Notes:
- The SEC Cybersecurity Rule (2023):
- Incident Disclosure (Form 8-K): Public companies must disclose material cybersecurity incidents within 4 business days of determining the incident is material.
- Materiality:Â Does the incident affect financial condition, operations, or reputation?
- Content:Â Description of the incident, timing, and impact.
- Annual Disclosure (Form 10-K):Â Companies must disclose their risk management, strategy, and governance of cybersecurity risks.
- Board Oversight:Â Describe the board’s role in overseeing cyber risk (e.g., which committee has responsibility, frequency of reporting).
- Management Expertise:Â Disclose whether any board member has cybersecurity expertise.
- Incident Disclosure (Form 8-K): Public companies must disclose material cybersecurity incidents within 4 business days of determining the incident is material.
- NIST Framework Integration:
- Most companies align their cyber risk management with the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover).
- Governance bodies must ensure this framework is implemented and tested regularly.
- Board Competency:
- Boards are increasingly expected to have at least one director with cybersecurity expertise.
- If no expert exists, the board must demonstrate how they access expert advice (e.g., via external consultants).
- Ransomware and Supply Chain Risks:
- Disclosure must address risks from third-party vendors (supply chain attacks).
- Companies must have incident response plans that are tested via tabletop exercises, often reviewed by the board.
- Global Variations:
- EU (NIS2 Directive):Â Stricter requirements for incident reporting (24-hour initial notification) for essential entities.
- US (CISA):Â Voluntary reporting for critical infrastructure, but mandatory for federal contractors.