Addressing the new SEC cyber incident disclosure rules
ID: e9a96bb6-9850-56c7-ac27-3aeaec0ebf72
STIX ID: report--e9a96bb6-9850-56c7-ac27-3aeaec0ebf72
Feed Name: Expel Blog
**Executive summary:** The SEC now requires publicly traded companies to disclose material cyber incidents within four days of determining materiality and to provide detailed information on incident nature, scope, impact, remediation, and board-level cyber risk governance; this tight timeline and expanded disclosure expectations will increase burdens on incident response, investor relations, and legal teams. The report summarizes the new rules, highlights ambiguity around materiality and the operational challenges of rapid, accurate reporting, and describes how Expel's incident findings, severity assessments, and investigation capabilities can help organizations comply with the requirements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
