Skip to Content
Flags outside government building
Article

The SEC and cybersecurity: What you need to know

January 23, 2019 / 3 min read

The SEC issued new guidance around cybersecurity disclosures, which likely affect your organization. Consider your procedures for effective disclosures, the process for notifying investors, as well as the forms that require this information and how to best adhere to this guidance.

Background

In October 2011, the Division of Corporate Finance issued guidance that provided views regarding disclosure obligations relating to cybersecurity risks and incidents. The guidance explains that, although no existing disclosure requirement explicitly refers to cybersecurity risk and cyber incidents, companies nonetheless may be obligated to disclose such risks and incidents. After the issuance of this guidance, many companies included additional cybersecurity disclosure, typically in the form of risk factors.

On Feb. 21, 2018, the SEC issued interpretive guidance in response to the ongoing risks and threats that cybersecurity presents to our capital markets and to companies operating in all industries, including public companies regulated by the Commission. Companies today rely more and more on digital technology to conduct their business operations and engage with their customers, business partners, and other constituencies. The U.S. Computer Emergency Readiness Team defines cybersecurity as “the activity or process, ability or capability, or state whereby information and communications systems and the information contained therein are protected from and/or defended against damage, unauthorized use or modification, or exploitation.”

Who does this guidance apply to?

When is it effective?

What is the SEC’s new guidance related to cybersecurity disclosures?

Public companies must inform investors about material cybersecurity risks and incidents, including breaches, in a timely fashion.

Where does this information need to be disclosed?

Why is the SEC providing additional guidance?

How can companies adhere to the SEC guidance?

Actions to take

Public company executives and their boards should revisit disclosures and disclosure controls and procedures, including controls over the sales of securities by executives. To learn more, or to understand how this cybersecurity guidance may impact your business, please contact us today.

Related Thinking

Wealthy couple talking to their financial advisor.
January 16, 2025

Why the Change Healthcare breach is a wake-up call for CFOs

In The News 5 min read
Business professionals in a conference room discussing FFIEC CAT sunset
December 16, 2024

FFIEC CAT sunset: Considerations for choosing a new cybersecurity framework

Article 6 min read
Business professional checking the multifactor authentication code on their cell phone.
November 1, 2024

Preparing for the inevitable: Navigating third-party tech failures

Article 7 min read