The Securities and Exchange Commission has proposed amendments to its cybersecurity disclosure framework that would materially expand registrants' obligations around incident reporting, materiality determination, and board-level oversight. Public companies should review the proposed rule and consider participating in the comment period.
The proposed amendments tighten the four-business-day reporting clock by clarifying the trigger event, introduce a new materiality framework that incorporates downstream supply-chain effects, and require enhanced disclosure regarding board-level cybersecurity governance. Companies should also anticipate increased SEC examination focus on the consistency between cybersecurity disclosures and underlying incident-response documentation.
Authors