logo

SEC disclosure rule for ‘material’ cybersecurity incidents goes into effect

ID: 083af9ef-4fe3-5f84-9925-4371b7bf9dbf

STIX ID: report--083af9ef-4fe3-5f84-9925-4371b7bf9dbf

Feed Name: CyberScoop

Date Published: 2023-12-18

Date Updated: 2026-04-21

Author: mbracken

...
...

The report analyzes the SEC’s new rule mandating publicly traded companies to disclose material cybersecurity incidents within four business days and to annually describe their cybersecurity risk management, addressing concerns about overlap with CISA’s CIRCIA reporting, potential national security risks, and increased CISO liability. It notes DOJ guidance that disclosures generally benefit investors and public safety while allowing limited delays for sensitive scenarios. Expert commentary highlights the need for defensible materiality assessments, the heightened impact on critical infrastructure operators, and the imperative to strengthen OT/IoT security and incident response readiness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.