Critical Milestone: How New SEC Rules Impact Corporate Cybersecurity

In 2023, the Securities and Exchange Commission (SEC) implemented new cybersecurity disclosure rules. These regulations require disclosure of ‘material’ threat and breach incidents within four days of occurrence, along with annual reporting on cybersecurity risk management, strategy and governance.

The introduction of the new SEC cybersecurity requirements represents a critical milestone in the ongoing fight against cyber threats. In 2023, Chief Information Security Officers (CISOs) revealed that three out of four companies in the United States were vulnerable to a material cyberattack. As a result, cybercrime remains one of the biggest risks facing US-based companies. Additionally, in the same year, nearly seven in 10 organizations in the United States experienced a ransomware attack in the previous 12 months.