SEC Imposes New Cybersecurity Disclosure Requirements

McDermott Will & Emery

At an Open Meeting on July 26, 2023, the US Securities and Exchange Commission (SEC) adopted final rules and amendments that impose new cybersecurity-related disclosure requirements for public companies subject to the Securities and Exchange Act of 1934’s reporting requirements. The new rules require domestic registrants to disclose material cybersecurity incidents within four business days of determining that an incident is material and to periodically disclose information regarding the company’s cybersecurity risk management, strategy and governance. The SEC also adopted rules requiring foreign private issuers to make comparable disclosures.

The rules reflect the SEC’s growing concern over an increase in cybersecurity threats and existing inconsistent disclosure requirements and are intended to enhance and standardize disclosures regarding cybersecurity risk management, strategy, governance and incidents. In a statement announcing the rules’ adoption, SEC Chair Gary Gensler emphasized the importance of cybersecurity disclosure to investors being “more consistent, comparable, and decision-useful.”

IN DEPTH


DISCLOSING MATERIAL CYBERSECURITY INCIDENTS ON NEW ITEM 1.05 ON FORM 8-K

The new rules will require registrants to disclose any cybersecurity incident they determine to be material on Form 8-K’s new Item 1.05. They will also need to describe the material aspects of the incident’s nature, scope, and timing and its material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations. Registrants must determine the materiality of an incident without unreasonable delay following discovery and, if the incident is determined material, file an Item 1.05 Form 8-K generally within four business days after such determination. The disclosure may be delayed if the United States Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the SEC of such determination in writing. The rules require comparable disclosures by foreign private issuers on Form 6-K.

DISCLOSING CYBERSECURITY RISK MANAGEMENT, STRATEGY AND GOVERNANCE IN ANNUAL REPORTS

The new rules also add Regulation S-K Item 106, which will require registrants to describe:

  • Their processes (if any) for assessing, identifying and managing material risks from cybersecurity threats.
  • The material effects or reasonably likely material effects of risks from cybersecurity threats and previous cybersecurity incidents.
  • The Board of Directors’ oversight of risks from cybersecurity threats and management’s role and expertise in assessing and managing material risks from cybersecurity threats.

These disclosures will be required in a registrant’s annual report on Form 10-K. The rules require comparable disclosures by foreign private issuers on Form 20-F.

IMPLEMENTATION

The final rules will take effect 30 days following publication of the adopting release in the Federal Register. All registrants must tag the disclosures in Inline Extensible Business Reporting Language (Inline XBRL) beginning one year after initial compliance with the related disclosure requirement. Form 10-K and Form 20-F disclosures will be due beginning with annual reports for fiscal years ending on or after December 15, 2023. Form 8-K and Form 6-K disclosures will be due beginning 90 days after the date of publication in the Federal Register or December 18, 2023, whichever is later. Smaller reporting companies will have an additional 180 days and must begin complying with Form 8-K Item 1.05 on the later of 270 days from the effective date of the rules or by June 15, 2024.

***

Staying on top of the ever-evolving legal landscape can be challenging. Creating an effective, comprehensive program for your organization requires a thorough understanding of relevant legal obligations, especially those subject to new SEC regulations that impact your cybersecurity programs. Our Global Privacy & Cybersecurity and Corporate & Transactional teams can help you navigate the various compliance requirements affecting your business, ensuring you remain secure and compliant.

Heidi Hutchins and Morgan King, summer associates in the Washington, DC, office, also contributed to this article.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© McDermott Will & Emery | Attorney Advertising

Written by:

McDermott Will & Emery
Contact
more
less

McDermott Will & Emery on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide