"SEC Implements Cybersecurity Rules for Public Companies' Risk Management and Incident Disclosure"
The Securities and Exchange Commission (SEC) has adopted new rules that require public companies to disclose material cybersecurity incidents and provide annual information on their cybersecurity risk management, strategy, and governance. The rules also apply to foreign private issuers. The disclosures must be made in a consistent and comparable manner to benefit investors and the markets. Registrants will need to disclose the nature, scope, timing, and impact of cybersecurity incidents, as well as describe their processes for assessing and managing cybersecurity risks. The rules will become effective 30 days after publication and compliance deadlines vary depending on the type of disclosure.
Reading Insights
1
10
2 min
vs 3 min read
79%
480 → 101 words
Want the full story? Read the original article
Read on SEC.gov