Auditen
Home / Frameworks / SEC Cyber Disclosure / Disclosure controls and procedures for cyber incidents

Disclosure controls and procedures for cyber incidents

Disclosure controls and procedures (DCPs) for cyber incidents require public companies to implement a formal process ensuring that information about cybersecurity risks and incidents is communicated up the chain of command. The goal is to ensure that "material" incidents are identified and reported to management and the board in time to meet SEC filing deadlines.

What it means

In practice, this requirement creates a mandatory bridge between your technical security operations (SOC/IR teams) and your legal and financial reporting functions. It is not enough to have a technical Incident Response Plan focused on containment; you must have a governance process that determines if an incident has a "material" impact on the company's financial condition or operations.

The scope extends beyond the IT department. It involves the coordination of CISO, Legal, CFO, and potentially a Disclosure Committee. The intent is to prevent situations where technical teams are aware of a breach for weeks while the executives responsible for SEC filings remain uninformed.

How to meet it

Evidence an auditor asks for

  • The written Incident Response Plan or Governance Policy explicitly detailing the escalation path to legal/financial leadership.
  • Documented materiality frameworks or checklists used by management to evaluate whether a cyber incident requires public disclosure.
  • Minutes from Disclosure Committee or Board meetings where cybersecurity risks and specific incidents were discussed.
  • Evidence of training provided to key personnel on their roles in the SEC disclosure process.

Common pitfalls

  • Treating "materiality" as a purely technical decision (e.g., based only on the number of records lost) rather than a business/financial decision.
  • Relying on informal communication (emails and chats) without a standardized, repeatable process for escalating incidents to the board.
  • Assuming that general corporate disclosure controls are sufficient without adding specific triggers for the speed and nature of cybersecurity events.