Making Sense of the New SEC Cybersecurity Rules and What They Could Mean for Your Company

The United States Securities and Exchange Commission’s (SEC) July 26 approval of new cybersecurity “incident” disclosure rules is top of mind for every public company, and understanding what it means and how companies will be held accountable is crucial. The rules were initially introduced in March 2022 but the Commission’s deliberation on disclosing cyber incidents began over ten years ago. Let’s dig into it.

The new rules, which will go into effect later this year, require that publicly-traded companies (or “registrants”) disclose a “material” cybersecurity incident within four business days of determining an incident was material. There is an exception to the reporting timeline, which allows for a delay if disclosing the incident could harm national security or public safety. However, only the United States Attorney General must grant such an exception.

What is most interesting is that registrants must disclose the impact of a material cybersecurity incident but are not required to disclose the technical details, such as the vulnerabilities exploited or the indicators of compromise.The rules will require the registrant to “describe the material aspects of the nature, scope, and timing of the incident, and the material impact or reasonably likely material impact on the registrant, including its financial condition and results of operations.”

In addition to cyber incident disclosure requirements, the SEC also mandates that public companies periodically disclose information regarding their cybersecurity risk management, strategy, governance and risk factors.

The upshot of the new rule means that while companies do not have to disclose the technical details of an incident, they need two capabilities to respond and report on a timely basis:

A Roadmap to Rapid Resilience

Service disruptions often look the same, but internal teams need help to obtain the holistic view required to solve a problem quickly. The field is crowded with players in roles ranging from business leaders, security, operations, IT, and audit, to engineers, developers, and architects. So how do you prepare and recover from unexpected cyber disruptions quickly?

It starts with public companies adequately investing in the right people, technology and processes that enable cyber resilience. This makes it possible for SecOps, ITOps, and engineering to collaborate with the right tools to prevent significant issues, remediate quickly, and accelerate transformation.

The new SEC rules drive publicly-traded companies — like Splunk — to take a resilient-first technology approach that enable improved visibility of IT and OT infrastructure, including:

Click here to learn more about Spunk’s ability to help increase your cyber resilience and help meet the SEC’s disclosure requirements.

Related Articles

Using stats, eventstats & streamstats for Threat Hunting…Stat!
Security
5 Minute Read

Using stats, eventstats & streamstats for Threat Hunting…Stat!

The stats command is a crucial capability when you’re threat hunting. And so are two related commands: eventstats & streamstats. Get all the details, right here.
Splunk BOTS 4.0: A New Hope
Security
3 Minute Read

Splunk BOTS 4.0: A New Hope

From the basics, to new data, to registration information, discover all you need to know about Splunk BOTS 4.0 at .conf19.
Detecting the Sudo Baron Samedit Vulnerability and Attack
Security
3 Minute Read

Detecting the Sudo Baron Samedit Vulnerability and Attack

Looking for ways to detect and protect against the SUDO Baron Samedit vulnerability (CVE-2021-3156)? Look no further. In this blog we tell you how to proactively detect vulnerable servers using Splunk and also to detect malicious folks who are attempting to exploit this vulnerability for nefarious outcomes!