Notes:

  • The SEC Cybersecurity Rule (2023):
    • Incident Disclosure (Form 8-K): Public companies must disclose material cybersecurity incidents within 4 business days of determining the incident is material.
      • Materiality: Does the incident affect financial condition, operations, or reputation?
      • Content: Description of the incident, timing, and impact.
    • Annual Disclosure (Form 10-K): Companies must disclose their risk management, strategy, and governance of cybersecurity risks.
      • Board Oversight: Describe the board’s role in overseeing cyber risk (e.g., which committee has responsibility, frequency of reporting).
      • Management Expertise: Disclose whether any board member has cybersecurity expertise.
  • NIST Framework Integration:
    • Most companies align their cyber risk management with the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover).
    • Governance bodies must ensure this framework is implemented and tested regularly.
  • Board Competency:
    • Boards are increasingly expected to have at least one director with cybersecurity expertise.
    • If no expert exists, the board must demonstrate how they access expert advice (e.g., via external consultants).
  • Ransomware and Supply Chain Risks:
    • Disclosure must address risks from third-party vendors (supply chain attacks).
    • Companies must have incident response plans that are tested via tabletop exercises, often reviewed by the board.
  • Global Variations:
    • EU (NIS2 Directive): Stricter requirements for incident reporting (24-hour initial notification) for essential entities.
    • US (CISA): Voluntary reporting for critical infrastructure, but mandatory for federal contractors.