logo

Navigating the SEC’s Cybersecurity Disclosure Rules: One Year On

ID: 541b8cdd-be07-5418-8d5f-26f1f39270e0

STIX ID: report--541b8cdd-be07-5418-8d5f-26f1f39270e0

Feed Name: Tenable Blog

Date Published: 2024-12-30

Date Updated: 2026-05-01

Author: Steve Vintz

...
...

This report analyzes the SEC’s cybersecurity disclosure rules—requiring material incident disclosure within four business days and annual reporting on risk management and governance—alongside early enforcement actions (e.g., nearly $7M in combined settlements involving Unisys, Avaya, Check Point, Mimecast over SolarWinds-related disclosures, and R.R. Donnelley’s $2.1M settlement), and offers guidance for CISOs and boards on achieving compliance. It stresses materiality-driven disclosures, transparent governance details, and proactive programs (exposure management, vulnerability management, zero trust, robust incident response) to align cybersecurity with business risk and investor expectations, noting related global trends such as the EU’s NIS2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.