SEC Cybersecurity Disclosure Rules (2023)
The SEC Cybersecurity Disclosure Rules require public companies to disclose material cybersecurity incidents and provide annual reports on their cyber risk management and governance. These rules exist to ensure investors have consistent, comparable information regarding a company's exposure to cyber threats and its ability to manage them.
Who it applies to
- Publicly traded companies registered under the US Securities Exchange Act of 1934.
- Foreign private issuers (FPIs) listed on US stock exchanges.
- Any entity required to file periodic reports with the SEC, such as Form 10-K or 20-F.
How it works
The standard is divided into two primary disclosure requirements: incident reporting and annual strategy disclosure. For incidents, companies must file a Form 8-K (Item 1.05) within four business days after determining that a cybersecurity incident is "material." The filing must describe the nature, scope, and timing of the incident, as well as its impact or reasonably likely impact on the company.
For annual reporting, companies must include detailed information in their Form 10-K describing their processes for assessing, identifying, and managing material risks from cybersecurity threats. This includes disclosing whether any third-party experts are used and how those experts are integrated into the risk management process.
Unlike technical certifications (such as ISO 27001), there is no one-time audit or certification. Compliance is an ongoing regulatory obligation based on internal materiality assessments and periodic public filings. The SEC focuses on whether the disclosures accurately reflect the company's actual governance and risk posture.
Getting started
- Establish a formal "materiality" framework to determine when a cyber incident crosses the threshold from a technical event to a reportable financial or operational event.
- Update Incident Response Plans (IRP) to include specific triggers and workflows for notifying legal and financial teams for SEC reporting purposes.
- Define and document the roles of management and the board of directors in overseeing cybersecurity risks to satisfy annual disclosure requirements.
- Create a communication bridge between the Chief Information Security Officer (CISO) and the CFO/General Counsel to ensure technical data is translated into materiality assessments quickly.
- Review current third-party risk management processes to ensure they align with the disclosures made regarding external expertise.
Controls & requirements
- Determining whether an incident is material
- 8-K Item 1.05 The four-business-day incident disclosure
- The national-security and public-safety delay provision
- Reg S-K Item 106 Annual disclosure: risk management, strategy and governance
- Board oversight and management's role
- Disclosure controls and procedures for cyber incidents
- How the rules apply to smaller reporting companies
- Enforcement actions and early lessons
Common misconceptions
- Every cybersecurity breach must be reported; in reality, only those determined to be "material" to a reasonable investor require disclosure.
- The four-day reporting clock begins at the moment of detection; it actually begins once the company determines that the incident is material.
- This is a technical security standard; it is actually a regulatory transparency requirement focused on financial and operational risk rather than specific software or hardware configurations.