New SEC Cyber Disclosure Rules
The new SEC rules require publicly traded companies to enhance and standardize disclosures of cyber incidents. At a high level, the rules require public companies to report “material” cybersecurity incidents within four business days after discovery, as well as file updates on previously disclosed incidents. Additionally, companies are required to disclose their risk management practices and the board’s role in cybersecurity oversight.