Womble Perspectives
Welcome to Womble Perspectives, where we explore a wide range of topics from the latest legal updates to industry trends to the business of law. Our team of lawyers, professionals and occasional outside guests will take you through the most pressing issues facing businesses today and provide practical and actionable advice to help you navigate the ever-changing legal landscape. With a focus on innovation, collaboration and client service, we are committed to delivering exceptional value to our clients and to the communities we serve.
Womble Perspectives
SEC Adopts Final Rules to Enhance Cybersecurity Disclosure
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The SEC has introduced a new rule when it comes to reporting cybersecurity incidents. This episode summarizes the ins and outs of the rule and sheds light on how companies can be prepared once the rule goes into effect.
Read the full article.
Learn more about the authors:
Tara N. Cho, CIPP/US, CIPP/E (bio)
Theodore F. Claypoole (bio)
Ting Zheng, CIPP/US (bio)
Rajiv Radia (bio)
Sid Shenoy (bio)
Welcome to Womble Perspectives, where we explore a wide range of topics, from the latest legal updates to industry trends to the business of law. Our team of lawyers, professionals and occasional outside guests will take you through the most pressing issues facing businesses today and provide practical and actionable advice to help you navigate the ever changing legal landscape.
With a focus on innovation, collaboration and client service. We are committed to delivering exceptional value to our clients and to the communities we serve. And now our latest episode.
On July twenty sixth, the SEC adopted new rules to enhance and standardize disclosures related to cybersecurity risk management, strategy, governance, and material cybersecurity incidents.
Despite previous improvements in cybersecurity-related disclosures, the SEC observed inconsistency in reporting practices and the new rule is intended to achieve uniform and useful disclosures, thus empowering investors to make well-informed evaluations of a company's cybersecurity posture.
This development will require public companies to disclose any cybersecurity incident they determine to be material. The disclosure will need to address the nature, scope, and timing of the incident, as well as its material impact or likely material impact on the company, particularly its financial condition and results of operations. Once a company makes a determination, they’ll need to file a disclosure form within four business days.
There are some notable changes to the new rule, one example being that the SEC narrowed the amount of information companies need to disclose. This change was made in an effort to strike a balance between investors’ need for information and a company’s cybersecurity posture. The disclosure also focuses on the impacts of a material cybersecurity incident rather than on the details of the incident itself.
Regarding Cybersecurity Risk Management and Strategy, companies must describe their processes for assessing, identifying, and managing material risks arising from cybersecurity threats.
Some of the information in the disclosure should include whether and how such processes have been integrated into the company’s overall risk management systems, Whether the company engages certain third parties in connection with any such processes, and Whether the company has processes to oversee and identify risks from cybersecurity threats associated with its use of any third-party service provider, As applicable
Companies must also disclose whether any risks from cybersecurity threats, including as a result of previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect the company, and if so, how.
The new rule also requires companies to disclose the board of directors' oversight of risks from cybersecurity threats and management's role and expertise in assessing and managing a company’s material risks from cybersecurity threats.
In advance of these new disclosure requirements, public companies should review and update their controls and procedures to prepare for new incident reporting requirements and prepare draft disclosures of their cybersecurity risk management and strategy to review and align with internal departments and external advisors. The final rules take effect thirty days after publication in the Federal Register with different disclosure guidelines having to adhere to different deadlines.
Any questions on this development can be directed to members of our Data Security Team or Public Company Advisors Team. Detailed information can be found under the alerts section of our website at www.womblebonddickinson.com/us/insights/alerts.
Thank you for listening to Womble Perspectives. If you want to learn more about the topics discussed in this episode, please visit The Show Notes, where you can find links to related resources mentioned today. The Show Notes also have more information about our attorneys who provided today's insights, including ways to reach out to them.
Don't forget to subscribe via your podcast player of choice so that you never miss an episode. Thank you again for listening.