Don’t do SECURITY. Do business SECURELY.

SEC cybersecurity incident disclosure rules take effect

US-listed companies must now disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality.

The incident disclosure requirements of the US Securities and Exchange Commission’s cybersecurity disclosure rules take effect today for most public companies.

Key points

  • Material cybersecurity incidents must be disclosed on Form 8-K (or Form 6-K for foreign private issuers) within four business days of a materiality determination.
  • Annual reports must describe cyber risk management processes, strategy and governance, including board oversight.
  • Disclosure may be delayed only where the US Attorney General considers it a substantial risk to national security or public safety.
  • Smaller reporting companies have until 15 June 2024 to comply with the incident disclosure requirement.

UK companies listed in the US, and suppliers to US-listed firms, should make sure incident escalation processes support fast materiality decisions.

Source: SEC cybersecurity disclosure final rule (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights