The incident disclosure requirements of the US Securities and Exchange Commission’s cybersecurity disclosure rules take effect today for most public companies.
Key points
- Material cybersecurity incidents must be disclosed on Form 8-K (or Form 6-K for foreign private issuers) within four business days of a materiality determination.
- Annual reports must describe cyber risk management processes, strategy and governance, including board oversight.
- Disclosure may be delayed only where the US Attorney General considers it a substantial risk to national security or public safety.
- Smaller reporting companies have until 15 June 2024 to comply with the incident disclosure requirement.
UK companies listed in the US, and suppliers to US-listed firms, should make sure incident escalation processes support fast materiality decisions.
Source: SEC cybersecurity disclosure final rule (Federal Register)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.