SEC proposes significant new cybersecurity disclosure requirements

SEC Update

On March 9, 2022 the SEC proposed rule amendments that would require public companies to report detailed information about material cybersecurity incidents affecting their business and about their cybersecurity risk management and governance. The new requirements are intended to promote standardization of cybersecurity disclosure and the comparability of such disclosure across companies and time periods.

The SEC proposes to amend Regulation S-K and Exchange Act forms to require companies to report cybersecurity incidents on Form 8-K within four business days after the company determines the incident is material. Companies would also be required to provide updated disclosures on Forms 10-Q and 10-K about previously disclosed incidents, as well as to disclose in their periodic reports any series of previously undisclosed individually immaterial incidents that has become material in the aggregate.

The proposed requirements would extend beyond incident reporting to include information intended to enable investors to evaluate companies’ ability to manage and mitigate their cybersecurity risk and exposure. Companies would be required to describe in their Form 10-K reports their policies and procedures for identifying and managing cybersecurity risk, including whether they consider cybersecurity risk as part of their business strategy, financial planning, and capital allocation.

The annual reporting requirements would also encompass disclosure about the board’s oversight of cybersecurity risk, management’s cybersecurity expertise, management’s role in assessing and managing cybersecurity risk, and its role in implementing the company’s cybersecurity policies, procedures, and strategies. In addition, companies would be obligated to disclose on Form 10-K and in their annual proxy statements whether any board member has cybersecurity expertise and, if so, to describe the nature of that expertise.

The SEC’s release describing the proposed amendments (Release No. 33-11038) can be viewed here. The comment period on the proposal will be open until May 9.

Read more:

button

 

 

 

Authored by Alan Dye (co-editor), Richard Parrino (co-editor), John Beckman, Kevin Greenslade, William Intner, Paul Otto, Harriet Pearson, and Nicholas Hoover.

Contacts
Alan Dye
Partner
Washington, D.C.
Richard Parrino
Partner
Washington, D.C.
John Beckman
Partner
Washington, D.C.
Kevin Greenslade
Partner
Northern Virginia
William Intner
Partner
Baltimore
Paul Otto
Partner
Washington, D.C.
Nick Hoover
Counsel
Baltimore
Steve Abrams
Partner
Philadelphia
Richard Aftanas
Partner
New York
Tifarah Allen
Partner
Washington, D.C.
Jessica Bisignano
Partner
Philadelphia
David Bonser
Partner
Washington, D.C.
Glenn Campbell
Partner
Baltimore
John Duke
Office Managing Partner
Philadelphia
Allen Hicks
Partner
Washington, D.C.
Paul Hilton
Senior Counsel
Denver
Eve Howard
Senior Counsel
Washington, D.C.
Bob Juelke
Partner
Philadelphia
Paul Manca
Partner
Washington, D.C.
Michael McTiernan
Partner
Washington, D.C.
Brian O'Fahey
Partner
Washington, D.C.
Les Reese
Partner
Washington, D.C.
Richard Schaberg
Partner
Washington, D.C.
Michael Silver
Partner
New York
Andrew Zahn
Partner
Washington, D.C.
Stephen Nicolai
Partner
Philadelphia

 

This website is operated by Hogan Lovells International LLP, whose registered office is at Atlantic House, Holborn Viaduct, London, EC1A 2FG. For further details of Hogan Lovells International LLP and the international legal practice that comprises Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses ("Hogan Lovells"), please see our Legal Notices page. © 2024 Hogan Lovells.

Attorney advertising. Prior results do not guarantee a similar outcome.