Navigating the SEC’s Cybersecurity Disclosure Rules: One Year On
ID: 541b8cdd-be07-5418-8d5f-26f1f39270e0
STIX ID: report--541b8cdd-be07-5418-8d5f-26f1f39270e0
Feed Name: Tenable Blog
This report analyzes the SEC’s cybersecurity disclosure rules—requiring material incident disclosure within four business days and annual reporting on risk management and governance—alongside early enforcement actions (e.g., nearly $7M in combined settlements involving Unisys, Avaya, Check Point, Mimecast over SolarWinds-related disclosures, and R.R. Donnelley’s $2.1M settlement), and offers guidance for CISOs and boards on achieving compliance. It stresses materiality-driven disclosures, transparent governance details, and proactive programs (exposure management, vulnerability management, zero trust, robust incident response) to align cybersecurity with business risk and investor expectations, noting related global trends such as the EU’s NIS2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
