Featured

Published on March 11th, 2022 📆 | 7471 Views ⚑

0

SEC proposes rule changes to standardize cybersecurity disclosures by public companies


tts

The U.S. Securities and Exchange Commission (SEC) has proposed rule changes designed to enhance and standardize disclosures for cybersecurity risk management by public companies.

Ā© Shutterstock

The proposed amendments would require current reporting about material cybersecurity incidents and periodic reporting to provide updates about previously reported cybersecurity incidents. In addition, it would require periodic reporting about a registrantā€™s policies and procedures to identify and manage cybersecurity risks, as well as the boardā€™s oversight of cybersecurity risk and managementā€™s role in assessing and managing cybersecurity risk and implementing cybersecurity policies and procedures.

Further, it would require annual reporting or certain proxy disclosure about the board of directorsā€™ cybersecurity expertise.

ā€œOver the years, our disclosure regime has evolved to reflect evolving risks and investor needs,ā€ SEC Chair Gary Gensler said. ā€œToday, cybersecurity is an emerging risk with which public issuers increasingly must contend. Investors want to know more about how issuers are managing those growing risks. A lot of issuers already provide cybersecurity disclosure to investors. I think companies and investors alike would benefit if this information were required in a consistent, comparable, and decision-useful manner. I am pleased to support this proposal because, if adopted, it would strengthen investorsā€™ ability to evaluate public companiesā€™ cybersecurity practices and incident reporting.ā€





The proposed amendments are designed to better inform investors about a registrantā€™s risk management, strategy, and governance while timely notification to investors of cybersecurity incidents.

The comment period will remain open for 60 days following publication of the proposal on the SECā€™s website or 30 days following publication of the release in the Federal Register, whichever period is longer.

Source link

Tagged with: ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢



Comments are closed.