How Can Organizations Navigate SEC's Cyber Materiality Disclosures?
ID: a596c04a-962f-504f-a3b7-d14d0612cfa9
STIX ID: report--a596c04a-962f-504f-a3b7-d14d0612cfa9
Feed Name: Dark Reading
The piece advises CISOs and executives on complying with SEC cyber-disclosure rules by adopting standardized, quantitative materiality thresholds (proposing 0.01% of annual revenue as a preliminary starting point) and complementary operational metrics (e.g., percentage of records compromised, outage hours). It emphasizes engaging stakeholders to set and document multiple loss scenarios, calculating likelihoods for Form 10-K line 1C, and using predefined thresholds to speed Form 8-K assessments and justify disclosure decisions while considering qualitative impacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
