Cloud Wars
  • Home
  • Top 10
  • CW Minute
  • CW Podcast
  • Categories
    • AI and Copilots
    • Innovation & Leadership
    • Cybersecurity
    • Data
  • Member Resources
    • Cloud Wars AI Agent
    • Digital Summits
    • Guidebooks
    • Reports
  • About Us
    • Our Story
    • Tech Analysts
    • Marketing Services
  • Summit NA
  • Dynamics Communities
  • Ask Copilot
Twitter Instagram
  • Summit NA
  • Dynamics Communities
  • AI Copilot Summit NA
  • Ask Cloud Wars
Twitter LinkedIn
Cloud Wars
  • Home
  • Top 10
  • CW Minute
  • CW Podcast
  • Categories
    • AI and CopilotsWelcome to the Acceleration Economy AI Index, a weekly segment where we cover the most important recent news in AI innovation, funding, and solutions in under 10 minutes. Our goal is to get you up to speed – the same speed AI innovation is taking place nowadays – and prepare you for that upcoming customer call, board meeting, or conversation with your colleague.
    • Innovation & Leadership
    • CybersecurityThe practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.
    • Data
  • Member Resources
    • Cloud Wars AI Agent
    • Digital Summits
    • Guidebooks
    • Reports
  • About Us
    • Our Story
    • Tech Analysts
    • Marketing Services
    • Login / Register
Cloud Wars
    • Login / Register
Home » Navigating the Impact of SEC Cybersecurity Rules on Businesses and Investors
Cybersecurity

Navigating the Impact of SEC Cybersecurity Rules on Businesses and Investors

Chris HughesBy Chris HughesAugust 24, 2023Updated:August 24, 20234 Mins Read
Facebook Twitter LinkedIn Email
sec cybersecurity rules 2023
Share
Facebook Twitter LinkedIn Email
Acceleration Economy Cybersecurity

If you’ve been paying attention to technology news lately, you’ve likely heard rumblings about the Securities and Exchange Commission (SEC) rule changes that occurred in July. You may be wondering what all the fuss is about, what led to these rule changes, and what these changes mean moving forward.

I’m going to unpack all of it here for you, so buckle up!

How Did the SEC Get Here?

It’s no secret that people and the businesses that serve them are undergoing rapid digital transformations. One can see this shift in various facets of life, from personal leisure activities to business operations. Even critical infrastructure, which is essential for the functioning of a society, now relies heavily on digital advances.

The SEC acknowledged this new reality when implementing its cybersecurity rule changes, citing factors such as business operations becoming more reliant on software; increased adoption of remote work; and rising occurrences of cybersecurity incidents, as well as financial gains from cybercrime activities. All these factors culminated in calls for bolstering the rules for publicly traded companies to enhance market and investor transparency. These demands align with similar themes of transparency from federal agencies and the White House, including the Cybersecurity Executive Order.

Insights into Why & How to Recover from a Cybersecurity Breach
Guidebook: Cybersecurity Breach and Recovery Response

How Have SEC Cybersecurity Rules Changed?

The final rules included two key components. The first focuses on enhancing transparency around cybersecurity incidents, particularly those deemed “material.” Material has been defined as something that a reasonable shareholder would consider important, such as incidents that could have ramifications for customers, revenue, and so on.

These incidents will be disclosed on a new Item 1.05 Form 8K. The disclosure must describe information such as the incident’s nature, scope, timing, and also material impact on the organization and its associated operations. This would be of interest to existing and potential investors and stakeholders in an organization due to the potential financial impact of cybersecurity incidents.

The incident disclosure must occur four days following its discovery and once it has been deemed to be a material incident. Some caveats here include the U.S. attorney general’s ability to delay disclosures if they could have an impact on national security or public safety. There is also the reality that organizations rarely identify an incident immediately upon its occurrence and there is often a period of “dwell time,” which is the time that malicious actors may dwell in an environment prior to their nefarious activities being discovered. The median dwell time as reported by groups such as Mandiant is around three weeks, but it can be as high as several hundreds of days as well.

