{"id":18513,"date":"2023-06-22T06:29:16","date_gmt":"2023-06-22T13:29:16","guid":{"rendered":"https:\/\/essential.construction\/news\/sec-delays-final-rule-on-cyber-incident-disclosure-as-industry-pushes-back\/"},"modified":"2023-06-22T06:29:17","modified_gmt":"2023-06-22T13:29:17","slug":"sec-delays-final-rule-on-cyber-incident-disclosure-as-industry-pushes-back","status":"publish","type":"post","link":"https:\/\/essential.construction\/news\/sec-delays-final-rule-on-cyber-incident-disclosure-as-industry-pushes-back\/","title":{"rendered":"SEC delays final rule on cyber incident disclosure as industry pushes back"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p><span><span><span><span><span><span>The Securities and Exchange Commission has <\/span><\/span><\/span><\/span><\/span><\/span><a rel=\"nofollow noopener\" href=\"https:\/\/www.reginfo.gov\/public\/do\/eAgendaViewRule?pubId=202304&amp;RIN=3235-AM89\" target=\"_blank\"><span><span><span><span><span><span><span><span>postponed until October<\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/a><span><span><span><span><span><span> a final rule that would require publicly traded companies to report material cyber breaches and attacks in regulatory filings.\u00a0<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>The rule, initially proposed in March 2022, would require public companies to submit a filing within four days of determining whether a cyber breach is material.\u00a0<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>As part of that proposal, the SEC also sought additional <\/span><\/span><\/span><\/span><\/span><\/span><a rel=\"nofollow noopener\" href=\"https:\/\/www.insideprivacy.com\/cybersecurity-2\/sec-delays-cybersecurity-rules\/?_gl=1*1e668d3*_ga*MTc5NTQyNDYyOC4xNjg2OTE0MTcw*_ga_KSNMJSN08X*MTY4NjkyNDY2OS4zLjAuMTY4NjkyNDY2OS4wLjAuMA..\" target=\"_blank\"><span><span><span><span><span><span><span><span>disclosures from companies regarding their cyber governance<\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/a><span><span><span><span><span><span>, including board expertise and upper management involvement in cyber risk.\u00a0<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>The SEC also proposed investment companies and advisors adopt written cybersecurity policies in February 2022.<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>The proposal stemmed from years of companies delaying or failing to disclose significant cyber breaches or ransomware attacks.\u00a0<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p>C<span><span><span><span><span><span>ompanies have historically only reported about one-quarter of ransomware attacks to public authorities, <\/span><\/span><\/span><\/span><\/span><\/span><a rel=\"nofollow noopener\" href=\"https:\/\/www.cybersecuritydive.com\/news\/senate-ransomware-cisa\/624369\/\" target=\"_blank\"><span><span><span><span><span><span><span><span>according to a report from the U.S. Senate released in 2022<\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/a>.<span><span><span><span><span><span>\u00a0These incidents have largely been kept confidential, with arranged ransom payments to avoid data disclosures, consumer or investor lawsuits and reputational harm.<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>IT security experts say the delay will increase the level of risk, because many investors, consumers and companies will rely on voluntary disclosure of major cyberattacks.\u00a0<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>\u201c<\/span><\/span><\/span><\/span><\/span><\/span><span><span><span><span><span><span><span>Without the hammer the SEC regulations can bring, reporting breaches will continue to be voluntary and historically that doesn&#8217;t work,\u201d Gary Barlet, field CTO, federal at Illumio, said via email.\u00a0<\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>SEC officials have not publicly stated the reasons for the delay, but there has been significant pushback from various stakeholders regarding the four-day disclosure proposal.\u00a0<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>Some organizations, like cybersecurity firm Rapid7, argued the proposed disclosure rules would risk making ongoing attacks part of the public record. Therefore, disclosure would potentially tip off criminal hackers if a company was required to go public before the incident was contained.<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<p><span><span><span><span><span><span>Rapid7 officials asked the SEC for the ability to <\/span><\/span><\/span><\/span><\/span><\/span><a rel=\"nofollow noopener\" href=\"https:\/\/www.sec.gov\/comments\/s7-09-22\/s70922-20137661-308069.pdf\" target=\"_blank\"><span><span><span><span><span><span><span><span>let companies delay disclosure<\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/a><span><span><span><span><span><span> until attacks were mitigated.\u00a0<\/span><\/span><\/span><\/span><\/span><\/span><\/p>\n<\/p><\/div>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/www.constructiondive.com\/news\/sec-delay-final-rule-incident-disclosure\/653284\/\" rel=\"nofollow noopener\" target=\"_blank\">This article was originally posted at Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] The Securities and Exchange Commission has postponed until October a final rule that would require publicly traded companies to &#8230; <a title=\"SEC delays final rule on cyber incident disclosure as industry pushes back\" class=\"read-more\" href=\"https:\/\/essential.construction\/news\/sec-delays-final-rule-on-cyber-incident-disclosure-as-industry-pushes-back\/\" aria-label=\"Read more about SEC delays final rule on cyber incident disclosure as industry pushes back\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":18514,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[457],"tags":[],"class_list":["post-18513","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-construction-dive","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-33"],"_links":{"self":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts\/18513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/comments?post=18513"}],"version-history":[{"count":0,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts\/18513\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/media\/18514"}],"wp:attachment":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/media?parent=18513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/categories?post=18513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/tags?post=18513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}