SEC Adopts Rules on Public Company Cybersecurity Disclosures
sec.gov
sec.gov
Wow, that's a short amount of time. Sometimes you know. something is material before you know much about it. And now you have to not only gather the data, but publish a legal SEC form that you can get sued over in....96 hours.
Specifically, we propose to amend Form 8-K by adding new Item 1.05 that would require a registrant to disclose the following information about a material cybersecurity incident, to the extent the information is known at the time of the Form 8-K filing:
When the incident was discovered and whether it is ongoing;
A brief description of the nature and scope of the incident;
Whether any data was stolen, altered, accessed, or used for any other unauthorized purpose;
The effect of the incident on the registrant's operations; and
Whether the registrant has remediated or is currently remediating the incident
https://www.federalregister.gov/documents/2022/03/23/2022-05...
Making this a private disclosure to the SEC is fine. But public publication only 96 hours after discovery will lead to issues.
"In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. 2Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay."
OK, it's not ALL cybersecurity incident but limited to personal data breach... but the delay is 72h !
So, in a way, it look to me like SEC is only playing catch-up