The second component of the SEC’s rules is S-K Item 106, which requires organizations to disclose their processes for identifying, assessing, and managing material risks related to cybersecurity threats. S-K Item 106 also requires organizations to disclose board- and management-level oversight of risks related to cybersecurity threats, as well as management’s role and expertise in assessing these cybersecurity threats. These rules are important for a variety of reasons, including the fact that organizations can’t identify and disclose material cybersecurity incidents effectively without established processes and capabilities. Proper oversight must start at the top. 

Cybersecurity Governance and Board Accountability

The originally proposed rules included requirements for firms to disclose any cybersecurity expertise on the board. This information would be valuable to some investors and shareholders who might have used the information either to rally around firms with solid cybersecurity leadership or used it as part of an incident post-mortem to see if the firm had appropriate leadership providing cybersecurity oversight. It likely would have encouraged firms to include cybersecurity expertise in the boardroom.

Some have argued that the final version of the rules that got accepted let the board off the hook with regard to cybersecurity governance and oversight. That said, few are arguing that the final rules aren’t, at minimum, a step in the right direction.

Final Thoughts

If you’re looking for a quick summary of the rule changes directly from the SEC, it published a concise two-page document that helps lay out the background, the rule changes, and what comes next.

The SEC’s final rule changes for cybersecurity make it clear that regulators are increasingly acknowledging the role it plays in today’s economy. “We aren’t a technology company” is a phrase that has fallen by the wayside, as nearly every organization is wielding technology to effectively serve its customers and run business operations — all of which must be underpinned by the cybersecurity of that digital infrastructure.

It’s safe to say that these won’t be the last rules that add requirements related to cybersecurity for publicly traded companies, so stay tuned!


for more cybersecurity insights, visit the cybersecurity channel

Board of Directors Cybersecurity featured governance software
Share. Facebook Twitter LinkedIn Email
Analystuser

Chris Hughes

CEO and Co-Founder
Aquia

Areas of Expertise
  • Cloud
  • Cybersecurity
  • LinkedIn

Chris Hughes is a Cloud Wars Analyst focusing on the critical intersection of cloud technology and cybersecurity. As co-founder and CEO of Aquia, Chris draws on nearly 20 years of IT and cybersecurity experience across both public and private sectors, including service with the U.S. Air Force and leadership roles within FedRAMP. In addition to his work in the field, Chris is an adjunct professor in cybersecurity and actively contributes to industry groups like the Cloud Security Alliance. His expertise and certifications in cloud security for AWS and Azure help organizations navigate secure cloud migrations and transformations.

  Contact Chris Hughes ...

Related Posts

OCI and IBM Expand Partnership, Customer Wins Incoming

May 21, 2025

ServiceNow AI Maturity Index: A 5-Stage Framework to Accelerate Enterprise AI Success

May 21, 2025

Microsoft Brings Sales Insights from Gong Into Copilot, Dynamics, and Other Apps

May 21, 2025

Salesforce Launches Life Sciences Partner Network to Accelerate GenAI and Agentforce Adoption in MedTech and Pharma

May 21, 2025
Add A Comment

Comments are closed.

Recent Posts
  • OCI and IBM Expand Partnership, Customer Wins Incoming
  • ServiceNow AI Maturity Index: A 5-Stage Framework to Accelerate Enterprise AI Success
  • Microsoft Brings Sales Insights from Gong Into Copilot, Dynamics, and Other Apps
  • Salesforce Launches Life Sciences Partner Network to Accelerate GenAI and Agentforce Adoption in MedTech and Pharma
  • AI Agent & Copilot Podcast: St. Luke’s University Health Network On Expanding AI Use Cases

  • Ask Cloud Wars AI Agent
  • Tech Guidebooks
  • Industry Reports
  • Newsletters

Join Today

Most Popular Guidebooks

Accelerating GenAI Impact: From POC to Production Success

November 1, 2024

ExFlow from SignUp Software: Streamlining Dynamics 365 Finance & Operations and Business Central with AP Automation

September 10, 2024

Delivering on the Promise of Multicloud | How to Realize Multicloud’s Full Potential While Addressing Challenges

July 19, 2024

Zero Trust Network Access | A CISO Guidebook

February 1, 2024

Advertisement
Cloud Wars
Twitter LinkedIn
  • Home
  • About Us
  • Privacy Policy
  • Get In Touch
  • Marketing Services
  • Do not sell my information
© 2025 Cloud Wars.

Type above and press Enter to search. Press Esc to cancel.

  • Login
Forgot Password?
Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.