months later is still -3.0% under the NASDAQ.
While it seems the SEC is taking a cyber reporting path that aligns more with operational security than governance, investors and the general public will likely continue to monitor companies' cyber governance expertise to mitigate the financial and reputational risk related to breach disclosures."
[RELATED: InfoSec Leaders Weigh in on New SEC Rules Making CISO Hotseat Hotter]