SEC Adopts Rules Requiring Public Companies to Disclose Cybersecurity Breaches

The Securities and Exchange Commission has adopted new rules requiring public companies to disclose within four days any cybersecurity breaches that could affect their bottom lines. This move aims to protect investors by providing transparency into what can be an "opaque but growing risk." Delays in disclosure will be permitted only in cases where immediate disclosure poses serious national security or public safety risks.

Key Takeaways:

  • Public companies must disclose all cybersecurity breaches within four days, except in cases where national security or public safety is at risk.
  • Delays in disclosure can be allowed for up to 60 days, but only under extraordinary circumstances.
  • The new rules also require annual disclosure of information on cybersecurity risk management and executive expertise in the field.
  • Failure to comply with the new rules may pose a challenge for smaller companies with limited resources.
  • Lesley Ritter, senior VP at Moody's Investors Service, notes that the new rules may spur improvements in cyber defenses.
  • The rules were first proposed in March 2022, when the SEC determined that cybersecurity breaches posed an escalating risk due to the increasing digitization of operations and remote work.
  • Companies affected by a breach in a widely used file transfer program, MOVEit, include multiple universities, major pensions funds, U.S. government agencies, and over 100 other organizations.
  • Researchers at IBM found that organizations now pay an average of $4.5 million to deal with breaches, a 15% increase over the past three years.
  • The Ponemon Institute researchers found that impacted businesses typically pass the costs on to consumers, who may also be victims of personal information theft in a breach.

Statistics:

  • 4 days: the time frame within which public companies must disclose all cybersecurity breaches that could affect their bottom lines.
  • 60 days: the maximum period during which delays in disclosure may be permitted.
  • $4.5 million: the average cost to organizations to deal with breaches, according to IBM researchers.
  • 15%: the increase in the cost to deal with breaches over the past three years, according to IBM researchers.
  • 9 million: the number of motorists in Oregon and Louisiana who were impacted by a major data breach involving the MOVEit file transfer program.

Sources:

  • AP news wire
  • [Source 1: SEC statement by Gary Gensler]
  • [Source 2: IBM research on breach costs]
  • [Source 3: Ponemon Institute research on breach impacts on consumers]