Main Content Main Menu

Legal Updates

Print PDF
Companies Now Have to Let Their Shareholders in on Their Cybersecurity Practices
Companies Now Have to Let Their Shareholders in on Their Cybersecurity Practices

Public companies now must disclose certain information regarding material cybersecurity incidents and the company’s cybersecurity risk management, strategy, and governance, under a Final Rule adopted by the Securities and Exchange Commission (SEC) on July 26, 2023. 

The Final Rule requires companies to disclose details concerning “material” cybersecurity incidents within four business days of determining that such an incident is “material.” These disclosures, which must be included on Forms 8-K and 6-K, must describe the nature, scope and timing of a cybersecurity incident – as well as its reasonably likely material impact on the registrant. Under the Final Rule, disclosure of a material cybersecurity incident may be delayed by up to 30 days if the U.S. Attorney General determines that disclosure would pose a substantial risk to national security or public safety.

Now more than ever public companies need to adopt proper cybersecurity incident response plans that reflect leadership’s discussions about what might be considered material for reporting purposes. Without such preparation, it will be extremely difficult for public companies to comply with the requirement that they disclose materiality findings within four business days.

Companies will have to comply beginning December 18, 2023, or within 90 days of the rule’s publication in the Federal Register, whichever is later. Smaller reporting companies will be afforded an extra 180 days to comply.

The new rules also require registrants to annually disclose on their Form 10-K information about the company’s cybersecurity strategies, risk management and governance practices, as well as information about their boards of directors’ oversight of – and their management’s role in assessing – cybersecurity-threat risks. These Form 10-K disclosures are due beginning with annual reports for fiscal years ending on or after December 15, 2023.

The SEC’s Final Rule, titled “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure” can be viewed here.

Archives

Back to Page

Connell Foley LLP Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek