In December 2023, the U.S. Securities and Exchange Commission’s (“SEC”) new rule requiring disclosure of material cybersecurity incidents became effective. SPB previously analyzed how the new rule applies to incidents affecting third-party vendors and what companies can do to manage reporting risks created by third-party cybersecurity incidents. In the first half of 2024, more than a dozen companies reported cybersecurity incidents pursuant to the new rule using the new Item 1.05 in the updated Form 8-K. The new Item 1.05 requires an issuer to disclose specific information about a cybersecurity incident within four business days of its determination that the incident is material. This new rule makes the materiality determination pivotal in a company’s response to a cybersecurity incident and raises an important question about who should be involved in making the pivotal determination.
Latest Post
More Posts
Recent Discover Lawsuits Provide Compliance Lessons
DOJ Updates Ephemeral Messaging Guidance
DOJ Announces New Corporate Enforcement Strategy
DOJ Ends “China Initiative” Targeting Economic Espionage
Subscribe: Subscribe via RSS
Blogs
Firm/Org